Start with Identity
Breach teardown · Snowflake customers (Ticketmaster, others)

The 2024 Snowflake customer breaches: stolen credentials meet missing MFA

Affected: Snowflake customers (Ticketmaster, others)Disclosed: 2024-05Root cause: Stolen credentials from infostealers, accounts without MFA

What happened

In mid-2024 a threat actor (tracked as UNC5537) accessed roughly 165 Snowflake customer environments and stole large volumes of data, affecting high-profile names. Investigations by Mandiant and Snowflake found no vulnerability in Snowflake itself. Instead, the attacker logged in with valid customer credentials, many harvested years earlier by infostealer malware on contractor and employee machines.

Root cause

The breached accounts shared three traits: credentials had been stolen and never rotated, the accounts had no multi-factor authentication, and there were no network policies restricting where logins could come from. With a username and password and nothing else in the way, access was trivial.

The identity lesson

This is the defining identity breach pattern of the era: the attacker does not break in, they log in. When single-factor accounts exist on a data platform, leaked credentials from unrelated breaches become a direct path to your data. The platform was secure; the identity configuration was not.

Prosecution and outcome

Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty in Seattle federal court on August 6, 2026 to computer fraud, wire fraud, aggravated identity theft, and conspiracy. Prosecutors put the campaign at 165 organizations and records on at least 100 million people, including nearly all AT&T cellular customers for a six-month window in 2022. Moucka personally took at least 495,000 dollars from ransoms and data sales, against victim losses above 9.5 million. Sentencing is set for October 27, 2026, carrying a two-year mandatory minimum on the identity theft count. Co-defendant John Erin Binns remains outside US custody; former Army soldier Cameron John Wagenius pleaded guilty in a related case in July 2025.

The charging documents restate the mechanism plainly: the credentials were harvested by infostealers years before use, the accounts had MFA disabled, and some passwords had gone unrotated for four years. See our news brief on the plea.

How to defend

  • Enforce MFA everywhere, with no exceptions for service or legacy accounts. Snowflake later moved to make MFA mandatory.
  • Add network allowlists so credentials alone cannot be used from arbitrary locations.
  • Rotate credentials and move to short-lived, federated access instead of long-lived passwords.
  • Monitor for impossible-travel and anomalous access (ITDR), and watch for your credentials in infostealer dumps.

Guide: how to choose an MFA solution, phishing-resistant MFA. Glossary: credential stuffing, infostealer.

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Compiled from public disclosures and incident reporting; see the linked sources. Independent, community-driven analysis, not a statement of fact about any party. See the disclaimer.