GKRootWire
AI xAI Publishes Details on Its Grok Web CrawlerAI Why 'Human-in-the-Loop' Might Have It BackwardsDev Tools Modular Ships Mojo 1.0, Marking the Language's Production DebutAI OpenAI's Head of Ethics Exits Less Than a Year Into the JobAI Researchers Show How to Extract Hidden Reasoning from Proprietary LLM APIsAI Nvidia Debuts Nemotron 3.5 Lightning and NeMo Switchyard for Local AI WorkflowsAI xAI Publishes Details on Its Grok Web CrawlerAI Why 'Human-in-the-Loop' Might Have It BackwardsDev Tools Modular Ships Mojo 1.0, Marking the Language's Production DebutAI OpenAI's Head of Ethics Exits Less Than a Year Into the JobAI Researchers Show How to Extract Hidden Reasoning from Proprietary LLM APIsAI Nvidia Debuts Nemotron 3.5 Lightning and NeMo Switchyard for Local AI Workflows
Security

Man Behind Massive Snowflake Data Theft Spree Pleads Guilty

Connor Riley Moucka admitted to hacking and extorting more than 165 companies through their Snowflake cloud accounts, including a breach that exposed call records for over 100 million AT&T customers.

A 26-year-old man from Kitchener, Ontario has pleaded guilty to computer fraud and conspiracy charges tied to one of the largest corporate extortion campaigns in recent memory. Connor Riley Moucka admitted to breaking into cloud storage accounts hosted on Snowflake, a platform widely used by large enterprises to warehouse customer data, and then demanding ransom payments from the affected companies to prevent the stolen information from being leaked or sold.

Prosecutors say Moucka's campaign touched more than 165 organizations, making him one of the most active and damaging threat actors identified in 2024. Among his admitted crimes was the theft of call and text metadata belonging to more than 100 million AT&T customers, a breach that exposed sensitive records about who customers communicated with and when, even though the content of the messages themselves wasn't taken.

Rather than exploiting a flaw in Snowflake's own infrastructure, the attackers reportedly relied on credentials stolen from customers or obtained through other means, then used those logins to access accounts that lacked multi-factor authentication. That pattern turned a routine cloud misconfiguration issue into a sprawling, multi-victim extortion operation that rippled across telecom, retail, and other sectors.

Why it matters: This case is a stark reminder that cloud platforms are only as secure as the credentials and access controls customers put in front of them, not just the provider's own defenses. Companies storing large volumes of sensitive data in shared platforms like Snowflake need to treat MFA and credential hygiene as non-negotiable, since a single weak login can cascade into a breach affecting hundreds of downstream customers.

Sources: Krebs on Security