- Key insight: Financial institutions appear in this case in two roles, as breached customers whose data got stolen and as card issuers absorbing the cost of a merchant's breach.
- What's at stake: Chief Judge Brian Morris let negligence and unjust enrichment claims stand against both Snowflake and Ticketmaster, sending the card issuers' theory into discovery rather than ending it.
- Forward look: The civil case against Snowflake and Ticketmaster is in discovery, which has already turned contentious enough to draw a sanctions order against Ticketmaster.
Overview bullets generated by AI with editorial review.
A Canadian man pleaded guilty last week to a scheme to break into the cloud storage accounts of at least 165 companies, steal their data and extort them for it.
Santander lost employee payroll data in the campaign, and credit unions that had no direct relationship with the storage provider are still paying the cost of cleanup after the intrusion allegedly exposed their members' card numbers.
The case serves as a reminder of the cybersecurity risks of fourth parties (tech vendors with which a financial institution has no direct relationship) and the importance of enforcing multifactor authentication.
Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty on Aug. 5 in a Seattle federal court to computer fraud, wire fraud, aggravated identity theft and a related conspiracy charge in a campaign against customers of Snowflake, a cloud data storage and analytics company.
Moucka used stolen usernames and passwords to access payroll records, Social Security numbers and "banking and other financial information" those companies had stored with the cloud provider, according to his
The Justice Department does not name Snowflake, but details in the case line up with a
For example, Moucka's plea agreement describes a scheme to defraud "at least 165 victim organizations." Mandiant said it and Snowflake had notified "approximately 165 potentially exposed organizations."
As the criminal case against Moucka wraps up in Seattle (he is scheduled for sentencing in October), an argument is heating up in federal court in Montana over who pays for the fallout of his scheme.
The Montana case, which involves Snowflake, Ticketmaster and a group of credit unions and card issuers, has gone to discovery, the phase of a lawsuit in which each side digs into the other's records to build their case.
Financial institutions have two roles in the saga: first as breached customers whose data Moucka stole, and second as card issuers absorbing the cost of a merchant's breach.
It is unclear just how many financial institutions got their data stolen in Moucka's campaign. Neither the Justice Department, Mandiant nor Snowflake has published how many of the 165 organizations were banks or credit unions.
However, through public disclosures and lawsuits against Snowflake, a few names have risen to the surface.
A Snowflake spokesperson declined to comment for this article.
Santander lost employee data in the campaign
Moucka's October 2024
Between April 17 and May 10, 2024, Moucka and his co-conspirators took names, addresses, Social Security numbers and payroll records belonging to Victim-6's employees in several countries, including the United States, according to the indictment.
The dates and details of Victim-6's stolen records align with those of a breach Santander disclosed to state attorneys general.
The Spanish multinational
The compromised database sat with a
Santander did not immediately respond to a request for comment.
Credit unions paid to replace cards
A number of credit unions have sued Snowflake over the 2024 campaign. None of them were compromised during it; rather, their members' cards sat inside Ticketmaster's Snowflake account, which Moucka compromised.
Visa began sending compromised-account alerts to card issuers in December 2024, more than six months after Ticketmaster disclosed the breach, according to
(New Orleans Firemen's Federal Credit Union sued separately and now represents the proposed class of card issuers in the consolidated Montana case.)
The card issuers claim Visa sent more than a hundred of those alerts, according to
These alerts told issuers a network intrusion at Ticketmaster had exposed payment card numbers sometime between May 2009 and May 2019, according to the complaint. The institutions then had to cancel and reissue cards and refund fraudulent charges.
Snowflake and Ticketmaster characterize the cancellations and reissuances as voluntary and precautionary, according to their
Nobody has disclosed how many cards the issuers had to replace, and the complaints do not detail the total replacement cost to the credit unions.
Credit unions filed the lawsuits, but the proposed class covers any financial institution (including banks) that had to reissue payment cards to their customers following the Ticketmaster breach.
A Ticketmaster spokesperson did not answer American Banker's questions, instead pointing to a
That statement says the breached database held "encrypted credit card information." The card issuers implicitly contradicted this in court records that said Visa's alerts identified card numbers they then had to cancel and replace.
The court has not decided whose encryption claim is correct. However, the judge found that Visa's alerts (combined with fraudulent charges the issuers had already absorbed) showed enough risk of further harm to let reissuance costs count as an injury.
Counsel for the credit unions did not immediately respond to a request for comment.
Did Snowflake enforce its own security rule?
Mandiant found no evidence that anyone broke into Snowflake's own systems. Rather, the intruders logged into customer accounts on Snowflake's platform using valid credentials.
The attackers stole these credentials using malware installed on machines belonging to customers' employees and contractors.
Mandiant's report does not say how the malware reached most of those machines, though it notes that attackers often get credentials from users who inadvertently download trojanized software (legitimate-looking software hiding malware inside it).
Crucially, the accounts the threat actors accessed did not have multifactor authentication, according to Mandiant.
Chief Judge Brian Morris, who oversees the consolidated case in Montana federal court, has largely denied Snowflake's and Ticketmaster's motions to dismiss.
In an October ruling, he threw out one count and let three others stand. The counts Snowflake and Ticketmaster still face include negligence and unjust enrichment, which is a claim that a company profited at someone else's expense and ought to pay it back.
At this stage, the ruling means only that the card issuers' legal theory survives; there has been no finding of guilt or innocence.
The credit unions "plausibly have alleged" that Snowflake and Ticketmaster "owed a duty of care to protect customer data from foreseeable risk of harm by providing additional security measures," such as multifactor authentication, Morris
Snowflake had
That failure "can be inferred" to have arisen from "Snowflake's failure to enforce its standards," he wrote.
That obligation was the customer's all along, Snowflake asserted in
"Not one" of the sources the credit unions cited supports their assertion that cloud providers must force their customers to use multifactor authentication for all accounts, or that cloud providers must enable it by default, Snowflake argued.
The company also cast blame on Ticketmaster for failing to use the security feature.
The facts uncovered during discovery will determine the direction of the case, and the process has already turned contentious. In July, Morris
Three lessons learned
Mandiant traced the break-ins to three failures in the accounts the intruders penetrated. The firm, which Google owns, ran its investigation jointly with Snowflake and notified the roughly 165 victim organizations.
First, the accounts lacked multifactor authentication. Second, nobody had rotated the stolen credentials. Third, there were no "network allow lists," which would have allowed logins only from trusted locations.
Some of the stolen passwords had gone unchanged for as long as four years, according to the
At least 79.7% of the accounts the intruders used had turned up in earlier credential leaks that were totally unrelated to the Snowflake campaign. Most of these credentials came from infostealer malware, which harvests saved passwords off an infected machine.
Those infected machines had nothing to do with Snowflake. In several of its investigations, the infections hit contractor laptops also used for gaming and pirated downloads, Mandiant found.
Contractors often use such laptops to reach several companies' systems at once, Mandiant wrote, so one infected machine can hand an intruder access across multiple organizations, often with administrator privileges.
The report calls for credential monitoring, universal enforcement of multifactor authentication, limits on where a login to a company's most sensitive data can come from and alerts on unusual login attempts.











