A Canadian hacker has pleaded guilty to charges tied to the 2024 breaches of more than 165 Snowflake customer environments, a campaign that exposed data belonging to at least 100 million people. Stolen credentials opened the doorThe Hacker News reported that credentials used in the attacks had previously been harvested by infostealer malware, in some cases years before the Snowflake campaign began. Other stolen information across the campaign included banking details, payroll records, driver’s license numbers, passport numbers, Social Security numbers, and Drug Enforcement Administration registration numbers. Moucka personally received at least $495,000 through extortion and the sale of stolen information, according to the publication. Security teams should treat exposed credentials as compromisedThe case reinforces the risks of allowing password-only authentication for sensitive cloud environments.