Technology
Hacker Pleads Guilty to Stealing Data from More Than 165 Snowflake Customers
A 26-year-old Canadian man has pleaded guilty in U.S. federal court to his involvement in a widespread hacking campaign that targeted customers of the cloud data platform Snowflake. Connor Riley Moucka admitted to helping compromise more than 165 organizations, stealing vast amounts of sensitive data, and participating in extortion efforts that generated millions of dollars.The plea marks a significant development in one of the largest known data-theft campaigns involving a major cloud service provider’s customers.Details of the Guilty PleaMoucka, of Kitchener, Ontario, pleaded guilty to charges including computer fraud, wire fraud, aggravated identity theft, and a related conspiracy. He is scheduled to be sentenced on October 27 and faces a mandatory minimum of two years on the identity theft count, with a potential maximum of around 30 years on the remaining charges.According to court documents and the U.S. Department of Justice, between February and October 2024 Moucka and co-conspirators used stolen login credentials to gain unauthorized access to the cloud environments of at least 165 Snowflake customers.How the Attacks WorkedThe attackers primarily relied on previously stolen credentials—often harvested by infostealer malware—that had not been rotated and belonged to accounts lacking multi-factor authentication. Once inside customer Snowflake environments, they downloaded terabytes of data containing highly sensitive information.Stolen data included:Personal and financial records
Call and text history information
Payroll details
Driver’s license, passport, and Social Security numbers
Other personally identifiable information
High-profile organizations affected in the broader campaign included major companies in telecommunications, finance, retail, and entertainment.Extortion and Financial ImpactAfter stealing the data, the group extorted victims by threatening to publish or sell the information. Prosecutors say the conspirators received approximately $2.5 million in ransom payments (paid in cryptocurrency). Moucka personally obtained at least $495,000 from the scheme, including through data sales on cybercrime forums.Victim organizations incurred more than $9.5 million in direct losses related to ransoms and response costs. That figure does not include downstream harm to the more than 100 million individuals whose personal information was exposed.Law Enforcement ActionMoucka was arrested in Canada in late 2024 and later extradited to the United States. A co-conspirator has also faced charges in connection with the campaign. The investigation involved cooperation among multiple international law enforcement agencies.Broader ImplicationsThe Snowflake customer breaches highlighted ongoing risks associated with credential-based attacks and the importance of strong authentication practices. Even when a cloud platform itself is not directly compromised, weak security configurations on the customer side can expose large volumes of sensitive data.The case has reinforced industry recommendations around:Enforcing multi-factor authentication
Regular credential rotation
Monitoring for unusual data access patterns
Zero-trust approaches to cloud environments
Looking AheadSentencing is expected later this year. The plea provides further accountability in a campaign that affected dozens of organizations and millions of individuals. It also serves as a reminder of the persistent threat posed by credential theft and the high value criminals place on large-scale data repositories.Organizations that use cloud data platforms continue to be urged to review their security configurations and access controls to reduce similar risks.Final ThoughtsThe guilty plea by Connor Riley Moucka brings a measure of resolution to one of the more significant cloud-related data theft and extortion campaigns of recent years. By admitting responsibility for helping compromise more than 165 Snowflake customers and participating in the subsequent extortion, the case underscores both the scale of modern cybercrime and the importance of basic security hygiene in cloud environments.
Comments (0)
Please log in to comment
No comments yet. Be the first!