LIVE · cybersecurity feed
Live wire
breach

Canadian man pleads guilty to Snowflake hacks that led to 165 breaches

A 26-year-old from Ontario faces as many as 32 years in prison after pleading guilty to fraud, identity theft and conspiracy charges related to the 2024 hacks of cloud platform Snowflake.

zeroday.news · 2h ago

A Canadian national has pleaded guilty to charges related to a widespread hacking campaign targeting customers of the data storage platform Snowflake, which resulted in the compromise of information from at least 165 companies. Connor Riley Moucka, 26, from Kitchener, Ontario, entered his plea in a Washington state federal court on Wednesday, facing charges of computer fraud, wire fraud, aggravated identity theft, and conspiracy. He is scheduled for sentencing on October 27 and could receive up to 32 years in prison.

Moucka and his co-conspirators are accused of breaching Snowflake customer accounts between February and October 2024. They leveraged stolen login credentials to access and exfiltrate billions of files containing sensitive data, including banking records, financial information, DEA registration numbers, driver’s license numbers, passport numbers, and Social Security numbers.

Among the high-profile victims were AT&T, where call and text logs for over 100 million customers were exposed, and Ticketmaster, which saw data from approximately 560 million users compromised. Other affected companies included Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, as well as one of the largest school districts in the United States.

Following the data theft, the group allegedly attempted to extort victim companies by threatening to publish the stolen information online. Prosecutors stated that the hackers collectively earned around $2.5 million in ransom payments. Court documents further reveal that Moucka re-extorted at least one victim, using the stolen data of a government officer and immediate family members of a former government officer in this second extortion attempt. Moucka also reportedly generated an additional $495,000 by selling some of the compromised data on cybercriminal forums such as BreachForums and XSS.is. Victim companies reportedly incurred approximately $9.5 million in losses due to these breaches.

The FBI characterized Moucka's actions as "calculated and predatory," emphasizing the harm inflicted on both the targeted companies and their millions of customers. Moucka was arrested in November 2024 and subsequently extradited to the U.S. in July 2025. Prior to his arrest, Moucka reportedly told a news outlet that he anticipated his detainment and had been destroying evidence.

Snowflake, the affected data storage platform, engaged Google's Mandiant unit to investigate the incident. Mandiant confirmed that the breaches were not due to vulnerabilities in Snowflake's platform security. Instead, the attackers exploited valid login credentials, some dating back to 2020, to access customer accounts. Mandiant's investigation indicated that the primary perpetrators of the campaign are based in North America, with an additional collaborator in Turkey. One individual, John Erin Binns, believed to be the Turkey-based hacker, was detained by Turkish authorities in 2024 after being indicted for his alleged role in a prior hack of telecom T-Mobile.

breachcloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hackers run khunt post-exploitation toolkit from Oracle database

Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. [...]

breach

Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals

Brown Health Medical Group-MA breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. Brown Health Medical Group-MA data breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. The healthcare group identified a data security breach involving a legacy file server on […]

ai

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm credentials to backdoor co-owned packages totaling over 1.3 billion monthly downloads.

vulnerability

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers

An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there the attacker runs code on the host. Bonita BPM handles loan approvals, insurance claims, and employee onboarding for banks, insurers, and government agencies, and its internal surface answers to strangers. Vulnerability resea

vulnerability

Flaws in Google APK for Python Unlock Agent-to-Agent Attack

Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain.

cloud

Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)

When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every supply-chain incident I have worked. In the keyv/cacheable compromise that has been unfolding since yesterday, it is the one thing you should not do first — because revoking the sto