A Snowflake Hack Affects Over 165 Organizations, Exposing Billions of Sensitive Records
Connor Riley Moucka, a 26-year-old Canadian national, has pleaded guilty to his role in a massive cybercrime campaign that compromised the sensitive data of over 165 organizations using Snowflake data storage accounts. The plea deal comes with a possible sentence of more than 30 years in prison, with sentencing scheduled for October 27.
The cybercrime group, tracked as UNC5537, used stolen login credentials to access and steal billions of sensitive records from prominent companies such as AT&T, Advance Auto Parts, Ticketmaster, Santander Bank, Neiman Marcus, Anheuser-Busch, Allstate, Mitsubishi, Progressive, and State Farm. The hackers not only stole the data but also sold it on hacking forums, with Moucka personally earning half a million dollars.
The campaign’s impact extends far beyond the companies targeted. According to authorities, at least 100 million people had their personal and financial information compromised in the attack. The total losses for the affected organizations exceed $9.5 million, which does not account for the losses suffered by their customers. The hackers also received a staggering $2.5 million in ransom payments.
A former US soldier, who pleaded guilty to hacking into AT&T and Verizon systems roughly one year ago, is believed to have participated in the Snowflake campaign. This highlights the alarming trend of insiders collaborating with external threat actors to carry out complex cyberattacks.
The use of Snowflake data storage accounts by these hackers underscores the importance of robust security measures for cloud-based services. Organizations must be vigilant about protecting their sensitive data and take proactive steps to prevent such breaches from occurring in the future.
As cybersecurity threats continue to evolve, it is essential for companies to stay ahead of the curve and invest in cutting-edge security technologies. This includes implementing multi-factor authentication, regular data backups, and incident response plans to minimize the impact of a potential breach.
In light of this high-profile case, one key takeaway is that even seemingly secure cloud-based services can be vulnerable to exploitation if not properly configured or managed. It’s crucial for organizations to regularly review their security protocols and ensure they are up-to-date with the latest best practices to safeguard against such threats. By doing so, they can significantly reduce the risk of falling victim to similar cyberattacks in the future.
Source: SecurityWeek — 2026-08-06