Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

Snowflake Database Breach Exposes Sensitive Data of Over 100 Million Individuals

A hacker, identified as a prominent figure in the cybersecurity community, has pleaded guilty to multiple counts of identity theft and data breaches affecting at least 100 million people worldwide. The individual, who was arrested earlier this year, gained unauthorized access to sensitive databases through a clever exploitation of cross-domain privilege escalation vulnerabilities.

The breach occurred when the hacker manipulated permissions across different domains within Snowflake’s cloud-based database, creating an “attack path” that allowed them to bypass security controls and extract sensitive information. This technique, known as domain hopping or privilege escalation, enables hackers to assume higher levels of access within a system, granting them unfettered movement between domains.

The hacker’s attack on Snowflake’s databases exposed vast amounts of personal data, including names, email addresses, phone numbers, and even financial records. While the full extent of the breach is still being assessed, authorities believe that millions more individuals could be impacted once all affected parties are notified.

Snowflake, a cloud-based data warehousing service used by thousands of organizations worldwide, has faced intense scrutiny in recent months due to concerns over its security posture. The company has since implemented stricter access controls and increased its security protocols to prevent similar breaches from occurring.

The Snowflake breach serves as a stark reminder that even the most seemingly secure systems can be vulnerable to sophisticated attacks. As hackers become increasingly adept at exploiting complex vulnerabilities, organizations must prioritize robust security measures, including regular penetration testing and employee education on cybersecurity best practices.

By understanding the mechanics behind these types of breaches, individuals and businesses alike can better prepare themselves against potential threats.


Source: The Hacker News — 2026-08-06