Snowflake Hacker Pleads Guilty to Massive Data Breaches

Connor Riley Moucka, a 26-year-old from Kitchener, Ontario, has pleaded guilty in a Seattle federal court to charges including computer fraud, wire fraud, aggravated identity theft, and conspiracy. These charges stem from his involvement in the 2024 breaches of Snowflake customer accounts, which impacted at least 165 organizations and exposed the personal data of over 100 million individuals. Moucka personally profited approximately $495,000 through ransoms and the sale of stolen data. His sentencing is scheduled for October 27, where he faces a mandatory minimum of two years for identity theft and up to 30 years for the other charges.

The breaches were facilitated by the exploitation of outdated credentials. Attackers utilized login information harvested by infostealer malware years prior, which remained unchanged and lacked multi-factor authentication (MFA). Notably, there was no exploitation of vulnerabilities within the Snowflake platform itself. The Department of Justice has not publicly named the affected company; however, Snowflake and cybersecurity firm Mandiant identified the platform in 2024.

Prosecutors revealed that Moucka engaged in re-extortion tactics, threatening to disclose sensitive data of government officials and their families to coerce victims further. W. Mike Herrington, special agent in charge of the FBI’s Seattle field office, described these actions as “calculated and predatory.” Mandiant’s investigation, tracking the actor as UNC5537, found that every incident was linked to customer credentials stolen by infostealers, some dating back to November 2020. Alarmingly, 79.7% of the compromised accounts had prior credential exposures, and the affected instances lacked network allow lists.

The scale of the breach is significant, with victim companies incurring over $9.5 million in losses, excluding the impact on their customers. Stolen data included non-content call and text histories, payroll records, Drug Enforcement Administration (DEA) registration numbers, passport details, and Social Security numbers. In July 2024, AT&T confirmed that records of calls and texts for nearly all its cellular customers between May 1 and October 31, 2022, were taken from its workspace on a third-party cloud platform.

Among the individuals charged in 2024, only Moucka is currently in U.S. custody. Co-defendant John Erin Binns remains at large, while former Army soldier Cameron John Wagenius pleaded guilty in a related case in July 2025. In response to these breaches, Snowflake has enforced MFA by default for human users on accounts created since October 2024. However, as of August 6, 2026, password-only sign-ins have not been entirely phased out. The final phase, scheduled between August and October 2026, aims to eliminate passwords as the sole authentication factor for all remaining human users.

This case underscores the critical importance of robust cybersecurity practices, particularly the regular updating of credentials and the implementation of multi-factor authentication. Organizations must remain vigilant against the persistent threat posed by cybercriminals who exploit outdated security measures to access sensitive data.