In brief: A Canadian man has pleaded guilty to hacking and extorting more than 165 Snowflake customers without MFA protection, including AT&T with data from over 100 million customers.
A 26-year-old Canadian has pleaded guilty to hacking and extorting more than 165 Snowflake customers. Victims include TicketMaster, Lending Tree, Advance Auto Parts and Neiman Marcus, as well as AT&T with over 100 million affected customer records.
Connor Riley Moucka of Kitchener, Ontario, pleaded guilty before a US court to computer fraud and conspiracy to commit hacking and extortion. According to the US Department of Justice, between February and October 2024 Moucka and co-conspirators used stolen credentials to access cloud-hosted data belonging to at least 165 customers of a US-based SaaS provider. Affected were those Snowflake accounts where multi-factor authentication was not enforced. Moucka operated under changing pseudonyms, most notably “Judische” and “Waifu”. As early as September 2024, KrebsOnSecurity had publicly exposed his role in the Snowflake incidents; roughly a month later, Canadian authorities arrested him based on a US warrant.
According to investigative records, the group stole billions of sensitive customer records and downloaded terabytes of information, including call and text message records, banking and financial data, payroll records, DEA registration numbers, and driver’s license, passport and Social Security numbers. Among the victims was also AT&T, whose call and text message records for more than 100 million customers were stolen. The perpetrators threatened to publish the data unless payment was made; according to the Department of Justice, ransom payments of more than 2.5 million US dollars were made as a result. In at least one case, Moucka extorted a victim a second time, using stolen data belonging to a government official and his family members.
For CISOs, the case once again highlights the risks of SaaS and cloud storage platforms without mandatory multi-factor authentication: Snowflake responded to the incidents by tightening password requirements and making MFA mandatory for all customer accounts. Companies using cloud services without their own MFA enforcement should check whether credentials from previous leaks or infostealer campaigns could be reused, and harden access policies accordingly.
An alleged co-conspirator, US soldier Cameron “Kiberphant0m” Wagenius, had already pleaded guilty in July 2025 to extorting AT&T and Verizon over customer data. Wagenius is alleged to have published, among other things, purported call logs of then President-elect Donald Trump and then Vice President Kamala Harris, as well as schematics purportedly originating from a US security agency.
Source: krebsonsecurity.com · Published August 6, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.