Connor Riley Moucka pleaded guilty for his role in the Snowflake data breach campaign affecting 165 organizations worldwide.
A Canadian man accused of taking part in the 2024 cyberattack campaign targeting Snowflake customer accounts has pleaded guilty in a U.S. federal court, admitting his role in a widespread data theft and extortion operation.
Connor Riley Moucka, 26, pleaded guilty on August 5, 2026, in the U.S. District Court for the Western District of Washington to charges including conspiracy, computer fraud, wire fraud, and aggravated identity theft.
The case relates to a series of attacks in which cybercriminals gained access to customer environments hosted on Snowflake, a cloud-based data platform used by many large organizations. Investigators said the attackers did not exploit a vulnerability in Snowflake’s infrastructure, but instead used usernames and passwords stolen through infostealer malware.
The compromised accounts did not have multi-factor authentication (MFA) enabled, allowing attackers to access and steal large volumes of sensitive information. Prosecutors said the group stole billions of customer records affecting more than 100 million individuals across at least 165 organizations.
After obtaining the stolen data, Moucka and his associates attempted to extort victims by demanding payment in exchange for not releasing or selling the information. According to prosecutors, Moucka personally received at least $495,000 through extortion payments and the sale of stolen data.
The affected organizations included several major companies, including AT&T, Ticketmaster, Santander, Advance Auto Parts, LendingTree, Neiman Marcus, and Pure Storage.
The Snowflake-related breaches became one of the most significant credential-based cybercrime campaigns of 2024, highlighting the risks associated with compromised passwords and the importance of multi-factor authentication for protecting cloud environments.
Following the incidents, Snowflake introduced stronger security requirements, including mandatory multi-factor authentication for new customer accounts, while encouraging existing customers to adopt additional security protections.
Moucka is scheduled to be sentenced on October 27, 2026. He faces up to 30 years in prison for the conspiracy, computer fraud, and wire fraud charges, along with a mandatory consecutive two-year sentence for aggravated identity theft, resulting in a potential maximum sentence of 32 years.
The investigation into the wider cybercriminal group remains ongoing, as authorities continue efforts to identify and prosecute other individuals connected to the operation.
Source: Department of Justice and Hacker News
Related articles :
__Reports are sourced from official documents, law-enforcement updates, and credible investigations.
Discover additional reports, market trends, crime analysis and Harm Reduction articles on DarkDotWeb to stay informed about the latest dark web operations.__