The campaign exposed data tied to more than 100 million people and relied on stolen credentials and accounts without multi-factor authentication, not a flaw in Snowflake's platform.
Connor Riley Moucka, 26, pleaded guilty in U.S. District Court for the Western District of Washington to computer fraud, wire fraud, aggravated identity theft and conspiracy for his role in a Snowflake-linked credential theft and extortion campaign. The operation breached 165 companies and exposed sensitive data belonging to more than 100 million individuals, using stolen usernames and passwords from infostealer malware logs rather than any compromise of Snowflake's own infrastructure. Between February and October 2024, Moucka and co-conspirators John Erin Binns and Cameron Wagenius used credentials harvested by infostealer malware (malicious software that steals logins) to access customer cloud storage accounts where multi-factor authentication (extra login verification) had not been required. Investigators said the group used custom software tracked by Google's Mandiant as "Frostbite" to identify valuable records inside compromised accounts, then extorted victims by advertising stolen datasets on criminal forums and Telegram and demanding ransom in cryptocurrency. The scheme brought in more than $2.5 million in ransom from at least three companies, with Moucka personally receiving at least $495,000 in bitcoin. Mandiant found about 79.7 percent of the compromised Snowflake accounts had prior credential exposure, with many stolen passwords dating back to 2020 and never rotated. The case has become a high-profile example of how old credentials from criminal markets can remain effective for years when organizations do not enforce MFA, regular password changes and network allow lists (trusted IP access restrictions). Moucka is scheduled to be sentenced on October 27 before Judge Lauren King. He faces a mandatory minimum of two years on the aggravated identity theft count and up to 30 additional years on the remaining charges, for a combined maximum of 32 years. The DOJ said the plea is part of Operation Riptide, the FBI's cybercrime crackdown announced in June 2026.