Skip to content

Canadian pleads guilty in Snowflake extortion case

In brief: A Canadian man has pleaded guilty to hacking and extorting more than 165 Snowflake customers without MFA protection, including AT&T with data on over 100 million customers.

A 26-year-old Canadian has pleaded guilty to hacking and extorting more than 165 Snowflake customers. Victims include TicketMaster, Lending Tree, Advance Auto Parts and Neiman Marcus, as well as AT&T with over 100 million affected customer records.

Connor Riley Moucka of Kitchener, Ontario, pleaded guilty before a US court to computer fraud and conspiracy to commit hacking and extortion. According to the US Department of Justice, between February and October 2024 Moucka and accomplices used stolen credentials to access cloud-hosted data from at least 165 customers of a US-based SaaS provider. The affected accounts were those Snowflake accounts where multi-factor authentication was not enforced. Moucka operated under changing pseudonyms, most notably “Judische” and “Waifu”. As early as September 2024, KrebsOnSecurity had publicly exposed his role in the Snowflake incidents; roughly a month later, Canadian authorities arrested him based on a US arrest warrant.

According to investigative records, the group stole billions of sensitive customer records and downloaded terabytes of information, including call and text message records, banking and financial data, payroll records, DEA registration numbers, and driver’s license, passport and Social Security numbers. Among the victims was also AT&T, whose call and text message records for more than 100 million customers were stolen. The perpetrators threatened to publish the data unless payment was made; according to the Department of Justice, ransom payments totaling over $2.5 million were made. In at least one case, Moucka extorted a victim a second time, using stolen data belonging to a government official and their family members.

For CISOs, the case once again highlights the risks of SaaS and cloud storage platforms without mandatory multi-factor authentication: Snowflake responded to the incidents by tightening password requirements and making MFA mandatory for all customer accounts. Companies using cloud services without their own MFA enforcement should check whether credentials from previous leaks or infostealer campaigns could be reused, and harden access policies accordingly.

An alleged accomplice, US soldier Cameron “Kiberphant0m” Wagenius, had already pleaded guilty in July 2025 to extorting AT&T and Verizon over customer data. Wagenius is alleged to have published, among other things, purported call records of then-President-elect Donald Trump and then-Vice President-elect Kamala Harris, as well as schematics purportedly originating from a US security agency.


Source: krebsonsecurity.com · Published August 6, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: