In brief: Connor Riley Moucka pleaded guilty to being part of the hacker group that used stolen credentials to compromise Snowflake customers at 165 companies and extort millions.
Canadian national Connor Riley Moucka has pleaded guilty to participating in a series of attacks affecting customer data of 165 organizations and generating millions of dollars in extortion payments. The offenses are linked to the 2024 attacks on customers of cloud data warehouse provider Snowflake, which came to light that year.
According to industry sources, Moucka is considered one of the central figures behind the attacks on data hosted at Snowflake. Affected companies include AT&T, Ticketmaster and Neiman Marcus Group, among others. According to investigators, Moucka worked together with two other hackers: John Edward Binns and Cameron John Wagenius, who operated under the pseudonym Kiberphant0m. As of April 2026, Binns was not in US custody, while Wagenius was arrested in January 2025 and pleaded guilty in July of that same year.
The group used stolen credentials to gain access to data belonging to at least 165 customers of a US-based SaaS provider. According to authorities, this unauthorized access resulted in the theft of billions of sensitive customer records and the exfiltration of terabytes of information. The affected companies were subsequently extorted to prevent the publication or further exploitation of the data.
A. Tysen Duva, Assistant Attorney General of the Criminal Division of the US Department of Justice, stated that Moucka had hacked over 150 companies and organizations, obtained extremely sensitive information, and extorted millions of dollars from the victims. The guilty plea is meant to signal to cybercriminals, regardless of their location, that anonymity offers no lasting protection from prosecution.
The case is the result of an internationally coordinated investigation into the so-called Snowflake group. The investigation was led by the FBI, with support from the Royal Canadian Mounted Police, the Australian Federal Police, the Spanish Guardia Civil, the Ukrainian security service SBU, and the Turkish National Police. For CISOs, the case once again underscores that compromised credentials on third-party platforms — here used without consistent multi-factor authentication — remain a key attack vector for large-scale data exfiltration and extortion.
Source: www.csoonline.com · Published August 7, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.