Threat Intelligence

Hacker Pleads Guilty in Massive Data Breach Affecting 100 Million People

The Hacker News · 6 Aug 2026
Key Takeaway Enable multi-factor authentication on all cloud service accounts to prevent attackers from exploiting weak login credentials, even when the platform provider's own security is strong.

Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty in a Seattle federal court to computer fraud, wire fraud, aggravated identity theft, and related conspiracy charges. The charges stem from a wave of 2024 breaches targeting customer accounts on the Snowflake cloud data platform, which affected at least 165 organisations and exposed the personal records of an estimated 100 million people.

According to court proceedings, Moucka personally profited by at least $495,000 from the scheme. While Snowflake itself was not directly breached, attackers exploited weak security practices in customer accounts—such as missing multi-factor authentication—to gain unauthorised access to sensitive data stored on the platform.

This case highlights how cloud platform breaches often stem not from flaws in the platform itself, but from gaps in how customer organisations configure and secure their own accounts. For Australian small businesses using cloud data services, this is a reminder that shared responsibility for security extends to every account and login your business controls.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.