Last Update: 09/19/2026 at 11:33 PM EST

Snowflake Credentials Breach 165 Companies

Coverage from STL.News, Rescana, and others

Snowflake Credentials Breach 165 Companies topic image

A 2024 campaign used credentials stolen from customer-managed devices to access at least 165 organizations using Snowflake-hosted environments, exposing billions of records and data involving more than 100 million people.

Connor Riley Moucka pleaded guilty in the United States, while investigations and civil claims continue. The incidents also highlighted risks from password-only access, stale credentials, limited tenant logging, and unrestricted login locations, prompting stronger authentication requirements and scrutiny of customer and platform security responsibilities.

Looking Back
20 Day Timeline
Aug 5Aug 9Aug 13Aug 15Aug 19Aug 23
History
08/24/2026

The story is now framed less as a breach of Snowflake itself and more as a large-scale abuse of weak customer access controls, with Mandiant finding no evidence of compromise of Snowflake’s core systems. The reported scale has increased to billions of records, while civil claims and remediation efforts continue.

All Articles9 articles
Additional9 articles · CI Score below 45
STL.News
8/9/2026 • Data Breaches & Exposure Events • General
Rescana
8/6/2026 • Data Breaches & Exposure Events • General
Christensen Group
8/24/2026 • Data Breaches & Exposure Events • General
TechCrunch
8/6/2026 • Data Breaches & Exposure Events • General
CSO Online / Maxwell Cooter
8/7/2026 • Data Breaches & Exposure Events • General
American Banker / Carter Pape
8/12/2026 • Data Breaches & Exposure Events • General
BleepingComputer / Ionut Ilascu
8/5/2026 • Data Breaches & Exposure Events • General
The Record / Jonathan Greig
8/5/2026 • Data Breaches & Exposure Events • General
MyNorthwest
8/5/2026 • Data Breaches & Exposure Events • General