Canadian Man Pleads Guilty in Snowflake Extortions
BLUF
A major Snowflake extortion ring operator has been convicted, highlighting ongoing risks in cloud data security.
NEWS
Connor Riley Moucka admitted guilt to conspiring to hack and extort more than 165 organizations utilizing Snowflake's cloud storage. Additionally, he confessed to stealing call and text history records belonging to over 100 million AT&T customers.
Why I Care
This case underscores the severe consequences of misconfigured cloud credentials and the scale of data exposure possible through third-party providers, affecting enterprises and millions of consumers alike.
Next Steps
Organizations using Snowflake should immediately audit MFA enforcement and credential management policies, while security teams must review historical access logs for unauthorized activity by end-of-quarter.
Source: Krebs on Security ·
