The 2024 Snowflake customer breaches: stolen credentials meet missing MFA
What happened
In mid-2024 a threat actor (tracked as UNC5537) accessed roughly 165 Snowflake customer environments and stole large volumes of data, affecting high-profile names. Investigations by Mandiant and Snowflake found no vulnerability in Snowflake itself. Instead, the attacker logged in with valid customer credentials, many harvested years earlier by infostealer malware on contractor and employee machines.
Root cause
The breached accounts shared three traits: credentials had been stolen and never rotated, the accounts had no multi-factor authentication, and there were no network policies restricting where logins could come from. With a username and password and nothing else in the way, access was trivial.
The identity lesson
This is the defining identity breach pattern of the era: the attacker does not break in, they log in. When single-factor accounts exist on a data platform, leaked credentials from unrelated breaches become a direct path to your data. The platform was secure; the identity configuration was not.
Prosecution and outcome
Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty in Seattle federal court on August 6, 2026 to computer fraud, wire fraud, aggravated identity theft, and conspiracy. Prosecutors put the campaign at 165 organizations and records on at least 100 million people, including nearly all AT&T cellular customers for a six-month window in 2022. Moucka personally took at least 495,000 dollars from ransoms and data sales, against victim losses above 9.5 million. Sentencing is set for October 27, 2026, carrying a two-year mandatory minimum on the identity theft count. Co-defendant John Erin Binns remains outside US custody; former Army soldier Cameron John Wagenius pleaded guilty in a related case in July 2025.
The charging documents restate the mechanism plainly: the credentials were harvested by infostealers years before use, the accounts had MFA disabled, and some passwords had gone unrotated for four years. See our news brief on the plea.
How to defend
- Enforce MFA everywhere, with no exceptions for service or legacy accounts. Snowflake later moved to make MFA mandatory.
- Add network allowlists so credentials alone cannot be used from arbitrary locations.
- Rotate credentials and move to short-lived, federated access instead of long-lived passwords.
- Monitor for impossible-travel and anomalous access (ITDR), and watch for your credentials in infostealer dumps.
Related
Guide: how to choose an MFA solution, phishing-resistant MFA. Glossary: credential stuffing, infostealer.
Related on Start with Identity
- ArticleIAM Incident Response Playbook: Handling Identity Breaches, Compromised Credentials, and Privilege Escalation
A complete playbook for responding to identity-related security incidents, including credential compromise, privilege escalation, and identity infrastructure at
- BlogOAuth client ID spoofing lets attackers validate stolen Entra credentials
Proofpoint found two campaigns submitting forged OAuth client IDs to Entra's token endpoint. Because error responses differ by whether the client ID is valid, a
- BlogShinyHunters claims an Ernst & Young breach that started with someone else's stolen credentials
The extortion group says it used credentials obtained through a supply-chain attack, source undisclosed, to reach EY's Jira, GitHub, and Azure environments, and
- BlogAnthropic's own Claude escaped a security test, stole a vendor's credentials, and used them
During evaluations Anthropic believed were sandboxed, Claude models broke out of test environments and hit real infrastructure at three organizations, in one ca
- RankingBest CIAM for B2B SaaS: Top 5 Customer Identity Platforms
The best CIAM platforms for B2B SaaS in 2026: WorkOS, Frontegg, Auth0, SSOJet, and Stytch. Ranked for enterprise SSO, SCIM, multi-tenancy, and self-service admi
- RankingBest CIAM for Enterprises: Top 6 Customer Identity Platforms
The best enterprise CIAM platforms in 2026: Auth0, Ping Identity, Transmit Security, WorkOS, Frontegg, and MojoAuth. Ranked for depth, compliance, orchestration