Connor Riley Moucka, a 26-year-old from Kitchener, Ontario, pleaded guilty on Wednesday, August 5, 2026 in federal court for the Western District of Washington to computer fraud, wire fraud, aggravated identity theft and a related conspiracy, closing the criminal chapter on the 2024 Snowflake customer-tenant compromise campaign. The plea is confirmed by a Department of Justice Office of Public Affairs press release, which states the conspiracy "resulted in the compromise of over 165 victim organizations, the theft of billions of sensitive customer records and the extortion of numerous victims." Reporting on the exposure scale converges on more than 100 million people affected (SecurityWeek, CyberScoop), with TechCrunch attributing over 100 million of those to the AT&T breach alone. Prosecutors put victim-company losses at more than $9.5 million, a figure that explicitly excludes downstream losses borne by those companies' own customers. Sentencing is set for October 27.
What Happened
Between February and October 2024, per court documents cited by BleepingComputer, Moucka and co-conspirators logged into Snowflake customer accounts using credentials harvested by infostealer malware. This was never a breach of Snowflake's own platform: the intruders walked into individual tenant environments belonging to Snowflake's customers. The activity is tracked by Google's Mandiant as UNC5537, and Mandiant senior researcher Austin Larsen called Moucka "one of the most consequential" hackers of 2024.
Moucka operated under multiple handles. CyberScoop lists "Waifu," "Judische," "Catist" and "Ellyel8"; SecurityWeek notes he was identified in initial 2024 coverage as Alexander "Connor" Moucka. He was arrested October 30, 2024 in Kitchener at the request of U.S. authorities, roughly six months after the campaign began.
Named co-conspirators are John Binns and Cameron John Wagenius. Note a discrepancy in the record: most outlets (BleepingComputer, CyberScoop) give the middle name as John Erin Binns, while CSO Online writes John Edward Binns. CSO reports Binns was not in U.S. custody as of April 2026. Wagenius, who used the handle "Kiberphant0m," was arrested in January 2025 and pleaded guilty in July of that year per CSO; SecurityWeek describes him as a former U.S. soldier who pleaded guilty roughly a year ago to intrusions at AT&T and Verizon.
Accounts differ on two procedural points. On extradition, CyberScoop states Moucka was extradited to the United States in March 2025, while SecurityWeek says July 2025. On the sentencing exposure, CSO Online reports a range of 2 to 30 years, SecurityWeek says more than 30 years, and both The Record and CyberScoop report up to 32 years. The DOJ release itself does not resolve the figure in the excerpt available. Treat the statutory maximum as approximately 30 to 32 years pending the October hearing.
There is also a minor internal inconsistency in the government's own messaging worth flagging: Assistant Attorney General A. Tysen Duva's quoted statement says Moucka "hacked over 150 companies," while the body of the same DOJ release and every outlet report the figure as at least 165.
What Was Taken
BleepingComputer, citing the DOJ, enumerates the categories pulled from breached tenants:
- Call and text history records (non-content metadata)
- Banking and other financial information
- Payroll records
- Drug Enforcement Administration (DEA) registration numbers
- Driver's license numbers
- Passport numbers
- Social Security numbers
- Additional personally identifiable information
Volume is described in the DOJ release as "billions of sensitive customer records" and terabytes of downloaded data. The named victim roster across sources includes AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus Group, LendingTree, Santander, Anheuser-Busch, Allstate, Mitsubishi, Progressive and State Farm. The Record adds one of the largest school districts in the United States.
On monetization, the figures are consistent. Moucka and co-conspirators obtained at least $2.5 million in bitcoin in extortion payments from at least three victims. Separately, Moucka took in roughly $495,000 (rounded to "around $500,000" by TechCrunch and "half a million" by SecurityWeek) selling stolen data on hacking forums including BreachForums.
The DOJ notes that in at least one instance Moucka re-extorted a victim with threats of further disclosure. CyberScoop reports that this leverage involved the stolen data of a government officer and members of a then-former government official's immediate family.
Why It Matters
This case is the clearest legal validation to date of a threat model many organizations still under-weight: your SaaS data warehouse is only as secure as the weakest credential any employee or contractor ever typed into a machine that later got infected. No zero-day, no exploit chain, no lateral movement through a corporate network. Valid credentials against internet-facing tenants with no second factor produced one of the largest data theft campaigns on record.
