The images in this article were generated with artificial intelligence. How we publish
The criminal repentance of Connor Riley Moulka in Seattle for his role in intrusions on Snowflake's client accounts is, in criminal terms, a partial closure: an accused pleaded guilty to computer fraud, electronic fraud, aggravated identity theft and related conspiracy, and faces severe penalties that include mandatory minimum and up to decades of imprisonment. But at the technical and risk management level, the case leaves a much harder lesson: there was no sophisticated explosion or intrinsic failure of the platform; what allowed access were old credentials stolen by infostealer type and never rotated, with multi-factor authentication (MFA) disabled. Mandiant's investigation (actor traced as UNC5537) and public confirmations show that many of these credentials were captured years ago and remained valid, allowing for commitments in at least 165 organizations and data exposure of more than 100 million people.
That the vector was so prosaic doesn't make it less serious. On the contrary: it reveals a systemic failure of digital hygiene and governance in the management of identities and access. When a large proportion of accounts used as pivot had a history of exposure and no lists of allowed on the network were applied, the attacker needed only to buy or use filtered credentials in an infostealers market to move. The result was economic and human: direct losses over $9.5 million for the companies concerned, leaks of call and text records, payroll data, DEA registration numbers, passports and social security numbers, as well as reextortion attempts directed at individuals identified in the stolen data.

This incident clarifies two frequent discussions on cloud safety. First, shared responsibility is not a mantra: it is practical. Cloud service providers may be technically safe, but if customers do not manage credentials, do not rotate secrets and do not force MFA, the risk persists. Second, safety is not improved only with new tools: basic credentials management, periodic rotation, closure of obsolete access and universal application of MFA are high-impact measures. Snowflake has begun to tighten its policies, requiring MFA by default in human accounts created since October 2024 and planning to block the exclusive use of passwords gradually until 2026, but the exceptions and long deadlines leave risk windows that the attackers exploit.
For organizations and technical officials who want to turn this warning into concrete actions, the immediate priority is to reduce the area that allowed the case. Implement and force MFA without exception for all human accounts and, where possible, for service accounts; prohibit single password login and migrate to more resistant factors such as FIDO keys or passwords; rotate passwords and secrets automatically and frequently, especially after incidents or signs of exposure; detect and block committed credentials using filter feeds and account intelligence services. In addition, close access to critical instances by applying network-allowed and segmentation lists, minimize the volume of sensitive data stored in shared environments and use field tokenization or encryption when feasible.
Recommendations for technical controls should be complemented by governance. Inventory accounts and privileges, conduct risk analysis and tabletop exercises on extortion or data leakage, implement abnormal use monitoring and response to playbooks incidents that include reporting to affected and cooperation with authorities. It is also relevant to review contracts with suppliers and to require transparency in security controls and response plans, because trust in a supplier does not replace the customer's operational responsibility.

This case also has a human and regulatory dimension: the sale and resale of credentials in illicit markets and the reextortion of individual victims underline the need for protection for people whose lives are exposed. The companies concerned should provide mitigation support to those who see personal data being compromised, and regulators are increasingly attentive to organizations demonstrating proactive measures. Criminal action against operators such as Moulka may have a deterrent impact, but it does not prevent the constant emergence of new collections of credentials if practices are not fixed at an operational level.
To read the Department of Justice's statement on guilt and charges, please refer to the official note by the DOJ on https: / / www.justice.gov / opa / pr /..., and to understand MFA's implementation recommendations and its nuances in Snowflake, official documentation is a direct resource in https: / / docs.snowflake.com / en / user-guide / security-mfa.html. It is also appropriate to review the technical analysis and warning of response to incidents published by threat response firms to learn how these accesses were detected and mitigated.
In short, the story is not that the cloud was insecure by default, but that the stolen credentials and the lack of basic practices remained the preferred back door by economically motivated attackers. The priority for any organization that uses cloud services should be to treat that door as the most critical vulnerability: to close it through strict identity policies, access control and continuous monitoring before the next wave of old credentials reappears in an illicit market.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...