Snowflake Credentials Breach 165 Companies
Coverage from STL.News, Rescana, and others

A 2024 campaign used credentials stolen from customer-managed devices to access at least 165 organizations using Snowflake-hosted environments, exposing billions of records and data involving more than 100 million people.
Connor Riley Moucka pleaded guilty in the United States, while investigations and civil claims continue. The incidents also highlighted risks from password-only access, stale credentials, limited tenant logging, and unrestricted login locations, prompting stronger authentication requirements and scrutiny of customer and platform security responsibilities.
The story is now framed less as a breach of Snowflake itself and more as a large-scale abuse of weak customer access controls, with Mandiant finding no evidence of compromise of Snowflake’s core systems. The reported scale has increased to billions of records, while civil claims and remediation efforts continue.
