Canadian Man Pleads Guilty After Stealing Data from 165 Snowflake Customers via MFA‑less Account Compromise
What Happened — A 26‑year‑old Canadian, Connor Riley Moucka, pleaded guilty to four counts—including computer fraud and aggravated identity theft—for accessing Snowflake cloud accounts that lacked multi‑factor authentication (MFA). Using credentials harvested by infostealer malware, he and an accomplice exfiltrated terabytes of data from at least 165 organizations and extorted millions of dollars.
Why It Matters for Compliance & Audit Readiness
- The incident exemplifies a classic SOC 2 CC6.1 (Logical Access) failure: accounts without MFA were compromised with only username/password. Continuous monitoring of access controls and MFA enforcement are core audit evidence.
- Demonstrates the need for documented access‑control policies, periodic MFA compliance checks, and incident‑response evidence that can be presented during a SOC 2 audit.
Who Is Affected – Technology / SaaS providers (Snowflake customers), financial services, retail, education, and government agencies that stored PII, payroll, and other sensitive data in Snowflake.
Recommended Actions –
- Enforce MFA on all privileged and non‑privileged Snowflake accounts immediately.
- Conduct a SOC 2 CC6.1 control gap analysis, map MFA enforcement to your audit readiness, and collect log evidence for continuous compliance.
- Review and remediate any legacy credentials; rotate passwords and implement credential‑vaulting where possible.
Source: BleepingComputer
Technical Notes – Attack vector: stolen credentials via infostealer malware; no MFA enabled on targeted Snowflake accounts. Data exfiltrated included call/text metadata, banking details, payroll records, DEA registration numbers, driver’s license, passport, SSN, and other PII. Source: [BleepingComputer]