HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Canadian Man Pleads Guilty After Stealing Data from 165 Snowflake Customers via MFA‑less Account Compromise

A Canadian citizen admitted to accessing Snowflake accounts without MFA, stealing data from at least 165 organizations and extorting millions. The breach highlights the importance of robust access‑control policies and continuous SOC 2 evidence collection for MFA enforcement.

LiveThreat™ Intelligence · 📅 August 06, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
4 recommended
📰
Source
bleepingcomputer.com

Canadian Man Pleads Guilty After Stealing Data from 165 Snowflake Customers via MFA‑less Account Compromise

What Happened — A 26‑year‑old Canadian, Connor Riley Moucka, pleaded guilty to four counts—including computer fraud and aggravated identity theft—for accessing Snowflake cloud accounts that lacked multi‑factor authentication (MFA). Using credentials harvested by infostealer malware, he and an accomplice exfiltrated terabytes of data from at least 165 organizations and extorted millions of dollars.

Why It Matters for Compliance & Audit Readiness

  • The incident exemplifies a classic SOC 2 CC6.1 (Logical Access) failure: accounts without MFA were compromised with only username/password. Continuous monitoring of access controls and MFA enforcement are core audit evidence.
  • Demonstrates the need for documented access‑control policies, periodic MFA compliance checks, and incident‑response evidence that can be presented during a SOC 2 audit.

Who Is Affected – Technology / SaaS providers (Snowflake customers), financial services, retail, education, and government agencies that stored PII, payroll, and other sensitive data in Snowflake.

Recommended Actions

  • Enforce MFA on all privileged and non‑privileged Snowflake accounts immediately.
  • Conduct a SOC 2 CC6.1 control gap analysis, map MFA enforcement to your audit readiness, and collect log evidence for continuous compliance.
  • Review and remediate any legacy credentials; rotate passwords and implement credential‑vaulting where possible.

Source: BleepingComputer

Technical Notes – Attack vector: stolen credentials via infostealer malware; no MFA enabled on targeted Snowflake accounts. Data exfiltrated included call/text metadata, banking details, payroll records, DEA registration numbers, driver’s license, passport, SSN, and other PII. Source: [BleepingComputer]

📰 Original Source
https://www.bleepingcomputer.com/news/security/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →