One Hacker, 165 Companies, Billions of Records. The Lesson for Your Business.
Your customer database lives in the cloud. Your invoices, your supplier records, your employee payroll — all of it, sitting on servers that belong to someone else. You pay for the software, you log in every morning, and you assume the company behind it is handling the security.
Then a 26-year-old Canadian named Connor Moucka pleads guilty to breaking into more than 165 companies and stealing billions of records — including data from over 100 million AT&T customers, with call logs, billing details, and more — and you have to pause. Moucka’s guilty plea was announced by the U.S. Department of Justice, and the victims included household names like Ticketmaster and LendingTree.
Here’s the part that should worry you most: Moucka didn’t hack Snowflake itself. He didn’t crack some sophisticated encryption or breach the vault. He walked through the front door using usernames and passwords that were already floating around on the dark web. Some of the biggest companies on the planet had simply left their doors unlocked.
TL;DR: This was not a breach of the cloud platform. Attackers used stolen customer credentials to log into accounts that lacked proper authentication. If your Malaysian SME uses any cloud tool — accounting, CRM, email, file storage — you have the same exposure. The fix starts with your login habits, not your IT budget.
What This Means: The Fortress Wasn’t Breached. The Door Was Open.
Snowflake is a cloud data platform. Companies store massive amounts of data there — customer records, transaction histories, analytics. For attackers, a platform like this is a single vault holding the keys to dozens of businesses at once.
Moucka and his accomplices used a technique called credential-stuffing. Think of it this way: when a website gets breached and its user database leaks, email addresses and passwords become public. Attackers collect these leaked credentials and automatically try them against thousands of other services, hoping people reused the same password. It’s a numbers game, and it works because most people — and most business owners — reuse passwords everywhere.
According to the TechCrunch reporting, Moucka’s group found Snowflake customer accounts protected only by passwords — no multi-factor authentication, no verification codes. Once inside, they stole data from more than 165 customers, then contacted victims and threatened to leak the data. They also sold some stolen records on hacking forums like BreachForums. The FBI called the tactics “calculated and predatory” — and they’re right. Moucka was arrested in Canada in late 2024, just months after the breaches, and faces sentencing on October 27.
The most important detail in this entire case is simple: Snowflake’s own security held. The company wasn’t broken into. What failed was the security habits of the people using the platform.
How This Applies to Malaysian SMEs
Now, you might be thinking: “I’m not AT&T. I’m a furniture retailer in Petaling Jaya with 15 employees. Nobody’s coming for me.” That is exactly what the Snowflake victims believed before they were hit. The attackers weren’t targeting specific companies — they were scanning for weak logins at scale. Those same automated tools are running right now against every cloud service Malaysian businesses use: accounting platforms like Xero and MYOB, CRM systems, e-commerce backends, e-invoicing portals, even business email.
Malaysian SMEs are at particular risk because of how many different cloud tools you juggle. The average small business holds a dozen or more logins — bank portals, payroll systems, LHDN e-invoicing platforms, government portals, social media accounts. When you reuse the same password across several of them — and especially when that password has appeared in a past data breach — you’ve created the exact condition that let this hacker walk into 165 companies. The breach method relied entirely on reused and leaked credentials.
There’s also the orphaned account problem. How many former employees still have active logins to your company’s cloud tools? If someone left your business two years ago, and their work email and password combination leaked in a breach since then, an attacker now has a working key to your business data. The Snowflake victims included companies that, by all appearances, should have known better. The reality is that most of these breaches started with a single unguarded account.
And the extortion part matters for you too. Moucka didn’t just steal data — he threatened victims directly and demanded payment. Imagine receiving an email with a sample of your customer database attached, and a threat to leak everything if you don’t comply. Even if you refuse to pay, the reputational damage is enormous — especially in Malaysia, where the Personal Data Protection Act (PDPA) places the responsibility for protecting customer data squarely on your shoulders. A breach isn’t just an IT problem. It’s a trust problem, a legal problem, and a survival problem.
What to Do This Week
- Turn on multi-factor authentication for every business app you use. Banking, accounting, email, cloud storage, CRM — all of it. If an app offers MFA, there is no excuse to leave it off.
- Audit who has access. Log into each platform and check the user list. Remove employees who have left. You will be surprised how often old accounts remain active for years.
- Stop reusing passwords. Use a password manager to generate and store a unique password for every service. This single change neutralises credential-stuffing attacks completely.
- Check if your business email has already been exposed. Use a service like Have I Been Pwned to see if your credentials are already circulating. If they are, change those passwords today.
- Delete data you don’t need. If you’re holding customer data you no longer use, get rid of it. Less data on your systems means less exposure if someone gets in.
“Snowflake built the bank vault. The hackers just walked through doors customers had left open. Your cloud provider is not your security department — you are.”
The Bigger Picture: What This Trend Means Long-Term
The Snowflake case marks a turning point in how we talk about cloud security. Cloud providers have spent years building stronger walls, and they will keep doing so. But the way in has shifted to the human layer: the login screen, the password, the forgotten account.
For Malaysian SMEs, the lesson is that the cloud model itself isn’t the risk — your habits are. As e-invoicing becomes universal, as more customer data moves into digital systems, and as data protection rules become more actively enforced, the businesses that treat login security as routine will be the ones that don’t end up as a cautionary tale.
Expect to see more of these cases in the coming years. Expect regulators to pay closer attention. And expect insurers and business partners to start asking about your security practices before they work with you. The companies that act now — before an incident forces them to — will be one step ahead. The ones that don’t? The Snowflake victims can tell you exactly how that story ends.
| Fact from the Case | What It Means for Your Business |
|---|---|
| 165+ companies breached | No industry was spared — telecom, retail, finance, and more were all hit the same way. |
| 100 million+ AT&T customer records stolen | One unprotected account can expose an enormous amount of customer data. |
| The attacker was 26 years old | This wasn’t a state-sponsored operation. It was a cybercriminal exploiting basic security gaps. |
| The method was credential-stuffing | Reused login credentials from past breaches were the entry key. |
| The hacker was caught in late 2024 | These attacks are traceable — but only after the damage is already done. |
Ready to Streamline Your Operations?
Your business should run itself. AutoRunBiz deploys AI agents to automate your daily operations — WhatsApp orders, invoicing, customer follow-ups, and accounting. Book a free 15-min ops audit to see where automation fits your business →
