Logo

Snowflake Hack Guilty Plea: A Wake-Up Call for SMBs

This week, a 26-year-old man from Ontario, Canada pleaded guilty in a Seattle federal court to one of the most damaging cybercrime campaigns in recent memory. Connor Riley Moucka admitted to hacking and extorting more than 165 organisations that used the cloud data storage provider Snowflake, exposing records belonging to at least 100 million people. He personally pocketed at least $495,000 in the process. It’s a headline-grabbing story about a young hacker and a household-name tech company, but underneath the drama is a lesson that applies directly to small and medium businesses right here in Gippsland and regional Victoria.

Here’s the twist that matters most: Snowflake itself wasn’t “hacked” in the traditional sense. The attacker didn’t need a clever zero-day exploit or sophisticated malware. He simply used stolen usernames and passwords, harvested from earlier, unrelated data breaches, to log into customer accounts that didn’t have multi-factor authentication (MFA) turned on. That’s it. No MFA, no extra verification step, and the door was wide open.

Why This Isn’t Just a “Big Company” Problem

It’s tempting to read stories like this and assume they only affect giant corporations with enormous cloud data warehouses. But the underlying technique used in the Snowflake breaches, known as credential stuffing, is one of the most common ways small businesses get compromised too. Attackers buy or scrape lists of leaked email and password combinations from old breaches (LinkedIn, Adobe, and countless smaller sites over the years), then automatically try those same combinations against banking portals, email accounts, accounting software, and cloud storage services.

If you or one of your staff has ever reused a password across multiple accounts, and let’s be honest, most people have at some point, you are potentially exposed to exactly the same attack method that brought down 165 organisations using Snowflake. The only thing standing between a leaked password and your business’s customer database, invoicing system, or email account might be whether MFA is switched on.

What Actually Went Wrong

Investigators found that the accounts hit hardest shared a few common weaknesses:

  • Passwords that had been reused across multiple online services
  • No multi-factor authentication enabled on the accounts
  • No monitoring or alerts for unusual login locations or times
  • Long-lived credentials that were never rotated or reviewed

None of these are exotic technical failures. They’re the same everyday gaps that show up in small business IT reviews across regional Victoria all the time. Many small businesses run their operations through cloud platforms now, everything from Xero and MYOB to Microsoft 365, Google Workspace, point-of-sale systems, and industry-specific job management software. Each of these is a potential target if login credentials leak and MFA isn’t enabled.

The “It Won’t Happen to Us” Trap

A common reaction from smaller operators is that cybercriminals only go after big targets with big payouts. The Snowflake case shows the opposite pattern: attackers cast a wide net, testing stolen credentials against as many accounts as possible, and then work out afterwards who has valuable data or a willingness to pay to make the problem go away. A regional retailer, trades business, medical clinic, or accounting firm holding customer names, addresses, and payment details is just as attractive to this kind of automated attack as a Fortune 500 company. The attacker doesn’t need to know who you are in advance. The software finds you.

What Small Businesses Should Do Right Now

The good news is that the fixes for this specific attack method are genuinely achievable for a small business, without needing a dedicated IT department or big budget.

  • Turn on multi-factor authentication everywhere it’s offered. This includes email, accounting software, cloud storage, remote access tools, and any customer databases. MFA alone would have stopped almost every account compromised in the Snowflake campaign.
  • Stop reusing passwords. Use a password manager so staff can have a unique, strong password for every service without needing to remember them all. This removes the single biggest cause of credential stuffing success.
  • Check if your business has already been exposed. Free tools like Have I Been Pwned let you check whether a work email address has appeared in a known breach. If it has, assume that password (and any others like it) needs to change immediately.
  • Set up login alerts where possible. Many cloud platforms can notify an account owner of logins from new devices or unusual locations. This gives you an early warning if something’s wrong.
  • Review who actually needs access. Old staff accounts, contractor logins, and unused admin accounts are prime targets. If someone has left the business or no longer needs access to a system, remove it.
  • Ask your software and cloud providers what security they offer, and use it. Snowflake did offer MFA to its customers, but it wasn’t mandatory, and many organisations simply never turned it on. Don’t assume a provider is protecting you by default; check what’s actually switched on in your account settings.

The Bigger Picture: Shared Responsibility

One of the most important takeaways from this case, as reported by The Hacker News, is the idea of shared responsibility in cloud computing. When you use a cloud service, whether it’s a data warehouse like Snowflake or something as everyday as Microsoft 365, the provider is responsible for securing their infrastructure, but you are responsible for securing your account. That means your passwords, your MFA settings, and your access controls are on you, not the vendor. It’s an easy detail to overlook when you’re busy running a business, but it’s exactly the gap that cost 165 organisations dearly.

A Practical Next Step

If you’re not sure which of your business’s cloud accounts have MFA enabled, that’s a worthwhile afternoon project. Go through your key systems, email, accounting, banking, customer databases, and check the security settings on each one. It costs nothing but time, and it closes off one of the most commonly exploited weaknesses in cybercrime today. The Snowflake case proves that even a lone individual, using nothing more sophisticated than stolen passwords and patience, can cause damage on a massive scale when basic protections aren’t in place. The businesses that avoid becoming the next headline are usually the ones that got the simple things right.


Worried This Could Affect Your Business?

If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.

Book your free security assessment →

Logo
Servicing small businesses across the valley.
Get in touch
Customer Support

(+61) 0412 440 804

Copyright © 2025 Maximum IT Solutions