Hacker Pleads Guilty After Stealing Data from 165+ Snowflake Customer Accounts
What Happened — Connor Riley Moucka (aka “Waifu”) used stolen credentials to infiltrate Snowflake’s cloud‑data platform, exfiltrating terabytes of sensitive information from more than 165 organizations between April and September 2024. He and co‑conspirators extorted victims for over $2.5 M and advertised the data for sale.
Why It Matters for Compliance & Audit Readiness
- The incident exemplifies a failure of credential‑management and access‑control safeguards that SOC 2 CC6.1 (Logical Access) is designed to address.
- Continuous monitoring of privileged‑account activity and immutable audit logs provides the evidence needed to demonstrate effective access‑control governance during a SOC 2 audit.
Who Is Affected – Cloud‑SaaS providers, their enterprise customers in finance, telecom, retail, and health‑care sectors.
Recommended Actions – Review and tighten IAM policies; enforce MFA for all privileged accounts; implement real‑time log aggregation and anomaly detection; map these controls to SOC 2 CC6.1 and retain evidence in a tamper‑proof repository. Source: Help Net Security
Technical Notes – Attack vector: stolen credentials (phishing or credential‑dump sources). Data exfiltrated: PII (SSNs, passports, driver’s licenses), financial records, DEA registration numbers, call/text logs. Source: same article