Snowflake hacker pleads guilty after breaching AT&T and Ticketmaster data
Connor Moucka has pleaded guilty to hacking over 150 organizations, including Live Nation and AT&T, by exploiting stolen credentials for cloud storage services. The incident highlights critical security vulnerabilities in third-party cloud infrastructure relied upon by major media and telecommunications entities.
Key Takeaways
- Connor Moucka faces a potential 30-year prison sentence after admitting to wire fraud, computer fraud, and aggravated identity theft.
- The campaign successfully extorted $2.5 million from victims by leveraging stolen credentials for accounts lacking multi-factor authentication.
- Data stolen from 165 organizations included call and text histories, banking records, and social security numbers.
- Victim companies incurred approximately $9.6 million in direct response and recovery costs following the breach campaign.
Why It Matters
The guilty plea confirms that the Snowflake data breach was not a platform-level failure but a widespread exploitation of poor credential hygiene at major streaming and telecom providers. For the streaming industry, this highlights the extreme vulnerability of third-party cloud data warehouses that centralize massive sets of customer telemetry and billing information. As companies shift more operational data to serverless cloud environments, the lack of mandatory multi-factor authentication remains a primary attack vector. The legal resolution of this case sets a precedent for cross-border cybercrime enforcement, though it leaves organizations with the permanent task of securing decentralized access points. Watch for a shift toward mandatory hardware-based authentication across major cloud service providers to mitigate similar credential-stuffing risks.
Additional Context
The impact of the Snowflake breach campaign extended significantly to the telecommunications sector. Per Reuters and other outlets in July 2024, AT&T revealed that hackers had exfiltrated call and text metadata for nearly all of its wireless customers—roughly 110 million people—during a specific six-month window in 2022. While the company stated the content of the messages was not taken, the metadata included phone numbers and cell tower identifiers. AT&T later reached a $177 million settlement in June 2025 to resolve multiple class-action lawsuits stemming from this and a separate 2024 data incident.
Entertainment giant Live Nation also faced severe repercussions when its subsidiary, Ticketmaster, was targeted. Per SEC filings in May 2024, the company identified unauthorized activity in a third-party cloud environment that exposed the personal information of approximately 560 million customers. This data, totaling roughly 1.3 terabytes, was subsequently listed for sale on cybercrime forums by the group ShinyHunters. The breach prompted immediate scrutiny of Live Nation's security protocols and led to litigation in the U.S. District Court for the Central District of California.
In response to these incidents, cloud provider Snowflake updated its security architecture to enforce stricter authentication requirements. According to security analysts from Mandiant and CrowdStrike in June 2024, the attacks utilized a targeted credential-stuffing technique rather than a direct vulnerability in Snowflake's software. By early 2025, industry-wide data showed a 235% increase in high-severity cloud alerts, according to Palo Alto Networks, reflecting a broader trend of attackers focusing on misconfigured cloud permissions and stolen administrative tokens. This has forced a reevaluation of identity and access management (IAM) strategies across the media technology stack.
Read full article at ctvnews.ca
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source