Credit Unions Advance Negligence Claims Against Snowflake
The 2024 Snowflake intrusion campaign exposed how financial institutions can inherit cyber risk through customers’ technology suppliers. Prosecutors say Canadian hacker Connor Moucka and accomplices used stolen credentials to enter customer accounts that lacked multi-factor authentication, affecting at least 165 organizations including Ticketmaster and Santander. The stolen material included payment-card information linked to Ticketmaster users and Santander employee payroll data. Attackers later advertised 560 million Ticketmaster customer records for $500,000, creating costs for card issuers with no direct contract with Snowflake.
On Oct. 29, 2025, U.S. District Judge Brian Morris in Montana denied Snowflake and Ticketmaster bids to dismiss negligence claims brought by financial institutions, allowing New Orleans Firemen’s Federal Credit Union to proceed as the representative plaintiff. Morris found the institutions plausibly alleged a duty of care, causation and damages, citing more than 100 Visa Compromised Account Management System alerts and fraudulent transactions. The ruling does not establish liability or set damages, but gives credit unions a path to recover card-reissuance, reimbursement, monitoring and other breach-related costs.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.