SYS::ONLINE
Wasteland.
Briefs1800
Issues22
SinceFeb 2026
LIVE
▣ Breach SNOWFLAKE-EXTORTIO 2026-08-09

Snowflake Customers: UNC5537 Credential Theft and Extortion Campaign

"Connor Riley Moucka, a 26-year-old Canadian from Kitchener, Ontario, pleaded guilty on August 5, 2026 in the Western District of Washington to the hacking conspiracy behind the 2024 Snowflake customer data-theft…"

Connor Riley Moucka, a 26-year-old Canadian from Kitchener, Ontario, pleaded guilty on August 5, 2026 in the Western District of Washington to the hacking conspiracy behind the 2024 Snowflake customer data-theft campaign. The U.S. Department of Justice, the primary source for this case, says the conspiracy compromised "over 165 victim organizations," stole billions of sensitive customer records, and extorted numerous victims. Counts of conviction include computer fraud, wire fraud, aggravated identity theft, and conspiracy. Reported exposure differs by outlet: heise online frames the maximum as 2 to 30 years (2 years being the mandatory minimum tied to aggravated identity theft), while SecurityWeek and TechCrunch describe exposure of more than 30 years, or "decades." Sentencing is scheduled for October 27, 2026.

What Happened

Between February and October 2024, according to the DOJ, Moucka and co-conspirators used stolen credentials to access the cloud environments of at least 165 customers of a U.S. software provider. Notably, the DOJ press release still does not name that provider, as The Register points out, but the allegations match the campaign against Snowflake tenants that is publicly attributed to the threat cluster Mandiant tracks as UNC5537.

Victim organizations named across reporting include AT&T, Ticketmaster (Live Nation), Santander, LendingTree, Advance Auto Parts, Neiman Marcus, Anheuser-Busch, Allstate, Mitsubishi, Progressive, and State Farm. BleepingComputer identifies John Erin Binns as a separately indicted co-defendant. SecurityWeek adds that a former U.S. soldier who pleaded guilty roughly a year earlier over intrusions at AT&T and Verizon is also believed to have participated.

Financial figures are broadly consistent but not identical across sources. The DOJ figure repeated by every outlet is at least $2.5 million in ransom proceeds; BleepingComputer specifies that this came in bitcoin from at least three victims, while The Register reports the group demanded at least $6 million and received roughly 36 BTC. Moucka personally netted at least $495,000 from data sales, rounded to "around $500,000" by TechCrunch and "half a million" by SecurityWeek. Victim organizations reported losses exceeding $9.5 million, a figure the DOJ says excludes harm to affected individuals. heise online reports that AT&T alone paid $370,000 for deletion of stolen data; the data was not deleted, and prosecutors say some victims were extorted more than once.

The re-extortion detail is the most striking admission. The DOJ states that "in at least one instance, Moucka re-extorted a victim with threats of further disclosure of the victim's stolen data." The Register, which reviewed the plea agreement, reports that the conspirators returned months after a May 2024 payment and leveraged stolen records concerning a government official and members of a former government official's immediate family.

Moucka, known online as Waifu and Judische and reported early on as Alexander "Connor" Moucka, was arrested in Canada on October 30, 2024, about six months into the campaign, and per SecurityWeek was extradited to the United States in July 2025.

What Was Taken

Record-volume claims vary in kind rather than contradicting outright, and defenders should note the difference. The DOJ and most outlets describe "billions" of stolen records. BleepingComputer characterizes the victim population as "hundreds of millions of individuals." SecurityWeek states the DOJ loss figure excludes the losses of victims' customers, "at least 100 million people." TechCrunch reports that data on more than 100 million AT&T customers was taken from that tenant alone. Read together: billions of database rows, tens to hundreds of millions of distinct people.

Per court documents cited by BleepingComputer and The Register, the stolen categories include call and text history metadata (non-content), banking and financial information, payroll records, DEA registration numbers, driver's license numbers, passport numbers, Social Security numbers, and other PII. The volume was measured in terabytes exfiltrated from tenant environments. Stolen data was advertised on BreachForums, Exploit.in, and XSS.is, and via Telegram, for fiat or cryptocurrency.

