Keypoints
- Moucka and John Erin Binns accessed Snowflake accounts without MFA.
- They used stolen usernames and passwords from infostealer malware.
- The attackers stole terabytes of data from at least 165 organizations.
- They extorted victims and received at least $2.5 million in bitcoin.
- Snowflake later required MFA and longer passwords for customer accounts.