Skip to main content

Snowflake Hacker Pleads Guilty: Analyzing the UNC5537 Data Breach

4 min read Runtime Rebel Intel
Primary source: securityweek.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • A major data breach campaign compromised 165 organizations and over 100 million individuals via Snowflake accounts.
  • Affected systems included Snowflake data storage accessed through stolen login credentials.
  • Organizations must immediately enhance access controls, implement MFA, and monitor for unauthorized access.

Advertisement

Overview of the Snowflake Data Breach and Guilty Plea

Connor Riley Moucka has pleaded guilty to multiple charges, including computer fraud, wire fraud, and aggravated identity theft, for his involvement in a significant cybercrime campaign. This operation, attributed to the threat actor tracked as UNC5537, targeted and compromised the Snowflake data storage accounts of 165 organizations. The extensive breach resulted in the theft of billions of sensitive data records, encompassing personal and financial information, and led to millions in ransom payments and financial losses for affected companies and their customers, as reported by SecurityWeek.

Moucka, arrested in Canada in late 2024 and extradited to the United States in July 2025, faces a potential sentence of over 30 years in prison. His guilty plea sheds further light on the tactics employed by UNC5537 and the far-reaching impact of this sophisticated cyber-attack.

UNC5537 Cybercrime Campaign Analysis: Tactics and Impact

The UNC5537 campaign primarily leveraged stolen login credentials to gain unauthorized access to data stored in Snowflake accounts. This method underscores the persistent threat posed by credential theft and the critical importance of strong identity and access management practices.

The scale of the attack was substantial, impacting prominent organizations across various sectors, including AT&T, Advance Auto Parts, Ticketmaster, Santander Bank, Neiman Marcus, Anheuser-Busch, Allstate, Mitsubishi, Progressive, and State Farm. The attackers not only extorted victims, receiving $2.5 million in ransom payments, but also profited by selling the stolen data on hacking forums, with Moucka personally gaining half a million dollars from these illicit sales. The U.S. Department of Justice (DOJ) estimates that targeted companies incurred losses exceeding $9.5 million, a figure that does not account for the extensive losses experienced by their customers—totaling at least 100 million individuals.

This incident highlights how critical data held in cloud data warehousing solutions like Snowflake can become a high-value target for cybercriminals. The use of pre-existing stolen credentials indicates a potential failure in applying strong authentication measures or detecting suspicious login attempts early. Another individual, a former US soldier who previously pleaded guilty to hacking AT&T and Verizon, is also believed to have participated in this widespread Snowflake campaign, suggesting a collaborative effort among cybercriminals.

Protecting Snowflake Accounts from Credential Theft: Actionable Recommendations

For security professionals seeking to protect their organizations against similar attacks, understanding and mitigating the methods used in the UNC5537 campaign is paramount. The primary vector of compromise—stolen login credentials—points directly to several key areas for immediate action:

  • Enforce Multi-Factor Authentication (MFA): MFA is the single most effective control against credential theft. Organizations using Snowflake should ensure that MFA is mandated for all user accounts, especially those with administrative or elevated privileges.
  • Strong Credential Management: Implement and enforce policies for strong, unique passwords. Regularly rotate credentials for service accounts and monitor for compromised credentials via dark web monitoring or breach notification services.
  • Access Control and Least Privilege: Review and tighten access controls within Snowflake. Ensure users and applications only have the minimum necessary permissions to perform their functions. Regularly audit access rights.
  • Proactive Monitoring and Alerting: Implement comprehensive logging and monitoring for all Snowflake activity. Establish alerts for anomalous login patterns, unusual data access, or changes in configuration. This includes monitoring for logins from unfamiliar IP addresses or at unusual times.
  • Security Awareness Training: Educate employees about phishing, social engineering, and the risks associated with reusing corporate credentials on personal accounts.
  • Regular Security Audits: Conduct periodic security audits and penetration tests specifically targeting your Snowflake environment and its integrations to identify and address potential weaknesses before they can be exploited. This will help detect vulnerabilities related to Snowflake data breach stolen credentials and reinforce defenses.

By prioritizing these measures, organizations can significantly reduce their attack surface and enhance their resilience against sophisticated cyber campaigns like that executed by UNC5537.

Related: Odido Data Breach Analysis: Dutch Police Suspect Local Hacker Involvement, Infostealers: Millions of Devices Compromised for Credential Theft

Advertisement

Advertisement