The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people.
Connor Riley Moucka pleads guilty in Seattle federal court
Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy for his role in the 2024 breaches of a U.S. software-as-a-service provider's customer accounts. Prosecutors say Moucka, 26, of Kitchener, Ontario, personally took at least $495,000 from ransoms and data sales. He is due to be sentenced on October 27 and faces a two-year mandatory minimum on the identity theft count and up to 30 years on the other counts.
How the attackers gained access: old credentials harvested by infostealers
Investigators concluded the intrusions were not the result of a platform exploit. "No exploit, no flaw in the platform," the record states. Rather, the attackers used credentials stolen years earlier by infostealer malware that had never been rotated and were used on accounts with multi-factor authentication (MFA) switched off.
Mandiant, which investigated alongside the vendor named in 2024 as Snowflake, tracked the actor as UNC5537 and found every incident it worked traced back to customer credentials stolen by infostealers. Some credentials had been harvested as far back as November 2020 and remained valid years later. At least 79.7% of the accounts the group used had prior credential exposure, and the compromised instances had no network allow lists.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildScale and types of data exposed and financial impact
Prosecutors say the campaign reached at least 165 organizations; that figure originated as a notification count in 2024 but is now used by prosecutors for customers actually compromised. The Justice Department's announcement cited "over 165" organizations in the body, while Assistant Attorney General A. Tysen Duva's statement said "over 150."
Victim companies suffered more than $9.5 million in actual losses, a figure the release says excludes losses to those companies' customers. Exposed data included non-content call and text history, payroll records, Drug Enforcement Administration registration numbers, passport numbers and Social Security numbers. AT&T confirmed in July 2024 that records of calls and texts for nearly all its cellular customers between May 1 and October 31, 2022 were taken from its workspace on a third-party cloud platform.
Co-defendants, related pleas, and re-extortion tactics
The indictment in October 2024 charged two men; as of an August 4 case update, only Moucka is in U.S. custody and co-defendant John Erin Binns remains outside it. In a related case, prosecutors tied Cameron John Wagenius, a former Army soldier, to the same intrusions; Wagenius pleaded guilty in July 2025.
Prosecutors also say Moucka re‑extorted at least one victim, threatening further disclosure using the stolen data of a government officer and members of a then‑former government officer's immediate family. W. Mike Herrington, special agent in charge of the FBI's Seattle field office, described the tactics as "calculated and predatory."
Snowflake's response: staged MFA enforcement and remaining exceptions
The Justice Department did not name the SaaS victim in its announcement or the October 2024 indictment; Snowflake and Mandiant named the platform themselves in 2024. Snowflake has enforced MFA by default for human users on accounts created since October 2024, but password-only sign-ins are not yet entirely eliminated.
Documentation checked by The Hacker News on August 6 indicates the final phase of Snowflake's MFA rollout is scheduled between August and October 2026, to be applied account by account. Only then will passwords be blocked as a sole factor for every remaining human and service user. Reader and trial accounts are exempt from the change.
What this means for technologists, enterprise defenders, and regulators
- Technologists and security teams: the incident underlines the persistence of credentials harvested years earlier by infostealer malware and the impact when MFA is not universally enforced; Mandiant's findings that many accounts had prior credential exposure and lacked network allow lists will focus teams on credential hygiene and network controls.
- Enterprise defenders and procurement leaders: victim firms recorded more than $9.5 million in direct losses and face the reputational and customer-impact costs associated with exposed personal data such as passport and Social Security numbers; contractual and third‑party security considerations—highlighted by AT&T's disclosure about third‑party cloud workspace exposures—will be central to risk assessments.
- Regulators and prosecutors: the case demonstrates prosecutors pursuing traditional criminal counts (computer fraud, wire fraud, aggravated identity theft) and securing guilty pleas and financial recovery claims, while publicly noting the absence of a platform vulnerability rather than an exploit.
The case leaves two concrete near‑term dates on the calendar: Moucka's sentencing on October 27, and Snowflake's planned completion of its MFA rollout between August and October 2026. Together they frame the legal and technical follow-through of a campaign the investigators said "is not the result of any particularly novel or sophisticated tool, technique, or procedure"—but one powered by a persistent market for stolen credentials and years of unrotated passwords.




