Snowflake Hacker Pleads Guilty — 100 Million People's Records Exposed
Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft, and conspiracy, according to The Hacker News. His actions reached at least 165 organisations and exposed records belonging to at least 100 million people. He personally collected at least $495,000 through ransoms and data sales.
The method was not clever. Attackers used passwords stolen years earlier by infostealer malware (software that silently harvests saved credentials from infected devices) and never changed by their owners. The accounts also had multi-factor authentication (MFA — a second verification step beyond just a password) switched off entirely. No platform flaw was needed.
Think of it like finding a years-old spare key under a doormat that nobody ever moved, and then walking straight in.
Data taken included call and text records, passport numbers, Social Security numbers, payroll data, and DEA registration numbers. AT&T confirmed in July 2024 that records covering nearly all its cellular customers between May 2022 and October 2022 were among the stolen material. Victim companies suffered over $9.5 million in confirmed losses, excluding harm to their own customers.
Moucka is sentenced on October 27 and faces up to 30 years. Co-defendant John Erin Binns remains outside U.S. custody.
What you should do: Turn on MFA for every cloud account you use, especially anything work-related. Then check whether any of your passwords are older than a year and change them.
Sources