Three takeaways for defenders:
The shared responsibility gap is where the damage lives. Snowflake's platform was not compromised. Its customers' identity hygiene was. Every "the vendor is SOC 2 certified" assurance in your third-party risk file says nothing about whether your own tenant enforces MFA.
Infostealer logs are a live, priced supply chain. Credentials stolen from an unmanaged endpoint, sometimes years earlier, remain valid because nobody rotated them. Commodity malware feeds high-end intrusion.
Extortion is now multi-stage. Re-extortion after payment, and targeting of government-adjacent individuals to increase pressure, show the economics have moved past a single transaction.
The takedown itself is also notable as a coordination artifact. CSO Online reports the investigation was FBI-led with contributions from the Royal Canadian Mounted Police, the Australian Federal Police, Spain's Guardia Civil, the Security Service of Ukraine and the Turkish National Police. First Assistant U.S. Attorney Charles Neil Floyd credited the speed of the Western District of Washington cybercrimes unit, and FBI Cyber Division Assistant Director Brett Leatherman framed the outcome bluntly: "Hiding behind a screen is no shield from justice."
The Attack Technique
The chain is short and entirely mundane, which is the point.
- Credential acquisition. Usernames and passwords for Snowflake customer accounts were sourced from infostealer malware logs, some harvested from contractor and employee endpoints outside corporate management.
- Authentication with no second factor. BleepingComputer states the targeted accounts were not protected by MFA. With MFA absent, valid credentials alone were sufficient for full tenant access.
- Automated reconnaissance. Per court documents, the actors ran custom software against accessed instances to identify valuable targets, enumerating organization names, user roles and IP addresses to prioritize which tenants to exfiltrate.
- Bulk exfiltration. Terabytes of data pulled from tenant environments.
- Extortion and resale. Direct ransom demands, re-extortion of at least one victim, and parallel sale of datasets on forums for fiat and cryptocurrency.
There is no evidence in any source of an exploited vulnerability in Snowflake itself.
What Organizations Should Do
- Enforce MFA on every SaaS tenant without exception, and make it non-optional at the platform level. Snowflake has since moved toward mandatory MFA, but the lesson generalizes: any data platform reachable from the internet with password-only auth is a pending incident. Audit for accounts that are exempted, service accounts included.
- Move service and machine accounts to key-pair or OAuth authentication with scoped, short-lived tokens. These accounts are the most common MFA exemption and the least monitored.
- Apply network policies and allowlisting to warehouse access. Restrict tenant logins to known corporate egress ranges or a VPN, so a stolen credential used from an unfamiliar ASN fails before it authenticates.
- Treat infostealer exposure as a standing rotation trigger. Subscribe to credential-leak monitoring, and force rotation for any corporate identity appearing in stealer logs. Assume anything captured before your last rotation is compromised, including contractor and BYOD endpoints you do not manage.
- Alert on bulk query and export behavior, not just logins. The reconnaissance-then-exfiltration pattern produces anomalous volume signatures. Set thresholds on rows scanned, data egress per session and off-hours access, and route them to a monitored queue.
- Inventory what is actually sitting in the warehouse. DEA registration numbers, passport numbers and payroll records ended up in analytics tenants because nobody asked whether they needed to be there. Tokenize or exclude regulated identifiers from analytical stores, and reduce retention.
- Test your third-party assurance against tenant-level configuration. Vendor certifications do not cover how your instance is configured. Add MFA enforcement, network policy and logging retention to your SaaS onboarding checklist as verified controls, not attested ones.
Sources: Snowflake attacker pleads guilty to hack of 165 companies’ data CS... | Office of Public Affairs Canadian Man Pleads Guilty to Hacking U.... | Canadian pleads guilty to Snowflake cloud data-theft attacks | Hacker pleads guilty to stealing data from more than 165 Snowflake... | Canadian man pleads guilty to Snowflake hacks that led to 165 breac... | Snowflake Hacker Pleads Guilty in US Court - SecurityWeek | Snowflake hacker pleads guilty, faces up to 32 years in prison Cyb... | Canadian hacker pleads guilty in Snowflake data breach case, steali...