The Snowflake breaches, start to finish: old stolen passwords, 165 companies and AT&T's call logs
In 2024, criminals walked into the data of at least 165 companies on one cloud platform without hacking the platform at all: they logged in with passwords stolen by malware, some of them nearly 4 years earlier.[1][2] This long read follows the Snowflake campaign from the first tip to the AT&T call records, the arrests and guilty pleas, and the one control that would have made those old passwords worthless.
A shared cloud platform and a tip in April
Snowflake is a cloud service where large companies store and analyze enormous amounts of data. Each customer runs its own account and manages its own users and sign-in rules. In 2024, whether those accounts required a second sign-in step beyond a password was largely up to the customer.[1]
In April 2024, the security firm Mandiant received intelligence about database records that had been stolen and appeared to come from a customer's Snowflake account. As it dug in, it found a much wider pattern, and on May 22, 2024, it contacted Snowflake. On May 30, Snowflake published guidance for customers on detecting the intrusions and tightening their accounts.[1]
By June 10, Mandiant said it had notified about 165 organizations that their data might have been exposed. It attributed the campaign to a financially motivated group, with members it believed were based in North America and collaborators in Turkey, that stole data, extorted victims and sold records on criminal forums.[1] Crucially, Mandiant found no evidence that Snowflake's own corporate environment had been breached. Every intrusion it examined traced back to customer credentials.[1]
That distinction matters for anyone who uses cloud software. Cloud providers secure their own systems. Customers are still responsible for who can log in to their accounts and how. In this case, the platform held, and the doors that customers controlled did not.
Passwords stolen years earlier that still worked
Mandiant traced the stolen logins to infostealers, a kind of malware that quietly copies passwords saved on an infected computer and sends them to criminals, who resell them in bulk. It identified 6 different infostealer families in the campaign.[1]
The dates were the startling part. The earliest infection Mandiant found went back to November 2020, and in some cases stolen credentials still worked up to 4 years after they were taken. About 79.7% of the accounts the attackers used had credentials that had already been exposed before.[1]
Many of the infected machines were not company computers at all. Mandiant said initial infections often happened on contractors' personal or unmonitored laptops that were also used for gaming and downloading pirated software. A single infected contractor laptop could expose logins, sometimes with administrator rights, for several client organizations at once.[1]
Mandiant boiled the success of the campaign down to 3 missing protections: no multifactor authentication on the affected accounts, credentials that were never changed even years after being stolen, and no network allow lists, the rules that limit logins to known, trusted locations.[1]
AT&T's call records and a $370,000 payment
The victims included some of the best-known names in American business. Prosecutors later listed AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, LendingTree and a major U.S. school district among them.[2] The Ticketmaster data covered about 560 million users.[2]
The AT&T theft was the largest in reach. The stolen files held call and text logs for more than 100 million customers: records of which numbers contacted which, and when, rather than the content of calls or messages.[2][3] Metadata on that scale can reveal relationships, routines and movements, which is why it drew so much attention.
AT&T paid the group $370,000 in ransom to have the data deleted, according to reporting on the case.[3] Across the campaign, prosecutors said the crew collected about $2.5 million in ransom payments and another $495,000 from selling stolen data, and they put total victim losses at about $9.5 million.[2] Other stolen files contained banking and financial records, Social Security numbers, driver's license and passport numbers, and even DEA registration numbers used by medical prescribers.[2]
The arrests and guilty pleas
In November 2024, Canadian police arrested Connor Riley Moucka of Kitchener, Ontario, who used online names including Judische. He was extradited to the United States in July 2025.[2] In August 2026, then 26, he pleaded guilty to computer fraud, wire fraud, aggravated identity theft and conspiracy for breaches carried out between February and October 2024. The charges carry up to 32 years in prison. His sentencing was scheduled for October 27, 2026.[2]
The second defendant was a U.S. Army soldier stationed in South Korea, Cameron John Wagenius, who went by Kiberphant0m online. Prosecutors said he and others used Snowflake accounts that had exposed credentials and no multifactor authentication to steal AT&T's call and text metadata and data from Verizon's push-to-talk business and more than a dozen other telecom companies.[3] In October 2024 he publicly tried to extort victims, including by claiming to hold call logs of the President-elect and Vice President. For all of that, he made about $1,500 selling stolen data.[3]
Wagenius pleaded guilty to all counts in 2 federal indictments. On September 25, 2026, a judge sentenced him to 70 months in federal prison and ordered $294,978 in restitution.[3] While awaiting sentencing, according to the report, he broke federal prison computer rules by using other inmates' email accounts to ask AI tools about software vulnerabilities and ways to escape prison.[3] A third man living in Turkey has been charged but, as of that report, had not been convicted.[2][3]
Why a platform nobody broke into lost so much data
Trace the chain back. The call logs left because an account accepted a login. The login worked because the password was correct and nothing else was asked. The password was correct because it had been stolen by malware, often from a contractor's personal laptop, and never changed, sometimes for years. And the login came from wherever the criminals happened to be, because nothing limited where sign-ins could come from.[1]
Any one of Mandiant's 3 protections would have broken that chain. A second sign-in step would have stopped the stolen password on its own. Rotating passwords would have killed it before it reached a buyer. A list of allowed locations would have rejected logins from the attackers' servers.[1]
None of those protections is exotic or expensive. Customers could already switch them on in their own accounts. The gap was that they were optional, and busy teams left them off because everything seemed to work fine without them. A setting that is off by default tends to stay off until something goes wrong.[1]
The case also shows how far contractor risk reaches. The companies that lost data did not choose to install malware or download pirated games. Someone with access to their accounts did, on a machine nobody at the company was watching.[1]
Timeline
| Date | What happened |
|---|---|
| Nov 2020 | Earliest infostealer infection Mandiant linked to the campaign.[1] |
| Feb–Oct 2024 | Breaches of Snowflake customer accounts, per prosecutors.[2] |
| Apr 2024 | Mandiant receives intelligence about stolen database records.[1] |
| May 22, 2024 | Mandiant contacts Snowflake.[1] |
| May 30, 2024 | Snowflake publishes detection and hardening guidance.[1] |
| Jun 10, 2024 | Mandiant reports about 165 organizations notified.[1] |
| Oct 2024 | Soldier publicly extorts telecom victims.[3] |
| Nov 2024 | Canadian defendant arrested.[2] |
| Jul 2025 | He is extradited to the United States.[2] |
| Aug 2026 | He pleads guilty; sentencing set for Oct 27, 2026.[2] |
| Sep 25, 2026 | Soldier sentenced to 70 months in prison.[3] |
The missing control
The missing control: require a second sign-in factor on every cloud account, allow logins only from trusted networks, and change passwords on a schedule so a stolen one expires before it is used. Mandiant found all 3 missing in the accounts that were breached.[1]
- Make two-factor sign-in mandatory. In every cloud service your business uses, change the setting from optional to required for all users, including contractors and service accounts that people log in to.
- Restrict where logins can come from. Where a service allows it, limit admin and data-access logins to your office network or company VPN.
- Rotate passwords and remove stale accounts. Change shared and long-lived passwords at least yearly, and delete accounts belonging to people and contractors who no longer need them.
- Set rules for contractor devices. Require contractors who log in to your systems to use a work-only device with up-to-date security software, not a personal machine shared with games and downloads.
- Watch for your logins being sold. Use a breach-monitoring service or your security provider's alerts to learn when company email addresses show up in stolen-password dumps, and reset them immediately.
What it means now
The Snowflake campaign was one of the largest data thefts of its year, and it required no break-in at all. It ran on old passwords and optional settings.
For a small business, the takeaway is to look at your own cloud accounts, not your provider's reputation. If a password stolen from a contractor's laptop 4 years ago would still let someone in today, that is the gap to close first. Start with the accounts that hold customer data or move money, then work outward to everything else.
How the 2024 Snowflake breaches happened: old stolen passwords and no second lock: the case file and the Shorts from this case.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- All episodes
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.