A Canadian man has pleaded guilty to his role in a large-scale Snowflake data theft campaign that compromised cloud accounts at at least 165 organisations.

Connor Riley Moucka, 26, admitted to accessing customer accounts at cloud storage provider Snowflake and stealing data later used in extortion attempts. According to US prosecutors, the breaches affected more than 100 million people and caused victim companies over $9.5 million in losses.

Moucka, also known online as Alexander Moucka and Waifu, was arrested in October 2024.

Stolen credentials gave attackers cloud access

Court documents say Moucka and alleged co-conspirator John Erin Binns targeted Snowflake customer accounts between February and October 2024.

The attackers used usernames and passwords stolen by infostealer malware to log into accounts that did not have multi-factor authentication enabled. With MFA absent, valid credentials were enough to access the targeted cloud environments.

Once inside, they allegedly used custom software to identify valuable data held in Snowflake storage instances. The tools helped them review details such as organisation names, user roles, and IP addresses before stealing data from selected victims.

The Snowflake data theft operation allegedly resulted in the theft of terabytes of information from customer environments.

Financial, identity and communication data stolen

The stolen information included a broad range of sensitive records, including:

  • Non-content call and text history records
  • Banking and financial information
  • Payroll files
  • DEA registration numbers
  • Driver’s licence and passport numbers
  • Social Security numbers
  • Other personally identifiable information

The Department of Justice said Moucka and Binns attempted to extort multiple companies after taking the data. They allegedly received at least $2.5 million in Bitcoin from at least three victims.

The pair also promoted stolen information for sale on hacker forums in exchange for cryptocurrency or traditional currency. Prosecutors say Moucka made at least $495,000 through those sales.

Prosecutors describe repeat extortion attempt

The Justice Department said the campaign included at least one case of re-extortion.

In that incident, Moucka allegedly threatened to disclose a victim’s stolen data again. Prosecutors said he used information belonging to a government officer and members of a former government officer’s immediate family during the attempt.

The case highlights how stolen cloud data can continue to expose organisations and individuals long after an initial breach. Attackers can use the same information for resale, fresh extortion demands, fraud, and identity theft.

Sentencing scheduled for October

Moucka pleaded guilty to four counts: computer fraud, wire fraud, aggravated identity theft, and a related conspiracy charge.

He is scheduled to be sentenced on October 27 and faces a maximum prison sentence of 32 years.

Binns was living in Turkey when he was arrested. A local court approved a US extradition request, although that decision was contested.

Organisations reportedly affected by the Snowflake data theft attacks include AT&T, Ticketmaster, Santander, Pure Storage, Advance Auto Parts, Los Angeles Unified, QuoteWizard/LendingTree, and Neiman Marcus.

After the breaches, Snowflake said it would enforce MFA protections and require customer passwords to contain at least 14 characters. The incident serves as a clear reminder that strong passwords alone are not enough to protect sensitive cloud accounts.


0 responses to “Canadian Man Pleads Guilty in Snowflake Data Theft Attacks”