This week, a 26-year-old man from Ontario, Canada pleaded guilty in a Seattle federal court to one of the most damaging cybercrime campaigns in recent memory. Connor Riley Moucka admitted to hacking and extorting more than 165 organisations that used the cloud data storage provider Snowflake, exposing records belonging to at least 100 million people. He personally pocketed at least $495,000 in the process. It’s a headline-grabbing story about a young hacker and a household-name tech company, but underneath the drama is a lesson that applies directly to small and medium businesses right here in Gippsland and regional Victoria.
Here’s the twist that matters most: Snowflake itself wasn’t “hacked” in the traditional sense. The attacker didn’t need a clever zero-day exploit or sophisticated malware. He simply used stolen usernames and passwords, harvested from earlier, unrelated data breaches, to log into customer accounts that didn’t have multi-factor authentication (MFA) turned on. That’s it. No MFA, no extra verification step, and the door was wide open.
It’s tempting to read stories like this and assume they only affect giant corporations with enormous cloud data warehouses. But the underlying technique used in the Snowflake breaches, known as credential stuffing, is one of the most common ways small businesses get compromised too. Attackers buy or scrape lists of leaked email and password combinations from old breaches (LinkedIn, Adobe, and countless smaller sites over the years), then automatically try those same combinations against banking portals, email accounts, accounting software, and cloud storage services.
If you or one of your staff has ever reused a password across multiple accounts, and let’s be honest, most people have at some point, you are potentially exposed to exactly the same attack method that brought down 165 organisations using Snowflake. The only thing standing between a leaked password and your business’s customer database, invoicing system, or email account might be whether MFA is switched on.
Investigators found that the accounts hit hardest shared a few common weaknesses:
None of these are exotic technical failures. They’re the same everyday gaps that show up in small business IT reviews across regional Victoria all the time. Many small businesses run their operations through cloud platforms now, everything from Xero and MYOB to Microsoft 365, Google Workspace, point-of-sale systems, and industry-specific job management software. Each of these is a potential target if login credentials leak and MFA isn’t enabled.
A common reaction from smaller operators is that cybercriminals only go after big targets with big payouts. The Snowflake case shows the opposite pattern: attackers cast a wide net, testing stolen credentials against as many accounts as possible, and then work out afterwards who has valuable data or a willingness to pay to make the problem go away. A regional retailer, trades business, medical clinic, or accounting firm holding customer names, addresses, and payment details is just as attractive to this kind of automated attack as a Fortune 500 company. The attacker doesn’t need to know who you are in advance. The software finds you.
The good news is that the fixes for this specific attack method are genuinely achievable for a small business, without needing a dedicated IT department or big budget.
One of the most important takeaways from this case, as reported by The Hacker News, is the idea of shared responsibility in cloud computing. When you use a cloud service, whether it’s a data warehouse like Snowflake or something as everyday as Microsoft 365, the provider is responsible for securing their infrastructure, but you are responsible for securing your account. That means your passwords, your MFA settings, and your access controls are on you, not the vendor. It’s an easy detail to overlook when you’re busy running a business, but it’s exactly the gap that cost 165 organisations dearly.
If you’re not sure which of your business’s cloud accounts have MFA enabled, that’s a worthwhile afternoon project. Go through your key systems, email, accounting, banking, customer databases, and check the security settings on each one. It costs nothing but time, and it closes off one of the most commonly exploited weaknesses in cybercrime today. The Snowflake case proves that even a lone individual, using nothing more sophisticated than stolen passwords and patience, can cause damage on a massive scale when basic protections aren’t in place. The businesses that avoid becoming the next headline are usually the ones that got the simple things right.
If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.
(+61) 0412 440 804