# He Didn't Hack Anything. He Just Logged In.


The Snowflake credential-theft campaign closes its first chapter — and the real story isn't the arrest.


---


## One Button They Never Clicked


Connor Riley Moucka didn't exploit a zero-day. He didn't pivot through corporate networks or write novel malware. Between February and October 2024, the 26-year-old Canadian — known online as Waifu — did something far simpler and, in retrospect, far more embarrassing for his victims: he bought stolen credentials harvested by infostealer malware, typed them into Snowflake's login page, and walked straight in.


No multi-factor authentication blocked his path. No anomaly detection flagged the logins. At 165 organizations — including AT&T, Ticketmaster, and Santander — the login screen accepted valid usernames and passwords as sufficient proof of identity. That was enough to hand over call records, Social Security numbers, passport numbers, DEA registration numbers, payroll data, and financial records belonging to more than 100 million people.


On August 5, 2026, Moucka pleaded guilty in U.S. federal court to four counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. He faces a maximum of 32 years when sentenced October 27. His co-conspirator, John Erin Binns, was arrested in Turkey, where extradition proceedings have been contested.


The Department of Justice puts victim losses at more than $9.5 million. The actual cost — in breach notifications, credit monitoring, regulatory scrutiny, and reputational damage across a who's-who of corporate America — runs orders of magnitude higher than that figure suggests.


---


## The Infostealer Pipeline Nobody Wants to Talk About


Moucka and Binns didn't generate the credentials themselves. The logins came from infostealer malware — Redline, Raccoon, Vidar, and their successors — which silently vacuum credentials from infected machines and sell them in bulk on criminal markets. This is a flourishing, industrialized supply chain operating largely in plain sight. For a few hundred dollars, a threat actor can purchase tens of thousands of credential sets tied to specific services, corporate environments, or geographies.


The Snowflake campaign followed the playbook precisely. Buy the logs. Filter for Snowflake. Test at scale. Login. Extract. Extort.


What made this campaign exceptionally damaging wasn't technical sophistication — it was the quality of the target. Snowflake sits at the center of modern data infrastructure. Organizations store their most sensitive consolidated datasets there: CRM exports, financial records, telecom metadata, HR databases. When a threat actor gains access to a Snowflake tenant, they're not getting one application's data. They're getting the data warehouse.


Moucka's team used custom software to systematically map each compromised environment — identifying organization names, user roles, IP addresses — before deciding what was worth stealing and what was worth selling. This wasn't smash-and-grab. It was methodical enterprise reconnaissance.


---


## Re-Extortion: The Threat Doesn't End with the Ransom


The most disturbing detail buried in court documents isn't the scale. It's the re-extortion.


After receiving payment, Moucka didn't stop. In at least one case, he went back to a victim and threatened further disclosure of already-stolen data. Worse, he specifically leveraged stolen information belonging to a government official and that official's immediate family members to apply pressure.


This matters beyond the courtroom. It directly contradicts the implicit assumption many organizations make when they pay a ransom or comply with extortion demands: that payment ends the exposure. It doesn't. Once data is exfiltrated, the extortionist holds leverage indefinitely. A second payment buys silence, not deletion.


Moucka also advertised stolen data on hacker forums, pulling in roughly $495,000 from buyers while simultaneously extorting victims with the same data. The victims weren't just paying to suppress exposure — they were funding a market where competitors, nation-states, or other criminal actors could purchase the same records regardless of what the original victim paid.


---


## What Snowflake Did — and When


Snowflake's response is worth examining carefully. After the campaign became public in mid-2024, the company announced it would enforce MFA and require passwords of at least 14 characters.


That's the right policy. It should have been the default from the start.


The attacks ran for eight months before the scope became clear. During that window, Snowflake's platform functioned as designed — authenticated users accessed their data. The security failure wasn't Snowflake's authentication architecture; it was the complete absence of mandatory MFA across a platform holding extraordinarily sensitive enterprise data.


The enforcement came after AT&T, Ticketmaster, Neiman Marcus, Advance Auto Parts, and six other named organizations were breached. After 100 million individuals had their data stolen. After $9.5 million in direct losses were tallied. Platform-level MFA enforcement retroactively protecting accounts is useful. Platform-level MFA enforcement as an opt-in feature for cloud storage holding enterprise data is a product decision that aged very badly.


---


## HackWire Analysis


The Snowflake campaign should force a reckoning with how the security industry thinks about third-party cloud risk — specifically the gap between what organizations assume their cloud providers enforce and what those providers actually require.


For years, security teams have focused heavily on perimeter defense, endpoint detection, and internal network segmentation. The infostealer-to-cloud-takeover pipeline sidesteps most of that investment entirely. Credentials get stolen from an employee's personal laptop, or a contractor's machine outside the corporate MDM envelope, and then used to authenticate directly to a SaaS platform. The corporate firewall never saw the login. The EDR had no visibility. The SIEM logged a clean authentication event.


What makes this campaign a bellwether rather than an anomaly is the infrastructure underpinning it. Infostealer operations are running at industrial scale, with credential markets updating in near real-time. Threat actors don't need to target your organization specifically — they purchase a filter and see who shows up. The targeting is the stolen dataset, not the attacker's reconnaissance.


The Ticketmaster breach alone exposed data on 560 million customers. AT&T's stolen call records affected virtually all of its wireless subscribers. These aren't contained incidents. They're systemic failures with cascading exposure.


For defenders, the priority hierarchy is clear: audit every SaaS platform your organization connects data to, verify MFA is enforced (not just available), and build a detection strategy around credential abuse from external sources — not just network anomalies. Infostealer logs containing your employees' corporate credentials are almost certainly on sale somewhere right now. The question is whether your authentication layer requires anything harder to steal than a password.


Moucka faces sentencing in October. Binns's extradition remains uncertain. The playbook they used will outlast both of them.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)