Snowflake Breach: Hacker Pleads Guilty to Affecting Over 100 Million Records

Published:

spot_img

Snowflake Breach: Hacker Pleads Guilty to Affecting Over 100 Million Records. Connor Riley Moucka has pleaded guilty in a Seattle federal court to multiple charges, including computer fraud and aggravated identity theft, related to significant breaches of Snowflake customer accounts in 2024. The breaches impacted at least 165 organizations and compromised records of over 100 million individuals. Moucka, a 26-year-old from Kitchener, Ontario, reportedly gained at least $495,000 through ransom payments and data sales. This case highlights the vulnerabilities associated with outdated security practices, particularly the use of old passwords and the disabling of multi-factor authentication (MFA).

Snowflake Breach Details and Impact

The breaches attributed to Moucka involved the exploitation of old passwords that had been harvested by infostealer malware. Many of these credentials had not been updated for years, and the accounts lacked multi-factor authentication, which left them vulnerable. The Justice Department has not publicly named the affected company, referring to it only as a U.S. software-as-a-service (SaaS) provider, although Snowflake and Mandiant identified it in their investigations.

Prosecutors indicated that Moucka also attempted to extort at least one victim by threatening to disclose sensitive information, including data related to government officials and their families. The FBI’s Seattle field office described the tactics used by Moucka as “calculated and predatory,” emphasizing the serious nature of the offenses.

Extent of the Data Compromise

The breaches resulted in the exposure of sensitive information, including call and text histories, payroll records, and personal identification numbers such as Social Security numbers. Victim companies reported losses exceeding $9.5 million, not accounting for the financial impact on their customers. The compromised data included records from major telecommunications providers, with AT&T confirming that data from nearly all its cellular customers was affected during the breach period.

According to Mandiant, which investigated the breaches, a staggering 79.7% of the accounts exploited had previously exposed credentials. The investigation revealed that many of these credentials had been valid for years, underscoring the risks associated with failing to rotate passwords regularly.

Legal Proceedings and Sentencing

Moucka is scheduled for sentencing on October 27, where he faces a mandatory minimum of two years for identity theft and up to 30 years for the other charges. His co-defendant, John Erin Binns, remains at large, while another individual linked to the case, Cameron John Wagenius, has already pleaded guilty in a related matter.

The evolving nature of the case has led to discrepancies in the reported number of affected organizations, with figures ranging from 150 to over 165. This inconsistency highlights the complexities involved in tracking the full extent of the breaches and their impact on various entities.

Future Security Measures

In response to the breaches, Snowflake has implemented mandatory multi-factor authentication for new accounts created since October 2024. However, password-only sign-ins are still permitted for existing accounts, with a phased rollout of enhanced security measures expected to conclude by October 2026. This initiative aims to mitigate the risks associated with credential theft and improve overall account security.

The case serves as a critical reminder of the importance of robust cybersecurity practices, including regular password updates and the implementation of multi-factor authentication to protect sensitive data.

This report is based on information published by thehackernews.com.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

spot_img

Related articles

Recent articles

Untrusted Data Safety

Microsoft Defender’s attack disruption now includes device isolation, a new response action that enhances protection for compromised endpoints. This capability was recently highlighted in...

Agent Risk Manager: KnowBe4 Enhances Security for Anthropic’s Claude AI

Agent Risk Manager is a new initiative by KnowBe4, aimed at enhancing security for Anthropic's Claude AI. Announced in Dubai, this integration extends KnowBe4's...

De Bijenkorf: Customer Data Potentially Exposed After Logistics Cyberattack

De Bijenkorf: Customer Data Potentially Exposed After Logistics Cyberattack. A cyberattack targeting a logistics provider for the Dutch luxury department store chain De Bijenkorf...

SENSOR PROXY: Tenable Releases Update for Vulnerability in Version 1.4.2

SENSOR PROXY Tenable has issued an advisory regarding a vulnerability affecting its Sensor Proxy product, specifically versions prior to 1.4.2. This advisory, numbered AV26-773...