GKRootWire
Security ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm ForecastsSecurity ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm Forecasts
Security

Man Behind Massive Snowflake Data Theft Spree Pleads Guilty

Connor Riley Moucka admitted to hacking and extorting more than 165 companies through their Snowflake cloud accounts, including a breach that exposed call records for over 100 million AT&T customers.

A 26-year-old man from Kitchener, Ontario has pleaded guilty to computer fraud and conspiracy charges tied to one of the largest corporate extortion campaigns in recent memory. Connor Riley Moucka admitted to breaking into cloud storage accounts hosted on Snowflake, a platform widely used by large enterprises to warehouse customer data, and then demanding ransom payments from the affected companies to prevent the stolen information from being leaked or sold.

Prosecutors say Moucka's campaign touched more than 165 organizations, making him one of the most active and damaging threat actors identified in 2024. Among his admitted crimes was the theft of call and text metadata belonging to more than 100 million AT&T customers, a breach that exposed sensitive records about who customers communicated with and when, even though the content of the messages themselves wasn't taken.

Rather than exploiting a flaw in Snowflake's own infrastructure, the attackers reportedly relied on credentials stolen from customers or obtained through other means, then used those logins to access accounts that lacked multi-factor authentication. That pattern turned a routine cloud misconfiguration issue into a sprawling, multi-victim extortion operation that rippled across telecom, retail, and other sectors.

Why it matters: This case is a stark reminder that cloud platforms are only as secure as the credentials and access controls customers put in front of them, not just the provider's own defenses. Companies storing large volumes of sensitive data in shared platforms like Snowflake need to treat MFA and credential hygiene as non-negotiable, since a single weak login can cascade into a breach affecting hundreds of downstream customers.

Sources: Krebs on Security