Canadian National Pleads Guilty After Stealing and Extorting Data from 150+ Snowflake Customers
What Happened — Connor Riley Moucka pleaded guilty to using stolen Snowflake login credentials to access and exfiltrate data from more than 150 customer accounts, then extorting three victims for a total of at least 36 BTC (≈ $3.4 M). The breach exposed billions of call‑detail records, banking, payroll, and government‑issued IDs across 165 organizations.
Why It Matters for Compliance & Audit Readiness
- Credential compromise is a core SOC 2 Access Control (CC6.1) failure; continuous monitoring of privileged access and MFA enforcement are required to demonstrate reasonable safeguards.
- The incident underscores the need for auditable evidence of credential rotation, login anomaly detection, and incident‑response readiness—key artifacts for a defensible SOC 2 audit.
Who Is Affected – Financial services, telecommunications, retail, entertainment, healthcare, and data‑storage firms that rely on Snowflake’s cloud data‑warehousing platform.
Recommended Actions –
- Verify that all Snowflake accounts enforce MFA and rotate service‑account credentials quarterly.
- Deploy real‑time login‑anomaly monitoring and integrate alerts into your SIEM for SOC 2 evidence collection.
- Review and tighten least‑privilege access policies for third‑party integrations.
- Document the incident‑response workflow and retain logs as audit artifacts.
Source: DataBreachToday
Technical Notes – Attack vector: stolen credentials (phishing or credential‑dumping). No public CVE; the breach involved terabytes of data, including call‑detail records, banking details, payroll, DEA registration numbers, driver’s licenses, passports, and SSNs.