Snowflake Data Breach Hacker Pleads Guilty: What Organizations Must Learn from the $9.5M Attack

The conviction of Connor Riley Moucka exposes critical gaps in cloud data security that every IT team and privacy professional must urgently address

Snowflake Data Breach Hacker Pleads Guilty: What Organizations Must Learn from the $9.5M Attack

Snowflake Data Breach Hacker Faces Over 30 Years After Guilty Plea

The Snowflake data breach hacker at the center of one of the most damaging cloud security incidents in recent memory has pleaded guilty in a United States federal court. Connor Riley Moucka, 26, admitted to his role in a sweeping cybercrime campaign that compromised the Snowflake cloud data accounts of 165 organizations, exposing billions of sensitive records and triggering more than $9.5 million in confirmed losses — not counting the financial and reputational damage suffered by the estimated 100 million or more customers whose personal data was stolen.

Moucka pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy charges. He faces a potential sentence exceeding 30 years in prison, with sentencing currently scheduled for October 27. The case is a watershed moment for cloud infrastructure security, data sovereignty advocates, and privacy professionals across Europe and beyond — not just because of its scale, but because of its profound simplicity: the hackers didn't exploit a zero-day vulnerability in Snowflake's platform. They simply used stolen login credentials.

Moucka was arrested in Canada in late 2024 and was extradited to the United States in July 2025. He had been reported in early news coverage under the name Alexander 'Connor' Moucka.

How the UNC5537 Threat Group Exploited Cloud Credential Theft

Hacker working on cybercrime at a computer terminal
The Snowflake breach was driven by credential theft rather than a platform vulnerability — a reminder that authentication hygiene remains a frontline defense.

According to the U.S. Department of Justice, Moucka was operating as part of a threat actor group tracked under the designation UNC5537 — a financially motivated cybercrime collective that targeted companies storing large volumes of data in Snowflake's cloud environment. Rather than breaking through technical defenses, the group leveraged a tried-and-true method: stolen or purchased login credentials, often sourced from infostealer malware campaigns, to gain direct access to victim accounts.

The list of impacted organizations reads like a who's-who of global enterprise: AT&T, Ticketmaster, Santander Bank, Advance Auto Parts, Neiman Marcus, Anheuser-Busch, Allstate, Mitsubishi, Progressive, and State Farm were all named as victims. These are not small organizations. They are companies with large, sophisticated IT teams — yet their Snowflake environments were accessible via valid credentials, often without mandatory multi-factor authentication (MFA) enforcement.

Once inside, UNC5537 harvested billions of records containing personal identifiers, financial information, and account data. The group then pursued a dual monetization strategy: extorting victims directly for ransom while simultaneously listing stolen datasets for sale on dark web hacking forums. According to DOJ filings, Moucka personally obtained approximately $500,000 from selling stolen data, while total ransom payments across the campaign reached $2.5 million.

"When attackers don't need to break down the door because someone left the key under the mat, the entire conversation about enterprise security has to change. Credential hygiene and MFA enforcement are not optional extras — they are the baseline."

— Cybersecurity analyst commentary on the UNC5537 campaign methodology

Investigators also noted that a former U.S. Army soldier, who had previously pleaded guilty approximately one year ago to separate hacking charges involving AT&T and Verizon systems, is believed to have participated in the Snowflake campaign as well — suggesting the group had broad operational reach and diverse membership.

Billions of Records, Millions in Losses: The True Cost of the Breach

165Organizations compromised
$9.5M+Corporate losses (excl. customer damages)
100M+Individuals potentially affected
$2.5MRansom payments received

The scale of the Snowflake breach is staggering not just in raw numbers, but in what those numbers represent. The DOJ confirmed that companies directly suffered losses exceeding $9.5 million — but that figure explicitly excludes the personal financial harm experienced by the estimated 100 million or more individuals whose data was stolen. When factoring in identity fraud, credit monitoring costs, regulatory fines, and legal proceedings that often follow large-scale breaches, the true societal cost climbs far higher.

