← All stories
● Covered by 5 sources · 5 reportsHigh impact3 negative2 neutral

Canadian Man Pleads Guilty to Snowflake Hacks Affecting 165 Companies and Millions of Users

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Connor Riley Moucka pleaded guilty to multiple charges related to Snowflake breaches.
  • Data was stolen from at least 165 companies, affecting over 100 million individuals.
  • Breaches occurred between February and October 2024, exploiting accounts without MFA.
  • Moucka and accomplices obtained over $2.5 million from extortion and data sales.
  • Victims include AT&T, Ticketmaster, Advance Auto Parts, and Santander.

Guilty Plea in Snowflake Data Breaches

Connor Riley Moucka, a 26-year-old Canadian citizen, has pleaded guilty in a Washington state federal court to charges including computer fraud, wire fraud, aggravated identity theft, and a related conspiracy. The charges stem from his involvement in hacking customer accounts on the cloud data storage platform Snowflake.

Moucka, also known as Alexander Moucka and Waifu, was arrested in November 2024 and extradited to the U.S. in July 2025. He is scheduled for sentencing on October 27 and faces a potential prison sentence of up to 32 years, including a mandatory minimum of two years for identity theft.

Scope of the Attacks

Between February and October 2024, Moucka and his co-conspirators, including John Erin Binns, accessed Snowflake accounts using stolen login credentials. These accounts were not protected by multi-factor authentication (MFA), allowing access with only a username and password. The credentials had been harvested years prior by infostealer malware and were not rotated.

The intrusions affected at least 165 organizations, leading to the theft of billions of sensitive data records. Major companies impacted include AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, LendingTree, Anheuser-Busch, Allstate, Mitsubishi, Progressive, and State Farm. The AT&T breach alone involved logs of calls and texts for over 100 million customers, while the Ticketmaster breach affected approximately 560 million users.

Financial Gains and Impact

Moucka and his accomplices used the unauthorized access to identify valuable information within cloud storage instances. They attempted to extort multiple companies after stealing terabytes of data from their Snowflake tenant environments. Prosecutors stated that they obtained at least $2.5 million in bitcoin from at least three victims through ransom payments.

Moucka personally received at least $495,000 from ransoms and data sales on hacking forums such as BreachForums. The U.S. Department of Justice reported that victims of these hacks suffered $9.5 million in losses.

Nature of the Vulnerability

Authorities clarified that the breaches were not due to a flaw in Snowflake's platform itself. Instead, the attackers exploited customer accounts that had old, unrotated passwords, previously stolen by infostealer malware, and lacked multi-factor authentication. This highlights the importance of credential hygiene and the use of MFA for cloud security.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Connor Moucka, a Canadian citizen, pled guilty to hacking over 165 companies, stealing billions of records, and extorting several entities after breaching cloud provider Snowflake. This case highlights the significant impact of supply chain attacks on cloud infrastructure, leading to widespread data compromise and substantial financial losses for affected organizations and individuals.

Connor Riley Moucka pleaded guilty to computer fraud, wire fraud, and aggravated identity theft for his involvement in hacking 165 organizations' Snowflake accounts. This campaign, attributed to UNC5537, resulted in the theft of billions of sensitive data records and over $2.5 million in ransom payments, impacting major companies and millions of individuals.

Connor Riley Moucka pleaded guilty to computer fraud, wire fraud, and identity theft charges related to the 2024 Snowflake customer account breaches, which exposed records of at least 100 million people across 165 organizations. The breaches were attributed to the use of old, unrotated passwords stolen by infostealer malware, rather than a flaw in Snowflake's platform, highlighting the importance of credential hygiene and MFA.

A Canadian man, Connor Riley Moucka, pleaded guilty to charges related to accessing Snowflake cloud accounts and stealing data from at least 165 organizations. The attacks, conducted with an accomplice, exploited accounts without multi-factor authentication and resulted in the theft of sensitive personal and financial information, leading to extortion attempts and the sale of stolen data.

Connor Riley Moucka pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy related to breaching Snowflake and stealing data from at least 165 companies. This case highlights the significant impact of credential theft on data platforms and the potential for widespread data breaches affecting millions of individuals and numerous organizations.