A Canadian man has pleaded guilty to charges related to the hacking of customer accounts at cloud storage provider Snowflake, an incident that led to the theft of data from over 165 organizations. Connor Riley Moucka, 26, of Kitchener, Ontario, also known by the online monikers "Waifu" and "Judische," entered his plea in a federal court in Washington state. He faces a potential sentence of up to 32 years in prison, with sentencing scheduled for October 27.
Moucka admitted to charges of computer fraud, wire fraud, aggravated identity theft, and conspiracy. The FBI characterized his actions as targeting U.S. companies, stealing sensitive information, and extorting victims for millions of dollars.
Between April and September 2024, Moucka and his co-conspirators utilized stolen credentials to gain unauthorized access to Snowflake customer accounts. Once inside, they downloaded terabytes of sensitive information. This data included non-content call and text records, banking and financial details, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver's license numbers, passport numbers, and Social Security numbers, among other personally identifiable information.
The group then demanded ransom payments, threatening to publish or sell the stolen data if their demands were not met. The conspirators collectively received over $2.5 million in these ransom payments. Moucka's personal share from the scheme amounted to at least $495,000.
In one instance, Moucka attempted a secondary extortion against a victim, threatening to disclose additional stolen data. This particular attempt involved personal information belonging to a government official and immediate family members of a former government official. The stolen data was also advertised for sale on various online forums, including BreachForums, Exploit.in, XSS.is, and Telegram.
The U.S. Justice Department reported that the direct financial losses to the victim companies exceeded $9.5 million. This figure does not account for the losses incurred by the companies' customers, which impacted at least 100 million individuals.
Organizations publicly identified as being affected by the Snowflake campaign include AT&T, Ticketmaster, Santander, Advance Auto Parts, LendingTree, Neiman Marcus, Pure Storage, and Bausch Health. The FBI emphasized that Moucka's "calculated and predatory" re-extortion tactics caused significant harm to both the targeted companies and the millions of individuals whose personal information was compromised.






