Executive Summary
Between February and October 2024, Connor Riley Moucka, a 26-year-old Canadian, orchestrated unauthorized access to at least 165 organizations utilizing Snowflake's cloud data services. Exploiting stolen credentials from accounts lacking multi-factor authentication, Moucka and his co-conspirators exfiltrated sensitive data, including personal information and call records of over 100 million AT&T customers. The stolen data was used to extort victims by threatening public disclosure.
This incident underscores the critical importance of implementing robust security measures, such as multi-factor authentication, to protect cloud-based data. Organizations must remain vigilant against credential-based attacks, as threat actors continue to exploit such vulnerabilities for financial gain and data theft.
Why This Matters Now
The Snowflake data breach highlights the escalating threat of credential-based attacks on cloud services. As organizations increasingly migrate to cloud platforms, ensuring stringent access controls and authentication mechanisms is imperative to safeguard sensitive information from malicious actors.
Attack Path Analysis
Attackers used stolen credentials to access Snowflake customer accounts lacking multi-factor authentication, enabling unauthorized data access. They escalated privileges within these accounts to gain broader access. Moving laterally, they accessed additional data repositories and systems. Established command and control channels facilitated data exfiltration. Sensitive data was exfiltrated to external servers. The stolen data was used to extort victims, threatening public disclosure.
Kill Chain Progression
Initial Compromise
Description
Attackers used stolen credentials to access Snowflake customer accounts lacking multi-factor authentication.
MITRE ATT&CK® Techniques
Valid Accounts
Brute Force
Data from Cloud Storage
Exfiltration Over Web Service
Data Encrypted for Impact
Inhibit System Recovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-Factor Authentication
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA ZTMM 2.0 – Enforce Strong Authentication
Control ID: Identity and Access Management
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
AT&T and Verizon customer data breaches expose massive call/text records, requiring enhanced multi-factor authentication and encrypted traffic controls to prevent exfiltration.
Financial Services
Banking and financial information theft through cloud platforms demonstrates critical need for zero trust segmentation and egress security controls.
Information Technology/IT
Snowflake SaaS platform targeting reveals cloud security vulnerabilities, demanding multicloud visibility controls and threat detection capabilities for service providers.
Entertainment/Movie Production
TicketMaster breach illustrates entertainment sector exposure to credential-based attacks, requiring kubernetes security and anomaly detection for customer data protection.
Sources
- Canadian Man Pleads Guilty in Snowflake Extortionshttps://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/Verified
- Snowflake: No evidence of platform breachhttps://www.techtarget.com/searchsecurity/news/366587555/Snowflake-No-evidence-of-platform-breachVerified
- Snowflake 2024 Data Breach: 165 Companies Hit (Not Snowflake)https://databreachcost.com/case/snowflake-2024Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF would likely have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not prevent initial unauthorized access due to credential theft, it would likely limit the attacker's ability to exploit this access further.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by enforcing strict access controls and segmentation.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely limit the attacker's ability to move laterally by enforcing strict segmentation and monitoring.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely limit the attacker's ability to establish command and control channels by monitoring and controlling outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit the attacker's ability to exfiltrate data by enforcing strict egress policies.
While Aviatrix CNSF may not prevent the initial data theft, it would likely limit the scope of data accessible to attackers, thereby reducing potential impact.
Impact at a Glance
Affected Business Functions
- Customer Data Management
- Financial Transactions
- Communication Services
Estimated downtime: N/A
Estimated loss: $2,500,000
Personal Identifiable Information (PII) of over 100 million AT&T customers, including call and text history records; sensitive data from 165 organizations using Snowflake, encompassing banking information, payroll records, DEA registration numbers, driver's license numbers, passport numbers, and social security numbers.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce multi-factor authentication (MFA) across all user accounts to prevent unauthorized access.
- • Implement Zero Trust Segmentation to limit lateral movement within the network.
- • Utilize East-West Traffic Security to monitor and control internal traffic flows.
- • Deploy Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Establish Threat Detection & Anomaly Response mechanisms to identify and respond to suspicious activities promptly.



