Ethical Hacking News
Swati Khandelwal has pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy over the 2024 breaches of Snowflake customer accounts that affected at least 100 million people. The breach resulted in actual losses exceeding $9.5 million for victim companies. Moucka took advantage of old passwords and had previously extorted at least one victim, threatening further disclosure using stolen data.
Snowflake hacker Swati Khandelwal pleaded guilty to charges related to a massive data breach affecting at least 100 million people. The breach targeted customer accounts of at least 165 organizations worldwide, exposing sensitive information such as non-content call and text history, payroll records, and passport numbers. The hacker took advantage of old passwords harvested years earlier by infostealer malware that never rotated, exploiting multi-factor authentication turned off on some accounts. At least 79.7% of the compromised accounts had prior credential exposure, with no network allow lists. The actual losses suffered by victim companies were estimated to be over $9.5 million. Snowflake has enforced MFA by default for human users on accounts created since October 2024.
Snowflake hacker Swati Khandelwal pleaded guilty to a slew of charges related to a massive data breach that affected at least 100 million people. The intrusions, which occurred in 2024, targeted customer accounts belonging to at least 165 organizations worldwide. Moucka's actions resulted in the exposure of sensitive information, including non-content call and text history, payroll records, Drug Enforcement Administration (DEA) registration numbers, passport and Social Security numbers.
The Justice Department announced that Moucka had taken advantage of old passwords that had been harvested years earlier by infostealer malware, which never rotated. The accounts in question had multi-factor authentication (MFA) switched off, making it easier for the hacker to gain access without exploiting any vulnerabilities or flaws in the platform.
Mandiant's investigation revealed that every incident they worked on was traced back to customer credentials stolen by infostealers. At least 79.7% of the accounts the group used had prior credential exposure, and the compromised instances had no network allow lists. The campaign was attributed to the size of the infostealer market and to credentials left unrotated for as long as four years.
The hacker also re-extorted at least one victim, threatening further disclosure using the stolen data of a government officer and members of a then-former government officer's immediate family. The tactics employed by Moucka were described by W. Mike Herrington, special agent in charge of the FBI's Seattle field office, as "calculated and predatory."
The actual losses suffered by the victim companies were estimated to be over $9.5 million, excluding losses to their own customers. AT&T confirmed that records of calls and texts for nearly all its cellular customers between May 1 and October 31, 2022, were taken from its workspace on a third-party cloud platform.
In addition to Moucka, two other individuals were charged in connection with the breach. John Erin Binns was outside U.S. custody as of an August 4 court update, while Cameron John Wagenius, a former Army soldier, had previously pleaded guilty in a related case and was scheduled to be sentenced in July 2025.
Snowflake has since enforced MFA by default for human users on accounts created since October 2024 but noted that password-only sign-ins were not going away. Its documentation put the final phase of account updates between August and October 2026, when passwords would be blocked as a sole factor for every remaining human and service user, except for reader and trial accounts.
Related Information:
https://www.ethicalhackingnews.com/articles/Snowflake-Hacker-Pleads-Guilty-to-Computer-Fraud-Wire-Fraud-Aggravated-Identity-Theft-and-Conspiracy-ehn.shtml
https://thehackernews.com/2026/08/snowflake-hacker-pleads-guilty-over.html
Published: Thu Aug 6 01:35:22 2026 by llama3.2 3B Q4_K_M