Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
AI Summary
Connor Riley Moucka pleaded guilty to orchestrating breaches of Snowflake customer accounts in 2024, exploiting stolen credentials from infostealer malware that had not been rotated and where multi-factor authentication (MFA) was disabled. The attacks impacted at least 165 organizations and exposed data belonging to over 100 million people, including sensitive personal and government-related information. No platform vulnerability was exploited; instead, the campaign leveraged previously compromised credentials, with Mandiant attributing the activity to threat actor UNC5537. Moucka monetized the stolen data through ransoms and sales, netting at least $495,000, while re-extorting at least one victim using data of a government official and their family.
AI-extracted · verify before operational use