For European businesses and privacy professionals, the implications are particularly sharp. Under the General Data Protection Regulation (GDPR), organizations that process the personal data of EU residents — regardless of where the company is based — are required to report a data breach to the relevant supervisory authority within 72 hours of becoming aware of it, and in many cases must notify affected individuals directly. Companies caught in an incident of this magnitude who failed to follow GDPR breach notification protocols face fines of up to €20 million or 4% of global annual turnover, whichever is higher.

As reported by SecurityWeek, the DOJ's case against Moucka represents one of the most consequential cloud-related prosecutions to date, underscoring that criminal accountability is catching up with the speed of cybercrime — but corporate compliance cannot wait for law enforcement to act.

What the Snowflake Breach Reveals About Cloud Storage Security Gaps

Security researchers and cloud architects have pointed out a fundamental issue exposed by the UNC5537 campaign: cloud platforms like Snowflake do not inherently enforce multi-factor authentication. According to Mandiant's threat intelligence reporting on the campaign, many of the compromised accounts lacked MFA entirely, and the credentials used to access them had often been sitting in infostealer logs for months before being weaponized. The breach was not a failure of Snowflake's infrastructure per se — it was a failure of how organizations configured and managed access to their cloud environments.

This is a nuance that matters enormously for IT decision-makers, small business owners, and entrepreneurs who rely on cloud data warehouses and storage solutions. The responsibility model in cloud computing — often described as "shared responsibility" — means the platform provider secures the infrastructure, while the customer is accountable for identity, access management, and data governance. As Cloudflare's documentation on the shared responsibility model explains, misunderstanding where that boundary lies is one of the most common and dangerous mistakes enterprises make.

Digital cloud infrastructure security visualization
Cloud infrastructure security depends as much on customer access controls as it does on platform-level protections — a distinction many organizations still overlook.

For organizations operating under data sovereignty frameworks — increasingly common across Europe as businesses seek to comply with GDPR and reduce dependence on U.S.-based hyperscalers — the Snowflake case reinforces why data residency alone is not enough. Where your data lives matters. But so does who can access it, under what authentication conditions, and with what monitoring in place.

Security Control Status in UNC5537 Victims Recommended Practice
Multi-Factor Authentication (MFA) Frequently absent or not enforced Mandatory for all cloud data accounts
Credential Monitoring Stolen credentials went undetected Monitor dark web and infostealer feeds
Access Logging & Anomaly Detection Insufficient alerting on unusual access Implement SIEM with behavioral baselines
GDPR Breach Notification Varies by jurisdiction and awareness 72-hour reporting obligation under GDPR
Data Minimization Excessive data stored in cloud Only retain what is necessary under GDPR Art. 5

Why This Case Should Prompt a Cloud Security Audit Across European Businesses

For privacy professionals and compliance officers operating within the EU regulatory framework, the Snowflake breach offers a sobering case study. Several of the affected organizations — including Santander Bank and Ticketmaster's parent company — have operations that directly touch European customers, triggering GDPR obligations. The breach underscored that even if an organization's own infrastructure is secure, third-party cloud environments used to store or process personal data represent a significant risk surface.

Under GDPR Article 28, organizations are required to conduct due diligence on data processors — including cloud providers — and ensure that appropriate data processing agreements are in place. This includes verifying that security controls meet an adequate standard. The UNC5537 campaign demonstrated that contractual assurances on paper must be matched with technical verification in practice. As the European Data Protection Board (EDPB) has reiterated in multiple guidance documents, accountability under GDPR is not delegated to a cloud vendor — it remains with the data controller.

The case is also likely to fuel ongoing debates around digital sovereignty and the desirability of European-hosted cloud alternatives. Organizations looking to reduce their exposure to U.S. jurisdiction — and to incidents involving U.S.-headquartered platforms — have a growing ecosystem of European cloud providers to consider. Platforms certified under frameworks like Gaia-X or compliant with emerging European cloud certification schemes (EUCS) offer an alternative path, though they too require rigorous access control discipline to be genuinely secure.

Key security controls adoption among cloud enterprise customers (estimated)

MFA Enforcement
Originally reported by RSS App New Cybersecurity Feed. Summarised and curated by European Purpose.