“In at least one instance, Moucka re-extorted a victim with threats of further disclosure of the victim’s stolen data,” the U.S. Department of Justice said in a press release released today.
The guilty plea and legal stakes
Connor Riley Moucka, a 26-year-old Canadian also known as Alexander Moucka and “Waifu,” pleaded guilty today to four counts of an indictment charging computer fraud, wire fraud, aggravated identity theft, and a related conspiracy. He is scheduled for sentencing on October 27 and faces a statutory maximum sentence of 32 years in prison. Moucka was arrested on October 30, 2024. His co-defendant, John Erin Binns, was indicted alongside him; at the time of the attacks Binns resided in Turkey, where he was arrested and where a local court approved a U.S. extradition request that was later contested.
How the attackers gained access: infostealer malware and missing MFA
According to court documents, between February and October 2024 Moucka and Binns accessed customer accounts at cloud storage provider Snowflake by using logins stolen via infostealer malware. The victims’ Snowflake accounts that were accessed lacked multi-factor authentication (MFA); without MFA enabled the actors needed only correct usernames and passwords to log in. The defendants used custom software to inspect cloud storage instances and identify “valuable information” such as organization names, user roles, and IP addresses before exfiltrating data.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildScale of theft, extortion, and the data taken
The DoJ says the pair stole terabytes of data from Snowflake tenant environments, extorted multiple companies, and obtained at least $2.5 million in bitcoin from at least three victims. Moucka separately advertised stolen data on hacker forums for fiat currency and cryptocurrency and obtained at least $495,000 from those sales. The department reports that victim companies suffered more than $9.5 million in losses and that the breaches affected more than 100 million individuals.
- Types of data stolen included call and text history records (non-content), banking and financial information, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, Social Security numbers, and other personally identifiable information (PII).
- Named impacted organizations include AT&T, Ticketmaster, Santander, Pure Storage, Advance Auto Parts, Los Angeles Unified, QuoteWizard/LendingTree, and Neiman Marcus.
- The DoJ said Moucka used stolen data of a government officer and of members of a then-former government officer’s immediate family in a re-extortion attempt.
Snowflake’s immediate changes to authentication policy
In response to the breaches, Snowflake announced it would enforce multi-factor authentication across accounts and require all passwords to be at least 14 characters long. Those vendor-side policy decisions followed the pattern described in the indictment: accounts without MFA were directly vulnerable when usernames and passwords were exposed by infostealer malware.
What this means for technologists, affected enterprises, and end users
- Technologists and security teams: The legal record here underscores the practical impact of missing MFA and weak password policies — Snowflake moved to enforce MFA and 14-character passwords after the incidents. The episode also highlights the value of detecting credential theft because, as a whitepaper cited in the source material notes, security teams “log 54% of successful attacks and alert on just 14%.”
- Affected enterprises and procurement leaders: Organizations named in the DoJ release suffered direct financial losses (reported as more than $9.5 million collectively) and exposure of sensitive customer and employee records. The combination of extortion payments (at least $2.5 million in bitcoin) and secondary sales of stolen files (at least $495,000 in known proceeds) illustrates the two immediate monetization paths attackers used.
- End users and the general public: More than 100 million individuals were reported affected; the stolen data types include Social Security numbers, passport and driver’s license numbers, DEA registration numbers, payroll and banking details, and other PII — the kinds of records that can enable identity theft and targeted extortion.
The guilty plea ties a named actor to a high-profile cloud data theft and extortion campaign that spanned months and reached large corporations and public-sector institutions. With sentencing set for October 27 and an indicted co-defendant whose extradition was approved but contested in Turkey, the case promises further legal developments while also leaving a clear operational legacy: cloud accounts without MFA and short passwords are attractive entry points for attackers wielding infostealer malware and custom reconnaissance tools.
Source: BleepingComputer — Canadian pleads guilty to Snowflake cloud data-theft attacks




