Case file · SNOWFLAKE 2024

How the 2024 Snowflake breaches happened: old stolen passwords and no second lock

Published 2026-09-29 · 5 min read · Missing control: Enforced MFA and credential rotation

Some of the passwords used in the 2024 Snowflake data thefts had been stolen more than 3 years earlier, and nobody had changed them.[1] This case file covers how a group logged into about 165 companies' accounts on a cloud data platform that was never itself broken into, what it cost, and the one control that would have stopped it.

What happened

Snowflake is a cloud service where large companies store and analyze their data. Each customer runs its own account on the platform and decides who can log in and how. In April 2024, investigators at Mandiant, the Google-owned incident response firm, were called in by a Snowflake customer whose data had been taken. By May 22 they had found a much wider campaign, which they tracked under the name UNC5537, and Snowflake and Mandiant went on to notify about 165 organizations that their accounts might be exposed.[1]

One of those organizations was AT&T. The company said it learned on April 19, 2024 that its workspace on a third-party cloud platform had been accessed, and on July 12 it disclosed that call and text records for nearly all of its wireless customers had been copied. The records covered May 1 to October 31, 2022, plus January 2, 2023. They showed which numbers contacted which, and some included cell site information that can reveal a rough location, but not the content of calls or texts, Social Security numbers or dates of birth.[2] AT&T delayed the announcement at the request of federal law enforcement.[2]

Other companies named in later prosecutions included Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander and LendingTree.[4] The group demanded payment to delete stolen data and offered some of it for sale on criminal forums.[1]

How they got in

No hacking of Snowflake's own systems was needed. Mandiant found no evidence that the attackers got in through a breach of Snowflake's corporate environment. Every incident it traced came back to a customer's own username and password.[1]

Those passwords had been collected by infostealer malware, a kind of malicious software that quietly copies saved logins from an infected computer and sends them to criminals, who resell them. Mandiant said at least 79.7% of the accounts used in the campaign had credentials that were exposed before, some as far back as November 2020.[1] Several of the infections were on computers belonging to contractors, machines that were also used for personal activities such as gaming and downloading pirated software, and that were used to reach more than one client's systems.[1]

Three things lined up in the accounts that were raided. They did not require multi-factor authentication, the second check such as an app prompt or code that a stolen password alone cannot pass. The passwords had not been changed, in some cases for years. And there was no network allow list, a setting that only accepts logins from approved locations.[1] With all three missing, a password bought from a criminal market was enough.

How it was caught and what it cost

A Canadian man, Connor Riley Moucka of Kitchener, Ontario, was arrested in Canada on October 30, 2024 on a U.S. warrant.[3] In August 2026 he pleaded guilty in federal court in Washington state to computer fraud, wire fraud, aggravated identity theft and conspiracy. His sentencing is set for October 27, 2026, and he faces up to 32 years.[3][4]

According to the case record reported at his plea, the scheme collected about $2.5 million in extortion payments, he made at least $495,000 more selling stolen data, and victim companies documented about $9.5 million in losses.[4] A U.S. Army soldier, Cameron Wagenius, separately pleaded guilty in July 2025 to extorting AT&T and Verizon with stolen call records. A third man, charged as a co-conspirator, was held in Turkey, which prosecutors cannot easily reach.[3]

AT&T did not confirm a payment, but published reports, based on the hacker's own account and a blockchain analysis firm's check of the transfer, said about $370,000 in bitcoin was paid in May 2024 to have its records deleted.[5]

On July 10, 2024, Snowflake gave account administrators a way to require multi-factor authentication for all their users, and began prompting users without it to turn it on.[6]

The missing control

The missing control: enforced multi-factor authentication, backed by regular rotation of old passwords.

Either half would likely have broken this. A second login factor means a password copied off an infected contractor laptop is not enough on its own. Changing passwords when staff and contractors change, or on a schedule, would have made credentials stolen in 2020 useless by 2024. An allow list limiting logins to the company's own network would have added a third wall.[1] None of these depended on the cloud provider. They were settings each customer could have turned on.

What to do in your business

Full episode

The Snowflake breaches, start to finish: old stolen passwords, 165 companies and AT&T's call logs: the long read behind the CL16 episode, chapter by chapter.

Watch the case
The 2024 Data Heist That Needed Only Old PasswordsDrops 2026-10-19
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Google Cloud (Mandiant): UNC5537 targets Snowflake customer instances for data theft and extortion
  2. Krebs on Security: Hackers steal phone, SMS records for nearly all AT&T customers
  3. Krebs on Security: Canadian man pleads guilty in Snowflake extortions
  4. The Record: Guilty plea in Snowflake hack
  5. CSO Online: Hacker allegedly paid $370,000 ransom to delete stolen AT&T data
  6. The Register: Snowflake lets admins make MFA mandatory