Connor Riley Moucka, the 26-year-old Canadian national behind the massive 2024 Snowflake data breach campaign, has pleaded guilty in Seattle federal court. Operating as part of the threat actor group designated by Mandiant as UNC5537, Moucka admitted to charges of computer fraud, wire fraud, aggravated identity theft, and conspiracy after systematically infiltrating cloud data environments, exposing sensitive records belonging to at least 100 million individuals.
The guilty plea brings legal closure to one of the most damaging cloud supply-chain extortion campaigns in recent years. Federal court filings show that Moucka personally extorted at least $495,000 from ransoms and illicit data sales. Meanwhile, victim organizations suffered more than $9.5 million in direct actual losses—a figure that excludes downstream damages borne by their affected customers.
How Old Infostealer Logins Fueled the Snowflake Data Breach
What made UNC5537’s campaign so widespread was not a zero-day vulnerability or an architectural flaw within the Snowflake platform itself, but persistent gaps in baseline identity hygiene. Attackers gained access entirely through valid customer credentials harvested years earlier by infostealer malware running on personal or unmanaged corporate devices.
Mandiant’s investigation revealed that every intrusion it analyzed traced back to credentials stolen by infostealer logs—some harvested as far back as November 2020 that remained active and unrotated years later. At least 79.7% of the compromised accounts used by the group had prior public credential exposure. These stolen usernames and passwords were used to authenticate directly against target Snowflake instances where multi-factor authentication (MFA) was turned off and no IP network allowlists were configured.
In cloud software-as-a-service (SaaS) environments, identity serves as the network perimeter. When multi-factor verification is absent and network access is unrestricted, valid credentials give attackers direct administrative or database control. UNC5537 leveraged these exposed accounts to execute automated bulk data exfiltration directly from victim data warehouses into actor-controlled infrastructure.
The Scope, Tactics, and Blast Radius of the Extortion Campaign
The intrusions reached at least 165 organizations (with Justice Department statements citing between 150 and 165 affected customer accounts). The blast radius spanned multiple critical sectors, resulting in the theft of non-content call and text histories, employee payroll data, Drug Enforcement Administration (DEA) registration numbers, passport details, and Social Security numbers.
Among the most prominent impacted organizations was AT&T, which confirmed in July 2024 that call and text records for nearly all of its wireless subscribers between May 1 and October 31, 2022, were exfiltrated from its third-party cloud workspace.
When victim companies resisted initial payment demands, Moucka escalated his tactics. Prosecutors noted that Moucka re-extorted at least one victim organization, threatening public disclosure using stolen personal data belonging to a government officer and members of a former government officer’s immediate family. W. Mike Herrington, Special Agent in Charge of the FBI’s Seattle Field Office, characterized the threat actor’s methods as “calculated and predatory.”
Legal Proceedings and Co-Defendants
Moucka, of Kitchener, Ontario, is scheduled to be sentenced on October 27. He faces a two-year mandatory minimum sentence on the aggravated identity theft count and up to 30 years in prison on the remaining fraud and conspiracy counts.
Federal law enforcement has tied several individuals to this intrusion series:
- Connor Riley Moucka: Pleaded guilty to four federal counts in Seattle on Wednesday.
- Cameron John Wagenius: A former U.S. Army soldier linked to the intrusions who pleaded guilty in a related case in July 2025.
- John Erin Binns: Indicted alongside Moucka in October 2024, Binns remains outside U.S. custody as of court updates on August 4.
Hardening Cloud SaaS Workspaces Against Identity Abuse
The Snowflake breaches underscored how legacy authentication defaults in cloud environments create systemic exposure across thousands of enterprise tenants. In response to the campaign, Snowflake began enforcing MFA by default for human users on newly created accounts in October 2024. However, single-factor password sign-ins have not been entirely eliminated. Snowflake documentation indicates a phased rollout scheduled between August and October 2026 that will block password-only authentication across remaining legacy human and service accounts, exempting only reader and trial environments.
To protect cloud data warehouses and SaaS tenants from infostealer-driven account takeovers, security teams should immediately enforce the following technical mitigations:
- Mandate Non-Bypassable Multi-Factor Authentication: Enforce phishing-resistant MFA (such as FIDO2 WebAuthn or hardware security keys) across all active and legacy cloud platform accounts. Ensure legacy single-factor password authentication pathways are explicitly disabled at the identity provider (IdP) level.
- Implement Network Allowlisting: Configure strict network policies and IP allowlists on cloud data warehouse instances, restricting access exclusively to known enterprise egress IPs, secure VPN endpoints, or dedicated network tunnels.
- Eliminate Static Credentials for Non-Human Accounts: Audit service accounts and programmatic API connections to ensure they do not rely on static passwords. Transition service authentication to key-pair authentication, short-lived OAuth tokens, or managed identities with restricted role permissions.
- Integrate Infostealer Intelligence: Ingest dark-web infostealer credential feeds into Identity and Access Management (IAM) and Security Information and Event Management (SIEM) systems to automatically revoke sessions and force password resets whenever corporate domain credentials appear in breach logs.
Related content
Canadian Man Pleads Guilty in Massive Snowflake Cloud Data Theft Scheme
Security NewsAccenture Confirms Data Breach After Source Code and Credentials Stolen
Security NewsAccenture Faces Data Breach: 35GB of Source Code Allegedly Stolen
Security NewsAesto Discloses AWS Cloud Breach Exposing 9.5 Million Patient Records
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call