Why It Matters

This case is the clearest legal confirmation yet that the modern high-impact breach is an identity problem, not a vulnerability problem. Snowflake maintained throughout that no flaw in its platform was exploited, and the DOJ's own account, credentials harvested by infostealer malware used against accounts without MFA, supports that position. The consequence for the customer is identical either way: one set of reused credentials produced a 165-plus organization breach chain.

The re-extortion admission should reset assumptions about paying for deletion. AT&T's reported $370,000 payment bought nothing verifiable, and the data was later monetized on forums anyway. There is no cryptographic proof of deletion, only the attacker's word, and the plea agreement documents that the word was worthless.

Microsoft's July 2026 research on ShinyHunters-associated OAuth abuse describes a separate and more recent campaign, not this one, but the trajectory is directly relevant. There, Microsoft observed vishing against OAuth consent flows and supply chain compromise through trusted integrations such as Salesloft and Gainsight, granting inherited user and application privileges that enabled mass CRM record theft "while evading conventional authentication detections." Microsoft is explicit that this was not a Salesforce vulnerability either. The same actor ecosystem has simply moved up the stack from stolen passwords to abused trust relationships, where MFA is not the control that saves you.

The Attack Technique

The mechanics are unglamorous and repeatable. Usernames and passwords were lifted from infostealer logs, many originating from unmanaged or personal devices where corporate SaaS credentials had been saved. Because the targeted Snowflake tenants lacked MFA, valid credentials alone were sufficient for authentication, with no exploit required.

Moucka's distinguishing contribution, per his plea agreement as reported by The Register and BleepingComputer, was tooling. He admitted developing custom software that automatically enumerated compromised cloud environments to surface valuable content, flagging organization names, user roles, and IP addresses to triage which tenants were worth the effort. That is industrialized target selection: reconnaissance at scale, then terabyte-volume extraction from the most lucrative environments, then extortion under threat of publication.

What Organizations Should Do

  1. Enforce MFA on every SaaS and data-platform account with no exceptions, including service accounts, contractor logins, and legacy integrations. Snowflake has since supported tenant-level enforcement policies; use them rather than relying on per-user opt-in. This single control would have blocked the entire campaign.
  2. Treat infostealer log exposure as an active incident, not background noise. Monitor criminal marketplaces and stealer-log feeds for your domains, and force rotation plus session invalidation on any hit. Assume credentials saved in browsers on unmanaged devices are already circulating.
  3. Move data platforms behind network policy allowlists and federated SSO, so that a valid credential from an unexpected ASN or geography cannot complete authentication at all.
  4. Audit and constrain OAuth grants and third-party integrations. Per Microsoft's guidance, inventory connected applications, review consented scopes, remove unused grants, and enable platform event monitoring so token-based access is visible in telemetry that password-focused detections miss.
  5. Alert on bulk query and egress behavior inside the data platform, not just at login. Custom enumeration tooling and terabyte-scale extraction produce distinctive query-volume and result-size patterns that authentication logs alone will never show.
  6. Write the "we will not pay for deletion" decision into your incident response plan now, before you are under a deadline. Budget for notification, monitoring, and legal exposure instead, and assume any exfiltrated data will eventually be published or sold regardless of payment.

Sources: Cybercriminal pleads guilty to extorting millions from cloud custom... | Office of Public Affairs Canadian Man Pleads Guilty to Hacking U.... | Defending SaaS-based applications against ShinyHunters OAuth abuse... | Canadian hacker pleads guilty in Snowflake data breach case, steali... | Canadian pleads guilty to Snowflake cloud data-theft attacks | Hacker pleads guilty to stealing data from more than 165 Snowflake ... | Snowflake extortionist admits 165-victim cloud crime spree – and sq... | Snowflake Hacker Pleads Guilty in US Court - SecurityWeek