Snowflake Hacker Pleads Guilty in 100M

Connor Riley Moucka, a Canadian hacker, pleaded guilty in Seattle federal court to computer fraud, wire fraud, aggravated identity theft, and conspiracy tied to 2024 breaches of 165+ Snowflake customer environments. Prosecutors said stolen credentials and missing MFA enabled access, exposing data tied to at least 100 million people, with $9.5M in direct losses and $2.5M in ransom payments. Sentencing is Oct. 27.

Original reporting
Published Aug 7, 2026, 10:45 PM UTC
Analysis
alphai AI DeskAI-generated
Added to alphai Aug 7, 2026, 11:27 PM UTC. Informational, not investment advice.
How this was made
alphai summarizes source reporting and applies a structured AI analysis for relevance, timing, sentiment and ticker impact. Always verify material claims with the original publisher.
alphai market briefRegulation
Primary signal
$SNOW
Bearish
medium confidence
Mentioned
$SNOW
Relevance
7/10
alphai data visualization · based on esecurityplanet.com
Decision brief

The 30-second read

$SNOWBearishMed
01

Why it matters

The case reinforces that identity hygiene (MFA, credential rotation, network access controls) is a primary defense against large-scale data theft, and it ties Snowflake’s customer environment security to enterprise IAM practices.

02

Market read

Traders may reassess cloud security risk premium for data-platform vendors as criminal proceedings and MFA rollout milestones keep the issue salient.

03

What to watch

The article emphasizes Snowflake’s MFA rollout timeline and default settings for newer accounts, which could mitigate longer-term reputational and customer-retention concerns if execution is strong.

Relevance 7/10Novelty 6/10Timing: sentencing set for Oct. 27, with MFA rollout milestones through Aug-Oct 2026

Background

Connor Riley Moucka pleaded guilty in federal court for a 2024 campaign that breached 165+ Snowflake customer environments using stolen, password-only credentials.

Company-level read

Ticker impact

$SNOWBearishMedium confidence
Context

The article says a Canadian hacker pleaded guilty over 2024 breaches of more than 165 Snowflake customer environments, exposing data tied to at least 100M people.

Expected impact

Near-term sentiment pressure is possible around security posture and customer risk, but the direct financial impact is not quantified in the article.

Evidence & confidence

The piece is a criminal-justice development tied to Snowflake customer breaches and includes specific security mechanics (stolen credentials, missing MFA), but it does not report new Snowflake financials, guidance, or a fresh regulatory action.

Market effects

Credential theft and missing MFA are highlighted as the root cause, which can increase scrutiny of cloud data-platform security practices across the sector.

Primarily US-focused court proceedings, but the victim list spans multiple industries, implying broad enterprise security concerns.

Credential-based attacks and MFA gaps are globally relevant, potentially affecting multinational cloud customers’ security budgets and vendor evaluations.

Counterpoint

Because the attacks relied on stolen credentials and not a Snowflake platform vulnerability, the incremental impact on Snowflake’s core product risk may be limited.

Key entities

  • Snowflake

    Cloud data platform whose customer environments were breached in the 2024 campaign described.

  • Connor Riley Moucka

    Canadian hacker who pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy.

  • Mandiant (UNC5537)

    Threat intelligence firm cited for findings that compromised credentials and missing MFA were central to the incidents.

Related articles

$SNOWMed

Early Snowflake Investor Nails a 50% Rebound That May Only Be Warming Up

Snowflake shares rose to about $260, up ~54% from $169 after its Q4 release. In Q1 FY27 (reported May 27), revenue grew 33.5% to $1.39B and non-GAAP EPS was $0.39 vs $0.32 consensus. Remaining performance obligations rose 38% to $9.21B. The company also announced a $6B multi-year AWS collaboration and raised FY27 product revenue guidance to $5.84B.

$SNOWMed

Hacker pleads guilty to stealing data from more than 165 Snowflake customers

The U.S. Department of Justice said Connor Moucka pleaded guilty to hacking Snowflake and breaking into dozens of its customers, including AT&T, LendingTree, and Ticketmaster. The DOJ said he stole data from more than 100 million AT&T customers and received over $2.5 million in ransom payments. Victims’ losses were cited at $9.5 million. Sentencing is set for Oct. 27.

$SNOWMed

Snowflake launches AI agent governance layer to track activity, control costs

Snowflake said it launched Cortex AI Gateway, an AI agent runtime control plane to track agent activity, enforce governance policies, and apply cost controls across models and tools. The technology is based on Snowflake’s Natoma acquisition. Analysts said it addresses gaps in securing and auditing agentic workflows as consumption-based AI pricing grows.

$SNOWMed

Snowflake launches AI gateway for secure agent access

Snowflake launched Cortex AI Gateway2 and related AI security products to centralize governance for AI agents accessing models, tools, enterprise systems and data, and to track AI spending. Snowflake says it can support 100+ MCP servers and routes requests to approved models. Integrations include 1Password, Okta and others; Natoma tech is folded in.

$SNOWMed

Snowflake unifies AI agent security, governance and cost controls with Cortex AI Gateway

Snowflake launched Cortex AI Gateway, a control layer to manage how AI agents connect to enterprise data, apps, models, and tools. It supports agents built in Snowflake and third-party agents via platforms like Claude Code and Cursor, and builds on Snowflake’s Natoma (MCP) acquisition. The product centralizes authentication, permissions, auditing, and cost tracking, supports 100+ MCP servers, and adds integrations with 1Password, Okta, and others.