LIVE · cybersecurity feed
Live wire
breach

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people. Moucka, 26, of Kitchener, Ontario, personally took at least $495,000 from

zeroday.news · 2h ago

A recent report indicates that a hacker has pleaded guilty in connection with the 2024 breaches of Snowflake customer accounts. The individual, Connor Riley Moucka, entered a guilty plea in Seattle federal court to charges including computer fraud, wire fraud, aggravated identity theft, and conspiracy. These intrusions reportedly impacted at least 165 organizations and exposed records belonging to a minimum of 100 million individuals.

The breaches targeted customer accounts within the Snowflake data cloud platform. While the specific technical mechanisms of the attacks were not detailed in the report, this class of incident often involves credential compromise, such as phishing, brute-force attacks against weak or reused passwords, or the exploitation of previously leaked credentials. Attackers frequently leverage automated tools to test large sets of credentials against cloud service login portals.

Once access is gained to a cloud data platform account, attackers typically seek to exfiltrate sensitive data. This can involve querying databases, downloading files, or manipulating access controls to facilitate data theft. The scale of the reported breaches, affecting numerous organizations and a large number of individuals, suggests a systematic approach to compromise and data extraction.

Snowflake is a cloud-based data warehousing and analytics service, widely used by enterprises to store and process large volumes of data. Products in this category commonly hold a wide array of sensitive information, including customer data, financial records, and proprietary business intelligence, making them attractive targets for cybercriminals.

Mitigation strategies for this type of attack generally include the mandatory implementation of multi-factor authentication (MFA) for all user accounts, strong password policies, and regular monitoring of access logs for unusual activity. Organizations are also advised to conduct security awareness training for employees to prevent phishing and social engineering attacks, and to regularly audit permissions and access controls within their cloud environments.

The plea agreement also noted that Moucka personally obtained at least $495,000 from these activities. This incident underscores the significant financial motivations behind large-scale data breaches and the ongoing challenges organizations face in securing their data within cloud environments against sophisticated and persistent threats. It also highlights the cross-border nature of cybercrime, with the defendant being from Ontario, Canada, and facing charges in the United States.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide

For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers’ servers. His work shows they pulled off intrusions in a shocking number of systems across the globe.

CVE-2026-63077critical

Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability

Tracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution. The post Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability appeared first on SecurityWeek.

ai

OWASP 2026 LLM Top 10: “The model will be fooled”

The OWASP GenAI Security Project has released the 2026 edition of its Top 10 for LLM Applications and, for the first time, the list was influenced by real-world incidents. The two top entries – Prompt Injection and Sensitive Information Disclosure – remained constant, but the order shifted more than in past years below them: The 2025 and 2026 versions of OWASP 2026 LLM Top 10, compared (Source: OW

ai

OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack

It started with an 'impossible task' and led to AI deciding it needed to act as a collective intelligence

ai

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm credentials to backdoor co-owned packages totaling over 1.3 billion monthly downloads.

ai

AI Sends Global Crime Syndicates Into Fraud Nirvana

Organized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation.