Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty on August 5, 2026 in U.S. District Court for the Western District of Washington to his role in the mass compromise of customer accounts at cloud data platform Snowflake. The U.S. Department of Justice announced the plea the same day. At least 165 organizations were breached between February and October 2024, billions of records and several terabytes of data were exfiltrated, and victims were extorted for millions. Sentencing is set for October 27, 2026.
The headline figure of "roughly 100 million people" is worth pinning down at the outset, because the sources do not all mean the same thing by it. The Times of India frames 100 million as the total population of affected individuals across the campaign. The Record attributes that number to a single victim, reporting that the AT&T breach alone involved call and text logs for more than 100 million customers, and separately that the Ticketmaster breach involved roughly 560 million users. Taken at face value, the per-victim totals reported by The Record exceed 100 million by a wide margin. What every source agrees on is the unit that prosecutors actually used: billions of records, terabytes of data, 165 victim organizations.
What Happened
Prosecutors say the conspiracy ran from February through October 2024. Moucka and co-conspirators, including John Erin Binns, who was separately indicted, used stolen login credentials to access cloud-hosted data belonging to Snowflake customers. Snowflake itself was not breached at the platform level in the sense of an exploited product vulnerability; the intrusions were account takeovers against individual customer tenants.
The Times of India, the only OTHER-tier source in this set, describes the target generically as "a US-based software-as-a-service provider" and does not name Snowflake. Every OUTLET-tier source, including CBC, BleepingComputer, The Record and Infosecurity Magazine, names Snowflake directly and ties the plea to the 2024 breach wave.
Accounts differ on two procedural details. BleepingComputer and Infosecurity Magazine put Moucka's arrest on October 30, 2024, while The Record reports he was arrested in November 2024. Both BleepingComputer and The Record note he was extradited to the United States in July 2025. On the charges, CBC and The Record both report four counts: computer fraud, wire fraud, aggravated identity theft and a related conspiracy. Infosecurity Magazine lists the same set minus wire fraud. On exposure, CBC and Infosecurity both report a mandatory minimum of two years on the aggravated identity theft count and a maximum of 30 years on the remaining counts; The Record renders the combined exposure as up to 32 years.
Infosecurity reports the arrest followed a law enforcement effort involving Canadian, Australian, Spanish, Ukrainian and Turkish police.
What Was Taken
Court documents describe a broad and deliberately monetizable data set pulled from victim tenants:
- Non-content call and text message history records
- Banking and financial information
- Payroll records
- Drug Enforcement Administration (DEA) registration numbers
- Driver's license numbers
- Passport numbers
- Social Security numbers
- Other personally identifiable information
Volume is described consistently as terabytes of data and billions of sensitive customer records across the 165 organizations. Named victims reported by The Record include AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, LendingTree and one of the largest school districts in the United States. That victim list appears in a single OUTLET source in this set and should be read as The Record's reporting rather than an enumerated DOJ list.
The financial picture: Moucka and co-conspirators obtained at least $2.5 million in bitcoin in ransom payments, which BleepingComputer specifies came from at least three victims and Infosecurity renders as "more than $2.5m." Moucka separately earned at least $495,000 selling stolen data on criminal forums. The Record reports that court documents put aggregate victim company losses at approximately $9.5 million. Sales venues are reported as BreachForums and XSS.is by The Record, and as BreachForums and Telegram by Infosecurity.
One detail stands out on the extortion side. DOJ stated that in at least one instance Moucka re-extorted a victim, and that he "used the stolen data of a government officer and members of a then-former government officer's immediate family in this re-extortion attempt." Paying did not end the pressure; it identified a victim willing to pay.
Why It Matters
This case is the legal endpoint of the single most consequential demonstration that cloud data warehouses concentrate risk. One credential class, applied at scale against one platform's customer base, produced 165 separate corporate breaches. No zero-day, no novel malware, no supply chain implant in the platform itself. The attacker inherited whatever each customer had loaded into their tenant, which is why the stolen data spans telecom call records, payroll, DEA registrant numbers and passports in the same campaign.
The guilty plea also settles the attribution question that hung over the 2024 breach wave, and it demonstrates that extradition works: arrest in Canada in late 2024, extradition to the U.S. in July 2025, plea in August 2026.
The wider 2026 context in this source set reinforces the pattern rather than extending this case. SecurityWeek reports that Telus is notifying customers that consumer telecom accounts were accessed between February 2025 and June 2026 using compromised credentials, exposing names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details and payment history, with some accounts modified without authorization. Telus has not stated the number of affected accounts and has not said the credentials came from a third party, though SecurityWeek assesses the description as consistent with credential stuffing or account takeover. Reuters reports that a Thomson Reuters unit detected a cybersecurity incident on June 30 affecting its C-Track court case management platform across 11 U.S. states, the U.S. Virgin Islands and Canada, with investigators later determining an unauthorized party obtained certain C-Track files in March. And CBC reports the claims process is now open for an $8.7 million class action settlement covering tens of thousands of Canadians whose CRA and other government portal accounts were compromised in 2020, with up to $5,000 for the most serious cases. These are separate incidents from the Snowflake campaign, but together they sketch the full lifecycle: credentials stolen, accounts taken over, data monetized, and years later, settlement cheques.
The Attack Technique
The mechanics are simple enough to be uncomfortable. Per BleepingComputer, Moucka and Binns accessed Snowflake customer accounts that were not protected by multi-factor authentication, using credentials harvested by infostealer malware. With no MFA in the path, valid usernames and passwords were sufficient for full tenant access.
Once inside, court documents describe the use of custom software to survey compromised cloud storage instances and identify valuable targets, pulling metadata such as organization name, user roles and IP addresses to prioritize which tenants and tables were worth bulk exfiltration. That reconnaissance tooling is the operationally interesting part: this was not smash-and-grab, it was triage at scale followed by targeted bulk download, then extortion backed by threats to publish, then forum sales for whatever the extortion did not monetize.
What Organizations Should Do
- Enforce MFA on every data platform tenant, with no exceptions and no admin carve-outs. This campaign succeeded specifically against accounts where MFA was absent. Make it a tenant-level policy enforced by the platform, not a user preference. Where the platform supports it, require phishing-resistant factors rather than SMS or TOTP.
- Treat infostealer infections as credential compromise events, not malware cleanups. Reimaging the endpoint does not invalidate the session tokens and passwords already exfiltrated. Rotate every credential the host touched, kill active sessions, and monitor criminal marketplaces for your domains appearing in stealer logs.
- Apply network policy and IP allowlisting to warehouse access. Snowflake and comparable platforms support restricting authentication to known egress ranges. A stolen password is far less useful when it must also arrive from your network.
- Audit what is actually sitting in the warehouse. The breadth of stolen data here, from call detail records to DEA registration numbers, reflects data loaded into cloud analytics environments without minimization. Inventory sensitive columns, tokenize or drop what analytics does not need, and set retention limits.
- Alert on bulk-read behavior, not just on login anomalies. The attackers enumerated metadata before exfiltrating terabytes. Query volume baselines, large result-set exports, and unusual table enumeration by a single principal are the detections that would have fired here.
- Plan for re-extortion in your incident response playbook. DOJ confirmed at least one victim in this campaign was extorted a second time. Assume payment does not end exposure, and build notification and legal timelines that do not depend on an attacker honouring a deletion promise.
- Extend the same controls to downstream and subsidiary accounts. The Telus notifications show credential-driven account takeover continuing to produce multi-month intrusions into 2026 against consumer-facing account systems, not just enterprise data platforms.
Sources: A 26-year-old Canadian hacker breached 165 companies and exposed da... | Canadian hacker pleads guilty in Snowflake data breach case, steali... | Canadian pleads guilty to Snowflake cloud data-theft attacks | Canadian man pleads guilty to Snowflake hacks that led to 165 breac... | Canadian Hacker Pleads Guilty Over Snowflake Extortion Campaign - I... | Telus Warns Customers of Account Breaches - SecurityWeek | Was your CRA profile hacked? A $8.7M lawsuit settlement claim is no... | Thomson Reuters detects cybersecurity incident, says unauthorized ...