The hacker behind the AT&T and Ticketmaster data thefts pleaded guilty - and the how is a lesson for all of us
If you had an AT&T phone in 2024, your call and text records were almost certainly in the pile. On August 5, Connor Moucka, a 26-year-old from Ontario, pleaded guilty in a Seattle federal court to the 2024 Snowflake attacks - one of the largest data thefts on record. He and an accomplice broke into at least 165 companies' cloud accounts and exposed information on at least 100 million people. He faces up to 30 years when he's sentenced on October 27.
The list of victims reads like your own receipts: AT&T (call and text records for nearly all its cellular customers), Ticketmaster, Santander, Advance Auto Parts, Neiman Marcus, LendingTree. What's striking is how ordinary the break-in was. There was no secret flaw in Snowflake's systems. The attackers simply used login details stolen years earlier by infostealer malware - some dating back to November 2020 - that had never been changed, on company accounts that didn't have two-factor authentication switched on. That's the whole trick.
Which makes the takeaway refreshingly concrete, because the two habits that would have stopped a 100-million-person breach are the same two that protect your own accounts. Turn on two-factor authentication anywhere it's offered - email and bank first - so a stolen password alone isn't enough to get in. And stop reusing passwords, because a single leaked one can sit quietly in a criminal's database for years before someone tries it.
Knowing which of your passwords have already leaked is where to start: Tendvane's Privacy & accounts check tells you which of your logins have turned up in known breaches, so you know exactly where to change a password and switch on two-factor first.