Canadian man pleads guilty to Snowflake hacks that led to 165 breaches

A Canadian national is facing decades in prison for participating in the hacking of data storage platform Snowflake.
Connor Riley Moucka, 26, pleaded guilty to computer fraud, wire fraud, aggravated identity theft and a related conspiracy on Wednesday in a Washington state federal court. He will be sentenced on October 27 and is facing up to 32 years in prison.
Moucka and others used stolen login credentials to breach Snowflake and steal troves of information from at least 165 companies.
The hackers stole billions of files from large companies including AT&T, Ticketmaster, Advance Auto Parts, one of the largest school districts in the U.S., Neiman Marcus, Santander, LendingTree and more.
The AT&T breach involved the logs of calls and texts to more than 100 million customers. The Ticketmaster breach involved about 560 million users.
Moucka, from Kitchener, Ontario, was eventually arrested in November 2024 and extradited to the U.S. in July 2025.
Prosecutors said Moucka and his co-conspirators breached Snowflake between February and October 2024 — allowing them to steal banking records, financial information, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, Social Security numbers and more.
The hackers then attempted to extort victim companies with threats of publishing the stolen information online. The crew earned about $2.5 million in ransom payments, and court documents showed Moucka extorted at least one victim a second time.
“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” prosecutors said.
Moucka earned another $495,000 by advertising some of the stolen data on cybercriminal forums like BreachForums and XSS.is. Court documents said victim companies suffered about $9.5 million in losses related to the breaches.
“Connor Moucka’s threats and re-extortion tactics were calculated and predatory, and his actions did real harm to his victims, be they companies targeted for theft and extortion or the millions of everyday people who are their customers,” said FBI Special Agent in Charge W. Mike Herrington.
After the breaches came to light, Snowflake hired Google’s Mandiant unit to investigate the incident and confirmed that there was no issue with the platform’s security. The hackers, according to Mandiant, stole still-valid credentials dating back to 2020 and were able to access company accounts through those login details.
Mandiant said at the time that the hackers behind the campaign are “based in North America, and collaborates with an additional member in Turkey.”
At least one of the alleged Turkey-based hackers, John Erin Binns, was detained by Turkish authorities in 2024 after being indicted for his role in a previous hack of telecom T-Mobile.
Before his arrest, Moucka allegedly spoke to news outlet 404Media, telling them that he expected to be arrested and had been destroying evidence in advance of his detainment.
References in this story
- Hackers stole ‘nearly all’ call logs over six months from AT&T therecord.media The telecom giant said the massive breach involving logs from 2022 occurred through the third-party cloud platform Snowflake.
- Live Nation confirms Ticketmaster breach after hackers hawk stolen info of 560 million therecord.media The company has confirmed that the leaked data was from a database hosted on Snowflake — one of the largest cloud storage companies.
- Advance Auto Parts says more than 2 million impacted by data breach therecord.media Automotive products retailer Advance Auto Parts notified regulators that a recent data breach exposed the information of more than 2 million people.
- More than 12,000 Santander employees in US affected by Snowflake customer breach therecord.media The Spanish banking giant was one of the first organizations to report a breach in the Snowflake incident, which is now known to have affected about 165 organizations.
- Neiman Marcus says 64,000 affected by breach of Snowflake customer account therecord.media Neiman Marcus is the latest large company affected by a run of attacks on customers of the data cloud storage provider Snowflake.
- LendingTree confirms that cloud services attack potentially affected subsidiary therecord.media LendingTree said it heard from cloud services company Snowflake about a potential incident involving QuoteWizard, an insurance platform.
- AT&T reportedly paid ransom for deletion of stolen call logs after culprit allegedly detained therecord.media The scale of AT&T’s data breach continued to widen over the weekend, with reports emerging that AT&T paid a $370,000 ransom to a hacker who obtained the logs of calls and texts to more than 100 million customers.
- Alleged Snowflake hacker consents to extradition from Canada after US charges therecord.media Connor Riley Moucka signed a consent order on Friday in Ontario Superior Court in Kitchener that would allow him to be transferred to U.S. custody to face multiple charges.
- BreachForums Latest News therecord.media Explore the latest trending news and updates on BreachForums. Dive into insightful articles, analyses, and more to stay informed on BreachForums.
- Suspected admin of major dark web cybercrime forum arrested in Ukraine therecord.media French law enforcement said the alleged administrator of the long-running cybercrime forum XSS, formerly known as DaMaGeLab, was arrested in Ukraine.
- UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion | Google Cloud Blog cloud.google.com A campaign targeting Snowflake customer database instances with the intent of data theft and extortion.
- Exclusive: American who hacked T-Mobile servers in 2021 arrested in Turkey, to be extradited to U.S. thedesk.net John Binns, 24, admitted to accessing servers connected to T-Mobile; he was federally indicted in 2022.
- Sealed Indictment Shows Case Against Hacker Behind Massive T-Mobile Data Breach www.404media.co A sealed indictment obtained by 404 Media describes the case against John Binns, who allegedly hacked into T-Mobile, stole 40 million user records, and then sold them.
- T-Mobile reaches historic $350 million settlement in 2021 data breach therecord.media T-Mobile on Friday said it agreed to pay $350 million to a group of victims and commit $150 million extra to security upgrades to settle a class-action lawsuit brought in the wake of a 2021 hack of sensitive customer…
- Suspected Snowflake Hacker Arrested in Canada www.404media.co For more than a week Judische, the hacker linked to the AT&T, Ticketmaster and other breaches, has not been responding to messages. That's because he's been arrested.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
- jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51


