Snowflake Hacker Pleads Guilty in 100M
Connor Riley Moucka, a Canadian hacker, pleaded guilty in Seattle federal court to computer fraud, wire fraud, aggravated identity theft, and conspiracy tied to 2024 breaches of 165+ Snowflake customer environments. Prosecutors said stolen credentials and missing MFA enabled access, exposing data tied to at least 100 million people, with $9.5M in direct losses and $2.5M in ransom payments. Sentencing is Oct. 27.
How this was made
The 30-second read
Why it matters
The case reinforces that identity hygiene (MFA, credential rotation, network access controls) is a primary defense against large-scale data theft, and it ties Snowflake’s customer environment security to enterprise IAM practices.
Market read
Traders may reassess cloud security risk premium for data-platform vendors as criminal proceedings and MFA rollout milestones keep the issue salient.
What to watch
The article emphasizes Snowflake’s MFA rollout timeline and default settings for newer accounts, which could mitigate longer-term reputational and customer-retention concerns if execution is strong.
Background
Connor Riley Moucka pleaded guilty in federal court for a 2024 campaign that breached 165+ Snowflake customer environments using stolen, password-only credentials.
Ticker impact
The article says a Canadian hacker pleaded guilty over 2024 breaches of more than 165 Snowflake customer environments, exposing data tied to at least 100M people.
Near-term sentiment pressure is possible around security posture and customer risk, but the direct financial impact is not quantified in the article.
The piece is a criminal-justice development tied to Snowflake customer breaches and includes specific security mechanics (stolen credentials, missing MFA), but it does not report new Snowflake financials, guidance, or a fresh regulatory action.
Market effects
Credential theft and missing MFA are highlighted as the root cause, which can increase scrutiny of cloud data-platform security practices across the sector.
Primarily US-focused court proceedings, but the victim list spans multiple industries, implying broad enterprise security concerns.
Credential-based attacks and MFA gaps are globally relevant, potentially affecting multinational cloud customers’ security budgets and vendor evaluations.
Counterpoint
Because the attacks relied on stolen credentials and not a Snowflake platform vulnerability, the incremental impact on Snowflake’s core product risk may be limited.
Key entities
- public_companySnowflake
Cloud data platform whose customer environments were breached in the 2024 campaign described.
- personConnor Riley Moucka
Canadian hacker who pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy.
- security_firmMandiant (UNC5537)
Threat intelligence firm cited for findings that compromised credentials and missing MFA were central to the incidents.





