Jessica Entwistle
August 7 2026
Connor Riley Moucka, a 26-year-old Canadian man, has pleaded guilty in a US court to computer fraud and conspiracy charges related to the 2024 Snowflake extortion campaign. Krebs on Security reports that Moucka admitted to hacking and extorting more than 165 organisations that used the cloud data storage provider Snowflake, as well as stealing call and text history records of over 100 million AT&T customers. Moucka was extradited to the United States in July 2025 after being arrested in Canada. The Snowflake campaign was one of the most significant supply chain-adjacent attacks of 2024, exploiting credential stuffing and weak authentication practices rather than vulnerabilities in Snowflake's platform itself. The guilty plea brings some closure to a case that affected organisations across multiple sectors and highlighted the risks of inadequate authentication controls in cloud environments.
This case matters operationally because it underscores how attackers continue to exploit weak authentication and credential reuse across cloud platforms, managed services and SaaS environments. The Snowflake incidents were not the result of a platform vulnerability but rather organisations failing to enforce multi-factor authentication (MFA) or monitor for anomalous access patterns. For UK businesses using cloud data platforms, managed services or any environment where customer or operational data is stored outside the traditional network perimeter, this is a reminder that security responsibility is shared. The platform provider secures the infrastructure, but the customer must secure access, enforce strong authentication, monitor usage and ensure that privileged accounts are protected and audited. The Snowflake campaign demonstrated that attackers are highly effective at exploiting the weakest link in cloud security: compromised credentials combined with absent or poorly implemented MFA. Many organisations discovered they had been breached only after receiving extortion demands, indicating that monitoring and anomaly detection were also insufficient.
For many organisations, this is a prompt to review whether MFA is enforced across all cloud platforms, SaaS applications and managed services, not just on email and VPNs. Consider whether you have visibility into who is accessing cloud-hosted data, from where, and whether anomalous login patterns or bulk data exports would trigger an alert. Ensure that privileged accounts used to access cloud platforms are protected, monitored and subject to regular access reviews. Review whether your organisation has a process for detecting and responding to credential stuffing attacks, whether you monitor for impossible travel or unusual access patterns, and whether you have logging and alerting in place for bulk data downloads or API access. This is also a prompt to consider whether your cloud security posture management includes regular audits of authentication policies, access controls and logging configurations across all cloud and SaaS platforms in use.
Source: Krebs on Security