grid
Abstract circular gradient with concentric rings in blue, green, yellow, and red fading into black background.
5 min read

Snowflake Data Theft: Canadian Hacker Pleads Guilty to 165 Hacks

Snowflake Data Theft
Published on
August 6, 2026

A 26-year-old man from Kitchener, Ontario has admitted to running one of the largest cloud intrusion campaigns on record. Connor Riley Moucka pleaded guilty on August 5 to four federal counts tied to the Snowflake data theft attacks of 2024. The scheme compromised at least 165 customer organizations. Prosecutors say the operation exposed billions of records and touched more than 100 million people.

A judge in the Western District of Washington will sentence him on October 27. He faces a two-year mandatory minimum on one count and up to 30 years on the other three. The Snowflake data theft case has moved through the courts for nearly two years since his arrest.

Stolen Logins and Missing Multi-Factor Authentication

The Snowflake data theft intrusions ran from February to October 2024. Moucka and his co-conspirators never exploited a flaw in the Snowflake platform. They logged in with valid usernames and passwords lifted from computers infected with infostealer malware. Those credentials worked because the targeted customer accounts had no multi-factor authentication switched on.

Infostealers harvest saved browser passwords, session cookies and other credentials from infected machines. Criminal markets then sell the resulting logs in bulk, often for a few dollars per victim. One set of corporate credentials in a batch like that can open a cloud tenant holding millions of customer records.

Court documents describe custom software the group built to survey each compromised environment. The tool pulled organization names, user roles and IP addresses, which let the attackers rank targets by value before they moved any files. That approach turned the Snowflake data theft operation into an assembly line rather than a run of one-off break-ins.

What the Attackers Took

The Snowflake data theft campaign swept up some of the most sensitive categories of personal information in circulation. Investigators listed non-content call and text history records, banking and financial details, and payroll files. Driver's license numbers, passport numbers and Social Security numbers appear on that list too.

Drug Enforcement Administration registration numbers turned up in the haul as well. Those identifiers belong to medical professionals licensed to prescribe controlled substances. In criminal hands they support prescription fraud and convincing impersonation of clinicians.

Victim companies reported more than $9.5 million in direct losses. That figure leaves out what their customers lost, and at least 100 million individuals sit downstream of the stolen files. Terabytes of data moved off cloud servers over those eight months.

Extortion, Resale and a Second Round of Demands

Extortion drove the Snowflake data theft scheme from the start. The group pressed victims for payment and threatened to publish the stolen files, and the conspiracy collected more than $2.5 million in ransom. Moucka also advertised data for sale on BreachForums, Exploit.in, XSS.is and Telegram. Those sales alone earned him at least $495,000.

One victim paid and then heard from him a second time. Prosecutors say he came back with fresh threats to release more of the same material. He used records belonging to a government officer and to the family of a former government officer as leverage.

That detail carries weight for any company weighing a ransom demand. Payment bought no guarantee here, and the same files returned as pressure a second time. Law enforcement agencies point to cases like this one when they advise against paying.

The Companies Named in the Snowflake Data Theft Attacks

Public reporting has linked a long list of familiar brands to the campaign. AT&T, Ticketmaster, Santander, Neiman Marcus and Advance Auto Parts all disclosed incidents that stemmed from compromised cloud accounts. Pure Storage, Los Angeles Unified School District and LendingTree subsidiary QuoteWizard round out the named victims.

That spread explains why the Snowflake data theft campaign dominated security coverage through 2024. Telecom records, ticketing databases, banking details and student information all moved through the same set of stolen logins. One weak authentication setting per tenant produced across-sector spill.

Attackers never breached Snowflake itself. The platform held up, and the failures sat inside individual customer configurations. That distinction shaped the response, because customers absorbed the notification costs and the regulatory exposure. Shared responsibility models put authentication settings on the tenant, and hundreds of tenants left them at the weakest option.

Where the Case Goes Next

Canadian authorities arrested Moucka on October 30, 2024, roughly six months after the Snowflake data theft intrusions began. The United States secured his extradition in July 2025. His plea covers computer fraud, wire fraud, aggravated identity theft and a related conspiracy count.

John Erin Binns faces charges in the same indictment. Turkish authorities arrested him, and a local court approved the American extradition request, though that decision drew a challenge. His case remains unresolved in public records. Prosecutors have not said what a conviction there would add to the picture.

Snowflake responded to the 2024 attacks by enforcing multi-factor authentication and requiring passwords of at least 14 characters. Other cloud providers have shifted their defaults in the same direction since.The Snowflake data theft prosecution closes one chapter, but the exposure it exploited still sits open across thousands of SaaS tenants. Credential logs stay cheap, employee machines keep leaking passwords, and a password on its own no longer counts as a control.

Subscribe to newsletter

Subscribe to receive the latest blog posts to your inbox every week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.