VYPR
breachPublished Aug 5, 2026· 2 sources

Canadian Man Pleads Guilty in Massive Snowflake Data Breach Conspiracy

An Ontario man has pleaded guilty to charges related to the 2024 attacks on cloud data platform Snowflake, which resulted in approximately 165 data breaches.

Connor Riley Moucka, a 26-year-old Canadian national from Kitchener, Ontario, has pleaded guilty to multiple federal charges in a Washington state court, including computer fraud, wire fraud, aggravated identity theft, and conspiracy. The plea marks a significant development in the investigation into the widespread data breaches that exploited the cloud data storage platform Snowflake.

Moucka and his co-conspirators are accused of breaching Snowflake between February and October 2024 by using stolen login credentials. This access allowed them to exfiltrate vast amounts of sensitive data from at least 165 companies. The stolen information included banking records, financial details, Drug Enforcement Administration (DEA) registration numbers, driver's license numbers, passport numbers, and Social Security numbers, among other personal and corporate data.

The scale of the breaches was immense, impacting major organizations such as AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, as well as a large U.S. school district. The breach affecting AT&T alone compromised the call and text logs of over 100 million customers, while the Ticketmaster incident impacted approximately 560 million users.

Following the data theft, the hackers attempted to extort victim companies by threatening to publish the stolen information online. The group reportedly amassed around $2.5 million in ransom payments. Court documents revealed that Moucka engaged in further predatory tactics, including re-extorting at least one victim by leveraging the stolen data of a government official and their family.

In addition to ransom demands, Moucka also profited by selling some of the pilfered data on dark web forums like BreachForums and XSS.is, earning an additional $495,000. The total losses incurred by victim companies due to these breaches are estimated to be around $9.5 million.

Moucka was arrested in November 2024 and subsequently extradited to the United States in July 2025. FBI Special Agent in Charge W. Mike Herrington stated that Moucka's actions were "calculated and predatory," causing significant harm to both targeted companies and millions of individuals whose data was compromised.

An investigation by Google's Mandiant unit, hired by Snowflake, concluded that the platform itself did not suffer a security failure. Instead, the attackers exploited still-valid credentials that dated back to 2020, gaining access to company accounts through these compromised login details. Mandiant noted that the threat actors involved were primarily based in North America, with an additional member in Turkey.

Moucka is scheduled for sentencing on October 27 and faces a maximum prison sentence of 32 years. His guilty plea underscores the severe legal consequences for individuals involved in large-scale cybercrime operations targeting cloud infrastructure and customer data.

The Justice Department announced that Connor Moucka, a Canadian national, has pleaded guilty for his significant role in the widespread compromise of over 165 Snowflake customer environments. Moucka, who operated under aliases such as "Waifu" and "Judische," earned $495,000 through extortion and selling stolen data, and is linked to the broader cybercriminal network known as The Com. He faces up to 32 years in prison.

Synthesized by Vypr AI