Cloud Security
Canadian Hacker Pleads Guilty in Massive Snowflake Cloud Extortion Case
FORTSECURE GLOBAL· 2026-08-10🛰 Krebs on Security
#Cloud Security#Data Breach#Cybercrime#Snowflake#MFA
A 26-year-old Canadian individual has admitted to hacking over 165 organizations by exploiting cloud storage vulnerabilities, leading to one of the largest data thefts in recent history.
The Snowflake Extortion Incident The cyber landscape was recently shaken by the guilty plea of Connor Riley Moucka, a Canadian man responsible for a series of devastating attacks against users of the Snowflake cloud data platform. By exploiting environments that lacked multi-factor authentication, Moucka and his associates managed to compromise the accounts of over 165 organizations. This campaign is considered one of the most consequential cybercrime events of 2024, highlighting the fragility of cloud environments when basic security hygiene is ignored. One of the most significant victims was AT&T, where the attacker successfully stole the call and text history records of more than 100 million customers, showcasing the massive scale of potential damage when cloud storage is improperly secured. ## The Mechanics of the Breach and Professional Insights The primary vector for these attacks was not a sophisticated zero-day vulnerability in Snowflake's infrastructure, but rather the exploitation of stolen credentials. Attackers used these credentials to access accounts where the customers had failed to enable Multi-Factor Authentication (MFA). Once inside, they exfiltrated massive volumes of sensitive data and initiated extortion attempts, threatening to leak the information unless a ransom was paid. At FORTSECURE GLOBAL, we view this as a stark reminder that security is a shared responsibility between the provider and the user. The breach was largely preventable had the victim organizations implemented robust identity and access management controls. ## Practical Recommendations for Cloud Security To protect your organization from similar cloud-based extortion attempts, we recommend the following actions: 1. Enforce MFA: Mandatory Multi-Factor Authentication must be implemented for all administrative and user accounts accessing cloud data platforms. 2. Monitor for Anomalous Access: Use Security Information and Event Management (SIEM) tools to detect logins from unusual geographic locations or unfamiliar devices. 3. Credential Hygiene: Regularly rotate passwords and use automated tools to check for leaked credentials in dark web forums. 4. Data Encryption: Ensure that sensitive data is encrypted both at rest and in transit, limiting the value of stolen data for extortionists.
แหล่งที่มา: Krebs on Security เผยแพร่ครั้งแรก: Thu, 06 Aug 2026 17:00:56 +0000 บทความต้นฉบับ: อ่านต้นฉบับ
Source Attribution
แหล่งที่มา: Krebs on Security
เผยแพร่ครั้งแรก: Thu, 06 Aug 2026 17:00:56 +0000
บทความต้นฉบับ: https://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/
* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์
