Skip to main content
Emerging ThreatsMalware & Ransomware

Canadian Hacker Pleads Guilty in Snowflake Extortion Scheme

Courthouse interior with blurred laptop, figure in foreground.

At least 165 Snowflake customers were compromised and the intruders stole “billions” of sensitive records — a campaign that yielded more than $2.5m in ransom payments and led a Canadian national to plead guilty in a U.S. court on August 5, 2026.

Connor Riley Moucka’s guilty plea and the charges he faces

Connor Riley Moucka, 26, of Ontario, pleaded guilty on August 5, 2026 to computer fraud, aggravated identity theft and a related conspiracy tied to the 2024 compromises of Snowflake customer accounts. The aggravated identity theft count carries a mandatory minimum penalty of two years in prison; the remaining counts could add up to a maximum of 30 years. Sentencing is scheduled for October 27.

How the Snowflake compromises occurred and were detected

According to court documents, Moucka and co-conspirators used stolen login credentials to access at least 165 customers’ Snowflake instances between February and October 2024. That unauthorized access was used to steal billons of sensitive customer records, including individuals’ call and text records, financial details, and other personally identifiable information.

Cybersecurity firm Mandiant first alerted the public to the Snowflake breach in June 2024 after analyzing database records that were subsequently determined to have originated from a victim’s Snowflake instance in April 2024. Mandiant then obtained additional intelligence identifying a broader campaign and contacted Snowflake with its findings in May 2024. That reporting led to a Victim Notification Program intended to alert potential victims and help them secure accounts and data.

The extortion campaign, marketplaces and the measured losses

Court documents describe a coordinated extortion campaign in which stolen data was used to threaten victims with publication unless payment was made. In at least one case the defendants re-extorted a victim with threats of further disclosure, “which related to the stolen data of a government officer members of a then-former government officer’s immediate family.”

Authorities said the hackers collected more than $2.5m in ransom payments during the campaign. The conspirators advertised stolen data for sale on cybercrime forums such as BreachForums and on Telegram; Moucka personally obtained at least $495,000 from sales on these platforms. U.S. authorities estimate that victim companies suffered over $9.5m in actual losses as a result of the campaign. That figure does not include losses suffered by victim companies’ individual customers, which authorities say totals at least 100 million people.

High-profile victims and Snowflake’s post-incident action

A number of high-profile companies were impacted by the campaign, including AT&T and Ticketmaster. In the wake of the incident, Snowflake announced it would make multi-factor authentication (MFA) mandatory for all customer accounts.

How technologists, affected enterprises, and the public are positioned

  • Technologists and security teams: The intrusion used stolen login credentials to reach customer Snowflake instances and was detected only after external analysis of leaked database records. Those facts underscore why security teams will be watching account access controls and authentication posture closely and why Snowflake’s move to require MFA is a focal response tied directly to the breach.
  • Affected enterprises and procurement leaders: Companies that relied on Snowflake services — including named victims AT&T and Ticketmaster — will face remediation costs and notifications tied to the Victim Notification Program; U.S. authorities estimate enterprise losses at over $9.5m, not counting customer harms.
  • End users and the public: Individuals’ call and text records, financial details and other personally identifiable information were among the data stolen; U.S. authorities say the campaign affected the data of at least 100 million people, and the records were both used for extortion and offered for sale on criminal marketplaces.

Moucka’s guilty plea caps a cross-border law enforcement effort that led to his arrest in October 2024 and extradition from Canada to the United States in July 2025 following cooperation among Canadian, Australian, Spanish, Ukrainian and Turkish police forces. With sentencing set for October 27, the record assembled in court documents lays out the scale of the intrusions, the mechanics of the extortion and the measurable financial and human impact — while leaving the thousands of organizations and millions of individuals affected to reconcile damage, data exposure and the long tail of recovery.

Original story

Canadian Hacker Pleads Guilty in Snowflake Extortion Scheme | OSINTSights