Snowflake Extortionist Enters Guilty Plea
A Canadian national has admitted to his role in a massive 2024 campaign that compromised over 165 major corporate Snowflake accounts.
A 26-year-old Canadian national has officially entered a guilty plea in a United States court regarding his participation in a sprawling extortion operation. The campaign targeted the cloud data infrastructure of Snowflake customers throughout 2024, resulting in the theft of vast quantities of sensitive information and millions of dollars in illicit gains.
A Coordinated Criminal Campaign
Connor Riley Moucka of Ontario appeared in court on August 5 2026, to answer for his role in the breaches. The charges against him include computer fraud, conspiracy, and aggravated identity theft. While the aggravated identity theft charge carries a mandatory minimum of two years behind bars, the total sentencing exposure across all counts reaches a maximum of 30 years. A sentencing date is currently set for October 27.
The operation, which unfolded between February and October 2024, relied on the unauthorized use of stolen login credentials. Investigators found that this access was leveraged to infiltrate at least 165 separate customer instances within the Snowflake data warehousing environment. The attackers utilized this foothold to exfiltrate billions of individual records containing financial data, personal identifiers, and private communication logs.
Extortion and Data Monetization
The criminal group employed a multi-pronged strategy to profit from their unauthorized access. Beyond the initial theft, they extorted victim organizations by threatening to release stolen data publicly. In one instance, the group engaged in re-extortion, targeting a victim with threats of additional disclosures involving the private data of a former government official’s immediate family members.
Monetization also occurred through the sale of stolen datasets on platforms such as Telegram and BreachForums. The scope of the financial impact and the scale of the data involved are detailed below:
- At least 165 Snowflake customer accounts were compromised.
- Hackers received more than $2.5m in direct ransom payments.
- Moucka personally secured at least $495,000 from data sales.
- Victim companies faced over $9.5m in confirmed losses.
- The breach impacted at least 100 million individual customers of the victim firms.
Detection and Law Enforcement
The campaign was brought to light in June 2024 when the cybersecurity firm Mandiant publicly alerted the industry to the activity. Their analysis traced the database records back to an initial compromise of a victim’s Snowflake instance that occurred as early as April 2024. Following the discovery, Mandiant initiated contact with Snowflake in May 2024 to coordinate a response.
The subsequent investigation involved a massive international effort, spanning police agencies in Canada, Australia, Spain, Ukraine, and Turkey. This collaborative work led to the arrest of Moucka in October 2024. He was later extradited from Canada to the United States in July 2025.
Industry Response and Impact
In the wake of the disclosures, Snowflake implemented a Victim Notification Program designed to assist affected parties in securing their instances and reviewing potential exposures. Furthermore, the company mandated the use of multi-factor authentication for all customer accounts to prevent similar credential-based attacks in the future.
High-profile organizations, including Ticketmaster and AT&T, were among those identified as victims during the campaign. The incident serves as a stark reminder of the risks associated with cloud-based data warehousing when authentication protocols are not strictly enforced across the enterprise.
Consequences for Cloud Security
This case suggests that the security of large-scale cloud environments remains a primary target for sophisticated threat actors. The ability for attackers to compromise 165 entities through a single platform highlights the potential for systemic risk when service providers become the point of failure. For businesses, the implications are clear: reliance on third-party cloud infrastructure necessitates rigorous internal security controls, particularly regarding identity and access management, to ensure that a compromise at the provider or account level does not translate into a catastrophic data loss event.
Sources
- Infosecurity Magazine Original source
Continue Reading
Beacon CRM Breach Exposes UK Charities
A cyberattack on the CRM provider Beacon has resulted in the potential theft of sensitive database backups for numerous UK charities.
Physical Attacks Targeting Crypto Wealth
New data reveals a surge in violent physical thefts targeting cryptocurrency holders, with millions lost in the first half of 2026.
PNLD Breach Exposes Police Contact Data
The Police National Legal Database confirms a data breach involving over 100,000 records of officers and legal professionals.