Canadian Man Pleads Guilty in Snowflake Extortions
Connor Riley Moucka, a Canadian man, pleaded guilty to computer fraud and conspiracy related to hacking and extorting over 165 organizations using stolen credentials for Snowflake cloud accounts lacking multi-factor authentication. The stolen data included sensitive customer records from major companies and personal information such as call and text histories of over 100 million AT&T customers. Moucka and co-conspirators extorted victims by threatening to publish stolen data, generating over $2.5 million in ransom payments. Snowflake responded by enforcing multi-factor authentication and increasing password complexity. Moucka also re-extorted victims and harassed officials and researchers. Co-conspirators include a U.S. Army soldier and another individual involved in prior breaches. Moucka faces significant prison time upon sentencing.
AI Analysis
Technical Summary
Between February and October 2024, Connor Riley Moucka and co-conspirators used stolen login credentials to access and steal data from at least 165 Snowflake customer accounts that did not enforce multi-factor authentication. The stolen data included billions of sensitive records such as non-content call and text history, financial information, government identifiers, and personally identifiable information. The group extorted victims by threatening to publish the stolen data, receiving over $2.5 million in ransom payments. Snowflake mitigated the issue by increasing password complexity requirements and enforcing multi-factor authentication on accounts. Moucka also engaged in re-extortion and harassment of government officials and security researchers. Co-conspirators include Cameron Wagenius, a U.S. Army soldier who pleaded guilty to similar extortion activities, and John Erin Binns, involved in a previous major breach. Moucka pleaded guilty to multiple criminal counts including computer fraud, wire fraud, aggravated identity theft, and conspiracy, facing up to 30 years in prison.
Potential Impact
The unauthorized access and theft of sensitive data from over 165 organizations using Snowflake cloud services exposed billions of sensitive customer records, including personal identifiers, financial data, and call/text histories. The attackers extorted victims for ransom payments totaling over $2.5 million and engaged in re-extortion using stolen data. The breach affected major companies and government officials, causing significant privacy and security risks. The incident also involved harassment of officials and researchers. Snowflake's enforcement of multi-factor authentication and password complexity mitigated further exploitation via stolen credentials.
Mitigation Recommendations
Snowflake has responded to the incident by increasing password complexity requirements and enforcing multi-factor authentication on customer accounts, which addresses the primary attack vector of stolen credentials without MFA. Organizations using Snowflake should ensure MFA is enabled and follow Snowflake's updated security recommendations. No additional vendor advisories or patches are indicated. Since this is a criminal case with guilty pleas, remediation focuses on prevention of similar credential-based attacks through strong authentication controls.
Canadian Man Pleads Guilty in Snowflake Extortions
Description
Connor Riley Moucka, a Canadian man, pleaded guilty to computer fraud and conspiracy related to hacking and extorting over 165 organizations using stolen credentials for Snowflake cloud accounts lacking multi-factor authentication. The stolen data included sensitive customer records from major companies and personal information such as call and text histories of over 100 million AT&T customers. Moucka and co-conspirators extorted victims by threatening to publish stolen data, generating over $2.5 million in ransom payments. Snowflake responded by enforcing multi-factor authentication and increasing password complexity. Moucka also re-extorted victims and harassed officials and researchers. Co-conspirators include a U.S. Army soldier and another individual involved in prior breaches. Moucka faces significant prison time upon sentencing.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Between February and October 2024, Connor Riley Moucka and co-conspirators used stolen login credentials to access and steal data from at least 165 Snowflake customer accounts that did not enforce multi-factor authentication. The stolen data included billions of sensitive records such as non-content call and text history, financial information, government identifiers, and personally identifiable information. The group extorted victims by threatening to publish the stolen data, receiving over $2.5 million in ransom payments. Snowflake mitigated the issue by increasing password complexity requirements and enforcing multi-factor authentication on accounts. Moucka also engaged in re-extortion and harassment of government officials and security researchers. Co-conspirators include Cameron Wagenius, a U.S. Army soldier who pleaded guilty to similar extortion activities, and John Erin Binns, involved in a previous major breach. Moucka pleaded guilty to multiple criminal counts including computer fraud, wire fraud, aggravated identity theft, and conspiracy, facing up to 30 years in prison.
Potential Impact
The unauthorized access and theft of sensitive data from over 165 organizations using Snowflake cloud services exposed billions of sensitive customer records, including personal identifiers, financial data, and call/text histories. The attackers extorted victims for ransom payments totaling over $2.5 million and engaged in re-extortion using stolen data. The breach affected major companies and government officials, causing significant privacy and security risks. The incident also involved harassment of officials and researchers. Snowflake's enforcement of multi-factor authentication and password complexity mitigated further exploitation via stolen credentials.
Defensive Guidance
Snowflake has responded to the incident by increasing password complexity requirements and enforcing multi-factor authentication on customer accounts, which addresses the primary attack vector of stolen credentials without MFA. Organizations using Snowflake should ensure MFA is enabled and follow Snowflake's updated security recommendations. No additional vendor advisories or patches are indicated. Since this is a criminal case with guilty pleas, remediation focuses on prevention of similar credential-based attacks through strong authentication controls.
Technical Details
- Classification
- {"confidence":0.67,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/","fetched":true,"fetchedAt":"2026-08-06T17:09:10.587Z","wordCount":977}
Threat ID: 6a74bfb6bf8831d53903c87f
Added to database: 08/06/2026, 17:09:10 UTC
Last enriched: 08/06/2026, 17:09:22 UTC
Last updated: 08/06/2026, 23:40:58 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.