What Happened in the Snowflake Data Breach?
In August 2026, a Canadian man pleaded guilty in a US federal court to hacking cloud storage accounts tied to Snowflake, a cloud data platform used by hundreds of companies. This guilty plea marks a major new development in a data theft scheme first uncovered in 2024. It confirms, in a court setting, exactly how attackers broke into corporate accounts and stole enormous amounts of personal data.
According to prosecutors, Connor Riley Moucka worked with another man, John Erin Binns, to break into Snowflake customer accounts between February and October 2024. Because many of these accounts lacked multi-factor authentication, the attackers only needed valid usernames and passwords. They obtained those credentials through infostealer malware that had already infected victim systems elsewhere.
Once inside, the pair used custom software to search cloud storage instances for valuable records. As a result, they were able to identify and pull terabytes of sensitive data from at least 165 organizations. Investigators say the attackers then tried to extort several of the affected companies, threatening to leak the stolen files unless they were paid.
The case became public after Moucka’s arrest in Canada in October 2024. Since then, federal investigators have pieced together the full scope of the operation through forensic analysis and court proceedings. The guilty plea confirms details that had previously only been alleged, including specific dollar amounts extorted from victims and the exact categories of data taken.
Who was affected?
Because this breach touched at least 165 separate organizations, the pool of affected people is enormous. The Department of Justice says more than 100 million individuals have been impacted across all the victim companies combined. This makes it one of the largest coordinated data theft campaigns in recent years.
The affected population includes customers, employees, and even family members of certain individuals. For example, prosecutors say Moucka used stolen data belonging to a government official’s relatives during a re-extortion attempt. Given the range of victim companies, which include telecom, retail, education, and financial firms, the people affected span nearly every part of the country.
Named victim organizations include AT&T, Ticketmaster, Santander, Pure Storage, Advance Auto Parts, Los Angeles Unified School District, LendingTree’s QuoteWizard unit, and Neiman Marcus. Because Los Angeles Unified was among the victims, some affected individuals may include students and minors. This broad mix means both consumers and employees across many industries could be at risk.
What Information Was Potentially Exposed?
The stolen data varied by company, but court documents describe a wide range of highly sensitive categories taken from Snowflake accounts. This is not a breach limited to basic contact information. Instead, it involves financial records, government identification numbers, and communication logs.
- Call and text history records (non-content)
- Banking and financial information
- Payroll records
- Drug Enforcement Administration (DEA) registration numbers
- Driver’s license numbers
- Passport numbers
- Social Security numbers
- Other personally identifiable information
Given this mix of data, affected individuals face a real risk of identity theft. Someone with a Social Security number, driver’s license number, and passport number can often open new credit accounts or file fraudulent tax returns in a victim’s name. Because the attackers also took banking and payroll information, direct financial fraud is another serious concern.
In addition, the theft of call and text records raises privacy risks beyond typical financial fraud. This kind of metadata can reveal who someone communicates with, which can enable targeted scams or even physical safety risks in extreme cases. Meanwhile, stolen DEA registration numbers could be misused to facilitate prescription fraud, adding a less common but still serious threat to certain victims, particularly medical professionals.
What is the company doing?
Following the initial wave of attacks in 2024, Snowflake responded by strengthening its security requirements for all customers. The company announced it would enforce multi-factor authentication by default going forward. This directly addresses the weakness attackers exploited, since unprotected accounts had no second layer of login security.
Snowflake also began requiring longer passwords, with a minimum of 14 characters, to make credential-based attacks harder to pull off. In addition, federal law enforcement pursued a lengthy criminal investigation that culminated in this guilty plea. Prosecutors continue to pursue related charges against Binns, who was arrested in Turkey, though his extradition to the United States remains contested.
Individual victim companies, such as AT&T, Ticketmaster, and Neiman Marcus, separately notified their own customers and conducted their own investigations after confirming their Snowflake environments were compromised. Because each company managed its own notification process, affected individuals may have received breach letters from the specific business that held their data, rather than from Snowflake directly.
What Should Affected Individuals Do?
Monitor Your Credit Reports Closely
Anyone who received a breach notice from one of the affected companies should start checking their credit reports regularly. You can request free reports from each of the three major credit bureaus. Look carefully for accounts you don’t recognize or inquiries you didn’t authorize.
Because this breach included Social Security numbers, criminals could attempt to open new lines of credit using stolen identities. Regular monitoring helps you catch fraudulent activity early. If you spot anything suspicious, report it to the credit bureau immediately and consider contacting a data breach attorney for guidance.
Consider a Credit Freeze or Fraud Alert
Since financial information and Social Security numbers were exposed, placing a credit freeze is a strong protective step. A freeze blocks new creditors from accessing your credit file, which makes it much harder for identity thieves to open accounts in your name. This is free to set up and free to lift when needed.
Alternatively, a fraud alert requires creditors to verify your identity before extending new credit. This option is less restrictive than a freeze but still adds a helpful layer of protection. Either way, acting quickly reduces the window criminals have to exploit your stolen information.
Watch for Phishing and Scam Attempts
Because attackers stole call and text history along with personal details, they may use that information to craft convincing phishing messages. Be cautious of unexpected calls, texts, or emails asking you to verify account details or click on links. Scammers often reference real details to appear legitimate.
As a result, you should never click links or provide personal information in response to unsolicited messages. Instead, contact the company directly using a verified phone number or website. This simple habit can prevent scammers from using your stolen data to trick you further.
Protect Financial and Payroll Accounts
Given that banking and payroll records were among the stolen data, it’s wise to review your bank and payroll accounts for unusual activity. Check for unauthorized withdrawals, changes to direct deposit information, or unfamiliar account access. Report anything unusual to your bank or employer right away.
In addition, consider changing passwords for any financial accounts, especially if you reused the same password elsewhere. Enabling multi-factor authentication on your own accounts adds an extra safeguard. This step directly addresses the same weakness that allowed attackers to breach Snowflake customer accounts in the first place.
