Connor Riley Moucka, a 26-year-old Canadian citizen, has pleaded guilty in a Washington state federal court to charges including computer fraud, wire fraud, aggravated identity theft, and a related conspiracy. The charges stem from his involvement in hacking customer accounts on the cloud data storage platform Snowflake.
Moucka, also known as Alexander Moucka and Waifu, was arrested in November 2024 and extradited to the U.S. in July 2025. He is scheduled for sentencing on October 27 and faces a potential prison sentence of up to 32 years, including a mandatory minimum of two years for identity theft.
Between February and October 2024, Moucka and his co-conspirators, including John Erin Binns, accessed Snowflake accounts using stolen login credentials. These accounts were not protected by multi-factor authentication (MFA), allowing access with only a username and password. The credentials had been harvested years prior by infostealer malware and were not rotated.
The intrusions affected at least 165 organizations, leading to the theft of billions of sensitive data records. Major companies impacted include AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, LendingTree, Anheuser-Busch, Allstate, Mitsubishi, Progressive, and State Farm. The AT&T breach alone involved logs of calls and texts for over 100 million customers, while the Ticketmaster breach affected approximately 560 million users.
Moucka and his accomplices used the unauthorized access to identify valuable information within cloud storage instances. They attempted to extort multiple companies after stealing terabytes of data from their Snowflake tenant environments. Prosecutors stated that they obtained at least $2.5 million in bitcoin from at least three victims through ransom payments.
Moucka personally received at least $495,000 from ransoms and data sales on hacking forums such as BreachForums. The U.S. Department of Justice reported that victims of these hacks suffered $9.5 million in losses.
Authorities clarified that the breaches were not due to a flaw in Snowflake's platform itself. Instead, the attackers exploited customer accounts that had old, unrotated passwords, previously stolen by infostealer malware, and lacked multi-factor authentication. This highlights the importance of credential hygiene and the use of MFA for cloud security.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Connor Moucka, a Canadian citizen, pled guilty to hacking over 165 companies, stealing billions of records, and extorting several entities after breaching cloud provider Snowflake. This case highlights the significant impact of supply chain attacks on cloud infrastructure, leading to widespread data compromise and substantial financial losses for affected organizations and individuals.
Connor Riley Moucka pleaded guilty to computer fraud, wire fraud, and aggravated identity theft for his involvement in hacking 165 organizations' Snowflake accounts. This campaign, attributed to UNC5537, resulted in the theft of billions of sensitive data records and over $2.5 million in ransom payments, impacting major companies and millions of individuals.
Connor Riley Moucka pleaded guilty to computer fraud, wire fraud, and identity theft charges related to the 2024 Snowflake customer account breaches, which exposed records of at least 100 million people across 165 organizations. The breaches were attributed to the use of old, unrotated passwords stolen by infostealer malware, rather than a flaw in Snowflake's platform, highlighting the importance of credential hygiene and MFA.
A Canadian man, Connor Riley Moucka, pleaded guilty to charges related to accessing Snowflake cloud accounts and stealing data from at least 165 organizations. The attacks, conducted with an accomplice, exploited accounts without multi-factor authentication and resulted in the theft of sensitive personal and financial information, leading to extortion attempts and the sale of stolen data.
Connor Riley Moucka pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy related to breaching Snowflake and stealing data from at least 165 companies. This case highlights the significant impact of credential theft on data platforms and the potential for widespread data breaches affecting millions of individuals and numerous organizations.