Stolen Snowflake Credentials Enable Breach of 165 Companies, Exposing Millions of Records
What Happened — A Canadian national, Connor Riley Moucka, pleaded guilty to using stolen Snowflake login credentials to infiltrate the accounts of at least 165 organizations between February and October 2024. The attackers exfiltrated billions of files—including call logs, ticketing data, financial records, and government IDs—and attempted extortion for a total of roughly $2.5 million.
Why It Matters for Compliance & Audit Readiness
- Credential theft bypasses the logical‑access controls that SOC 2’s CC6.1 (Logical Access) expects organizations to enforce and continuously monitor.
- The scale of data exposure underscores the need for auditable evidence that privileged accounts are protected, rotated, and reviewed in real time.
- Demonstrating that you have a continuous‑monitoring pipeline for credential use directly supports the “monitoring” criteria of SOC 2 and provides defensible proof during an audit.
Who Is Affected — Telecommunications, ticketing, automotive parts, education, luxury retail, banking, and other sectors that store data in Snowflake’s cloud data‑warehouse platform.
Recommended Actions
- Enforce MFA and password‑less authentication for all Snowflake accounts, especially privileged roles.
- Implement automated credential‑rotation and real‑time access‑log monitoring to detect anomalous logins.
- Map these controls to SOC 2 CC6.1 and retain continuous evidence for audit readiness.
Source: The Record
Technical Notes
- Attack vector: stolen, still‑valid Snowflake credentials dating back to 2020.
- Data types exfiltrated: call‑detail records, ticketing user data, banking records, DEA registration numbers, driver’s‑license numbers, passports, SSNs, etc.
- No platform‑level vulnerability was identified; the breach stemmed from credential compromise.
Source: The Record