Canadian Man Pleads Guilty in Snowflake Extortions – Krebs on Security

August 6, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: krebsonsecurity.com

Threat Risk: High
Victim: Enterprise users of cloud data platforms
Incident: A large-scale extortion campaign targeting Snowflake customers via stolen credentials.
Impact: Theft of billions of sensitive records and over $2.5 million in ransom payments.
Attacker: Connor Riley Moucka (aka Judische, Waifu)
Analysis: The attacker exploited the absence of multi-factor authentication (MFA) to leverage stolen credentials across numerous Snowflake customer accounts. This allowed for the exfiltration of billions of records, including PII and financial data, across multiple high-profile industries. The campaign underscores a persistent vulnerability in SaaS environments where legacy authentication methods are still permitted.
Recommendations: Enforce mandatory multi-factor authentication (MFA) for all cloud service and SaaS accounts.; Implement strict password complexity requirements and monitoring for credential stuffing.; Audit cloud access logs for anomalous data egress or unauthorized login locations.
Source: Krebs on Security

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *