26-year-old Canadian Connor Riley MouckaSnowflake cloud platform in 2024, impacting more than 165 organizations and exposing the personal data of at least 100 million people. The key attack vector was not an exploit or platform vulnerability, but old passwords stolen by info-stealer malware years earlier and never changed, combined with disabled multi-factor authentication.
Timeline and attack mechanism
The group that Mandiant tracks under the identifier UNC5537 operated in an extremely simple way. According to Mandiant’s investigation, every incident they studied was tied to credentials previously stolen by info-stealer malware. Some of these accounts had been compromised as far back as November 2020 and were still valid at the time of the attacks — almost four years later. At least 79.7% of the accounts used by the attackers had a documented history of credential exposure.
Mandiant described the campaign bluntly: “This is not the result of any particularly novel or sophisticated tool, technique, or procedure.” The scale of the attack was driven by two factors — the size of the info-stealer market and widespread neglect of password rotation. All compromised Snowflake instances examined by the researchers lacked configured network allow lists.
The stolen data included call and text message records (without content), payroll information, Drug Enforcement Administration (DEA) registration numbers, passport numbers, and Social Security numbers. AT&T confirmed in July 2024 that call and text message records for virtually all of its mobile subscribers for the period from May 1 to October 31, 2022, had been extracted from a company workspace on a third-party cloud platform.
Prosecution and defendants
Moucka personally received at least $495,000 from ransom payments and data sales. Prosecutors also stated that he extorted at least one victim a second time, threatening further disclosure of stolen data belonging to a public official and to family members of a former public official. FBI Special Agent Mike Herrington called this tactic “calculated and predatory.”
Sentencing is set for October 27. The aggravated identity theft charge carries a mandatory minimum of two years in prison, while the other charges carry up to 30 years. The combined direct losses of the victim companies exceeded $9.5 million, and this figure does not include the damage suffered by their own customers.
Notably, the Department of Justice, in neither the 2024 indictment nor the current announcement, named Snowflake explicitly, referring to the victim only as a “U.S.-based SaaS provider.” Snowflake and Mandiant themselves disclosed the platform’s name in 2024.
Of the three defendants, only Moucka is under U.S. jurisdiction. Co-defendant John Erin Binns, according to an August 4 court update, remains outside U.S. jurisdiction. Former U.S. Army soldier Cameron John Wagenius, whom prosecutors linked to the same intrusions, pleaded guilty in a related case in July 2025.
Discrepancies in the numbers
It is worth noting that the figure “165 organizations” has changed meaning over the course of the investigation. Initially, this was the number of organizations that Mandiant and Snowflake notified of potential compromise. Prosecutors are now using it to denote the customers that were actually hacked. At the same time, there is an internal discrepancy in the DOJ press release: the main text states “more than 165 organizations,” while the statement by Principal Deputy Assistant Attorney General A. Tysen Duva refers to “more than 150.”
Snowflake’s response and remaining gaps
Snowflake enabled MFA by default for accounts created since October 2024. However, password-only logins have not been fully eliminated. According to Snowflake’s documentation, the final phase of disabling password authentication as the sole factor for all remaining users and service accounts is scheduled for the period from August to October 2026 and will be rolled out in stages. Reader and trial accounts are excluded from this process.
This means that for more than another year, existing Snowflake accounts may potentially remain vulnerable to similar attacks unless their administrators take proactive steps.
Practical recommendations
- Enable MFA immediately on all Snowflake accounts and any other cloud services where it is not yet enabled. Do not wait for the enforced rollout in 2026.
- Audit your credentials — check whether corporate logins and passwords appear in known breaches (via Have I Been Pwned or similar services). Force a reset of all passwords that have not been changed for more than 90 days.
- Configure network allow lists to restrict access to cloud instances only from trusted IP addresses.
- Implement info-stealer monitoring — track the appearance of corporate credentials on underground markets and in info-stealer logs. Integration with Threat Intelligence platforms allows you to detect compromise before an attacker uses the data.
- Revisit service account access policies — these accounts often operate without MFA and with non-rotated passwords. Use tokens or certificates instead of static passwords.
The UNC5537 case is a clear demonstration that the most destructive attacks do not require zero-days or complex exploits. All it takes is a password stolen four years ago and the absence of a second authentication factor. Organizations using Snowflake or any other cloud platform with password-based access should immediately enforce MFA, rotate all credentials, and set up network restrictions — every day of delay leaves open the same attack vector that has already cost 165 companies millions of dollars and exposed the data of 100 million people.