Connor Moucka, a 26-year-old Canadian national, has admitted to orchestrating a series of cyberattacks that compromised over 165 companies, resulting in the theft of billions of records and subsequent extortion attempts. The U.S. Department of Justice announced his guilty plea on August 6, 2026.
Moucka’s criminal activities centered around exploiting vulnerabilities in cloud service provider Snowflake. By infiltrating Snowflake’s infrastructure, he and his accomplices gained unauthorized access to the data of numerous clients, including major corporations such as AT&T, LendingTree, and Ticketmaster. The breaches led to the exposure of sensitive information from more than 100 million AT&T customers, encompassing call logs, text message records, banking details, driver’s license numbers, and Social Security numbers.
Over the course of these cyber intrusions, Moucka and his co-conspirators extorted victims for over $2.5 million in ransom payments. Additionally, they profited approximately $500,000 by selling stolen data on notorious hacking forums like BreachForums. The cumulative financial impact on the affected companies is estimated at $9.5 million.
FBI Special Agent W. Mike Herrington, involved in the investigation, highlighted the severity of Moucka’s actions, emphasizing the calculated and predatory nature of his threats and extortion tactics, which inflicted significant harm on both corporate entities and millions of individual customers.
Operating under the online aliases ‘Waifu’ and ‘Judische,’ Moucka was apprehended in Canada in late 2024, mere months following the Snowflake breaches. His sentencing is scheduled for October 27, where he faces the possibility of decades-long imprisonment.
This case underscores the critical importance of robust cybersecurity measures for cloud service providers and their clients. The extensive reach and sophistication of Moucka’s attacks serve as a stark reminder of the vulnerabilities inherent in digital infrastructures. Organizations must prioritize the implementation of comprehensive security protocols, including multi-factor authentication and regular system audits, to safeguard sensitive data against increasingly sophisticated cyber threats.