LIVE · cybersecurity feed
Live wire
security

Snowflake hacker pleads guilty, faces up to 32 years in prison

Connor Moucka obtained almost $500,000 for playing a key role in one of the most widespread and damaging cyberattack sprees on record. The post Snowflake hacker pleads guilty, faces up to 32 years in prison appeared first on CyberScoop.

zeroday.news · 1h ago

A Canadian man has pleaded guilty to charges related to a widespread cyberattack campaign that compromised over 165 customer environments of the data storage platform Snowflake in 2024. Connor Moucka, also known by online aliases such as Waifu, Judische, Catist, and Ellyel8, was arrested in Kitchener, Ontario, on October 30, 2024, and extradited to the United States in March 2025. He faces up to 32 years in prison, with sentencing scheduled for October 27.

Moucka pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy. Prosecutors allege he earned $495,000 through extortion and by selling stolen data online. In one instance, he re-extorted a victim using data belonging to a government official and their immediate family.

The cyberattack campaign, which Moucka allegedly carried out with co-conspirators John Binns and Cameron Wagenius, involved using stolen credentials to access customer accounts on the Snowflake platform. The group is said to have stolen billions of sensitive records and received over $2.5 million in combined extortion payments. Victims included major companies such as AT&T, Ticketmaster, Advance Auto Parts, and Santander.

The stolen data reportedly exposed records of more than 100 million individuals, encompassing call and text history, banking and financial information, payroll records, government identification numbers, and other personally identifiable data. Officials estimate that the victim companies incurred over $9.5 million in losses, excluding those borne by their customers.

Moucka and his alleged co-conspirators are associated with "The Com," a cybercriminal network reportedly composed of minors and young adults involved in various illicit activities, including violence, extortion, and sextortion. The Department of Justice highlighted the significant impact of Moucka's actions, noting the harm inflicted on both targeted companies and the millions of individuals whose data was compromised.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm credentials to backdoor co-owned packages totaling over 1.3 billion monthly downloads.

cloud

Canadian pleads guilty to Snowflake cloud data-theft attacks

A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. [...]

vulnerability

Prompt injection isn't the bug, AI agent frameworks are

Check Point researchers tried to break the frameworks enterprises use to build AI apps. Now they're telling Black Hat attendees what they found

breach

Canadian man pleads guilty to Snowflake hacks that led to 165 breaches

A 26-year-old from Ontario faces as many as 32 years in prison after pleading guilty to fraud, identity theft and conspiracy charges related to the 2024 hacks of cloud platform Snowflake.

breach

Hackers run khunt post-exploitation toolkit from Oracle database

Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. [...]

vulnerability

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers

An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there the attacker runs code on the host. Bonita BPM handles loan approvals, insurance claims, and employee onboarding for banks, insurers, and government agencies, and its internal surface answers to strangers. Vulnerability resea