Snowflake Hacker Pleads Guilty in US Court
Connor Riley Moucka pleaded guilty in a US court for his role in a cybercrime campaign targeting Snowflake accounts of 165 organizations. The campaign involved using stolen credentials to access sensitive data, resulting in the theft of billions of records and ransom payments totaling $2.5 million. The attack impacted major companies across various sectors, causing over $9.5 million in direct losses to targeted organizations. Moucka faces over 30 years in prison, with sentencing scheduled for October 27. The operation was linked to the threat actor UNC5537 and included data extortion and resale on hacking forums.
AI Analysis
Technical Summary
Connor Riley Moucka was extradited from Canada to the US and pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy related to a cybercrime campaign targeting Snowflake data storage accounts. The attackers used stolen login credentials to access data from 165 organizations, including major corporations such as AT&T, Santander Bank, and State Farm. The campaign, attributed to UNC5537, resulted in the theft of billions of sensitive personal and financial records, ransom payments of $2.5 million, and additional financial gains from selling stolen data. The DOJ estimates direct losses to victim companies at over $9.5 million, excluding customer losses affecting at least 100 million individuals. A former US soldier is also believed to have participated in the campaign.
Potential Impact
The cybercrime campaign caused significant financial losses exceeding $9.5 million to targeted organizations and compromised billions of sensitive personal and financial records. At least 100 million individuals' data was affected. The attackers extorted ransom payments totaling $2.5 million and profited further by selling stolen data on hacking forums. The breach impacted a wide range of major companies across multiple industries, undermining data confidentiality and causing reputational damage.
Mitigation Recommendations
This is a law enforcement case involving prosecution of the threat actor. No technical patch or remediation applies to the vulnerability itself. Organizations should ensure robust credential security and monitoring to prevent unauthorized access to cloud data storage accounts. Follow vendor and Snowflake security best practices for account protection. No direct remediation or patch is indicated by the advisory.
Snowflake Hacker Pleads Guilty in US Court
Description
Connor Riley Moucka pleaded guilty in a US court for his role in a cybercrime campaign targeting Snowflake accounts of 165 organizations. The campaign involved using stolen credentials to access sensitive data, resulting in the theft of billions of records and ransom payments totaling $2.5 million. The attack impacted major companies across various sectors, causing over $9.5 million in direct losses to targeted organizations. Moucka faces over 30 years in prison, with sentencing scheduled for October 27. The operation was linked to the threat actor UNC5537 and included data extortion and resale on hacking forums.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Connor Riley Moucka was extradited from Canada to the US and pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy related to a cybercrime campaign targeting Snowflake data storage accounts. The attackers used stolen login credentials to access data from 165 organizations, including major corporations such as AT&T, Santander Bank, and State Farm. The campaign, attributed to UNC5537, resulted in the theft of billions of sensitive personal and financial records, ransom payments of $2.5 million, and additional financial gains from selling stolen data. The DOJ estimates direct losses to victim companies at over $9.5 million, excluding customer losses affecting at least 100 million individuals. A former US soldier is also believed to have participated in the campaign.
Potential Impact
The cybercrime campaign caused significant financial losses exceeding $9.5 million to targeted organizations and compromised billions of sensitive personal and financial records. At least 100 million individuals' data was affected. The attackers extorted ransom payments totaling $2.5 million and profited further by selling stolen data on hacking forums. The breach impacted a wide range of major companies across multiple industries, undermining data confidentiality and causing reputational damage.
Defensive Guidance
This is a law enforcement case involving prosecution of the threat actor. No technical patch or remediation applies to the vulnerability itself. Organizations should ensure robust credential security and monitoring to prevent unauthorized access to cloud data storage accounts. Follow vendor and Snowflake security best practices for account protection. No direct remediation or patch is indicated by the advisory.
Technical Details
- Classification
- {"confidence":0.75,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/snowflake-hacker-pleads-guilty-in-us-court/","fetched":true,"fetchedAt":"2026-08-06T15:11:12.784Z","wordCount":994}
Threat ID: 6a74a410bf8831d539e4ddb1
Added to database: 08/06/2026, 15:11:12 UTC
Last enriched: 08/06/2026, 15:11:39 UTC
Last updated: 08/07/2026, 00:29:57 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.