A Canadian national has pleaded guilty to charges related to a widespread hacking campaign targeting customers of the data storage platform Snowflake, which resulted in the compromise of information from at least 165 companies. Connor Riley Moucka, 26, from Kitchener, Ontario, entered his plea in a Washington state federal court on Wednesday, facing charges of computer fraud, wire fraud, aggravated identity theft, and conspiracy. He is scheduled for sentencing on October 27 and could receive up to 32 years in prison.
Moucka and his co-conspirators are accused of breaching Snowflake customer accounts between February and October 2024. They leveraged stolen login credentials to access and exfiltrate billions of files containing sensitive data, including banking records, financial information, DEA registration numbers, driver’s license numbers, passport numbers, and Social Security numbers.
Among the high-profile victims were AT&T, where call and text logs for over 100 million customers were exposed, and Ticketmaster, which saw data from approximately 560 million users compromised. Other affected companies included Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, as well as one of the largest school districts in the United States.
Following the data theft, the group allegedly attempted to extort victim companies by threatening to publish the stolen information online. Prosecutors stated that the hackers collectively earned around $2.5 million in ransom payments. Court documents further reveal that Moucka re-extorted at least one victim, using the stolen data of a government officer and immediate family members of a former government officer in this second extortion attempt. Moucka also reportedly generated an additional $495,000 by selling some of the compromised data on cybercriminal forums such as BreachForums and XSS.is. Victim companies reportedly incurred approximately $9.5 million in losses due to these breaches.
The FBI characterized Moucka's actions as "calculated and predatory," emphasizing the harm inflicted on both the targeted companies and their millions of customers. Moucka was arrested in November 2024 and subsequently extradited to the U.S. in July 2025. Prior to his arrest, Moucka reportedly told a news outlet that he anticipated his detainment and had been destroying evidence.
Snowflake, the affected data storage platform, engaged Google's Mandiant unit to investigate the incident. Mandiant confirmed that the breaches were not due to vulnerabilities in Snowflake's platform security. Instead, the attackers exploited valid login credentials, some dating back to 2020, to access customer accounts. Mandiant's investigation indicated that the primary perpetrators of the campaign are based in North America, with an additional collaborator in Turkey. One individual, John Erin Binns, believed to be the Turkey-based hacker, was detained by Turkish authorities in 2024 after being indicted for his alleged role in a prior hack of telecom T-Mobile.






