Connor Riley Moucka, a 26-year-old Canadian national known online as “Waifu” and “Alexander Moucka,” has pleaded guilty in U.S. federal court for his central role in the widespread Snowflake cloud data theft campaign that compromised at least 165 enterprise organizations between February and October 2024. Moucka was arrested on October 30, 2024, following an international law enforcement operation targeting the extortion ring responsible for one of the largest enterprise cloud compromise sprees in recent history. The Snowflake breach campaign impacted over 100 million individuals and resulted in more than $9.5 million in direct financial losses across affected organizations.
Moucka pleaded guilty to four federal counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy to commit computer fraud. He is scheduled for sentencing on October 27, 2025. His co-conspirator, John Erin Binns, was previously arrested in Turkey, where U.S. extradition proceedings remain actively contested in local courts.
How the Snowflake Account Takeovers Occurred
The campaign did not rely on a zero-day vulnerability in Snowflake’s underlying cloud architecture or platform software. Instead, the threat actors executed targeted account takeover (ATO) attacks against customer tenant environments by exploiting widespread authentication weaknesses—specifically, single-factor authentication paired with enterprise credentials harvested via infostealer malware.
Prior to the campaign, login credentials belonging to corporate employees and contractors were compromised through end-user infections involving infostealers such as Lumma, RedLine, and Vidar running on personal or unmanaged devices. Because many victim organizations had not enabled multi-factor authentication (MFA) on their Snowflake administrative or user accounts, the attackers needed only valid username and password pairs to authenticate successfully.
Once initial access was secured, Moucka and Binns utilized custom software to automate post-exploitation reconnaissance and data exfiltration. Their custom tools queried Snowflake metadata views to identify high-value tables containing personally identifiable information (PII), customer call records, financial transactions, internal user roles, and IP logs. The actors then exfiltrated terabytes of sensitive data directly from victim tenant storage instances to attacker-controlled infrastructure.
Cloud data warehouses present a uniquely high blast radius for credential-based attacks. Because organizations centralize vast repositories of structured analytics data, customer databases, and operational logs inside a single cloud platform, compromising a single administrative or high-privileged user account without MFA grants attackers unfettered SQL query access to the organization’s entire data estate.
Extortion Operations and Monetization
Following exfiltration, Moucka and Binns systematically extorted victim companies, demanding massive ransom payments in cryptocurrency under threat of publishing or selling the stolen data on cybercrime platforms such as BreachForums and Telegram.
The extortion ring successfully coerced at least three victim organizations into paying a combined $2.5 million in bitcoin. In addition to direct ransom payments, Moucka earned at least $495,000 by advertising and selling stolen enterprise databases to third parties on underground hacker forums.
Court filings reveal particularly aggressive re-extortion tactics used during the campaign. In at least one instance, Moucka attempted to re-extort a victim organization that had already been targeted, leveraging stolen personal records belonging to a U.S. government official and members of their immediate family to escalate pressure on executives.
Impacted Organizations and Blast Radius
The scale of the breach spanned multiple major enterprise sectors, including telecommunications, entertainment, retail, financial services, and education. Among the prominent organizations confirmed to have suffered tenant compromises and data theft in the campaign are:
- AT&T: Exfiltration of call and text log records covering nearly all AT&T cellular customers over a multi-month period.
- Ticketmaster / Live Nation: Compromise of customer payment details, ticketing histories, and personal information for tens of millions of users.
- Santander Bank: Breach involving customer and employee data across multiple international branches.
- Pure Storage: Unauthorized access to telemetry and customer support data environments hosted on Snowflake.
- Advance Auto Parts: Theft of massive customer databases and employee records.
- Los Angeles Unified School District (LAUSD): Compromise of educational and administrative records.
- QuoteWizard / LendingTree: Exposure of sensitive consumer financial quote and lead data.
- Neiman Marcus: Breach of retail customer accounts and order histories.
In total, the financial impact exceeds $9.5 million in direct incident response, remediation, and extortion expenses, with personal data exposures impacting well over 100 million individuals globally.
Platform Changes and Hardening Requirements
In response to the campaign, Snowflake updated its platform security defaults, making multi-factor authentication mandatory across all customer organizations and enforcing a minimum password length requirement of 14 characters.
To safeguard cloud data warehouse environments against credential-stuffing and infostealer-based account takeovers, security teams operating Snowflake or similar SaaS analytics platforms should immediately verify the following technical controls:
- Mandate Identity Provider SSO with Phishing-Resistant MFA: Require all human accounts to authenticate exclusively through an Enterprise Identity Provider (IdP) enforcing WebAuthn/FIDO2 hardware tokens or push-based MFA with number matching.
- Enforce Network Policies: Configure Snowflake Network Policies (
CREATE NETWORK POLICY) to restrict account login access solely to explicit corporate public IP ranges, trusted VPN egress points, or private connectivity options such as AWS PrivateLink or Azure Private Link. - Disable Password Auth on Service Accounts: Transition all automated, programmatic, and service accounts from basic password authentication to key-pair authentication (
RSA_PUBLIC_KEY), ensuring private keys are secured in dedicated key management systems. - Audit Historic Authentication Logs: Run queries against the
SNOWFLAKE.ACCOUNT_USAGE.LOGIN_HISTORYview to identify historic successful logins originating from non-MFA connections, foreign IP addresses, or uncommon user-agent strings between February and October 2024.
Related content
Snowflake Hacker Connor Moucka Pleads Guilty to Extorting 165 Organizations
Security NewsSnowflake Hacker Connor Riley Moucka Pleads Guilty to Mass Extortion Campaign
Security NewsAccenture Confirms Data Breach After Source Code and Credentials Stolen
Security NewsAccenture Faces Data Breach: 35GB of Source Code Allegedly Stolen
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call