Connor Moucka Pleads Guilty to Snowflake Breach Spree Affecting 165+ Organizations

Connor Moucka, a 26-year-old Canadian citizen who operated under the aliases "Waifu" and "Judische," pleaded guilty in Seattle federal court to charges including computer fraud, wire fraud, aggravated identity theft, and conspiracy, stemming from a hacking campaign that compromised more than 165 organizations through cloud provider Snowflake's customer base. The U.S. Justice Department announced the guilty plea on August 5, 2026. Moucka faces up to 32 years in prison at sentencing, scheduled for October 27. (Justice Department)
Moucka admitted to hacking Snowflake, which enabled him and his co-conspirators to breach dozens of Snowflake customers, including AT&T, LendingTree, and Ticketmaster. The campaign yielded billions of stolen records. From AT&T alone, Moucka exfiltrated call and texting records belonging to more than 100 million customers. Other breaches produced banking information, drivers' license numbers, and Social Security numbers. (TechCrunch)
The financial mechanics were straightforward. Moucka and his accomplices collected more than $2.5 million in ransom payments over the course of the conspiracy, extorting companies and individuals whose data they had stolen. Moucka separately earned approximately $500,000 selling victims' data on hacking forums, including BreachForums. The DOJ quantified victims' losses at $9.5 million. (TechCrunch)
Moucka was arrested in Canada at the end of 2024. FBI special agent W. Mike Herrington, who worked the case, characterized Moucka's threats and re-extortion tactics as "calculated and predatory." Austin Larsen, a senior researcher at Google's Mandiant, called Moucka "one of the most consequential" hackers of 2024. (TechCrunch)
The charges, filed in the Western District of Washington, cover the full arc of the conspiracy: unauthorized access to protected computers, wire fraud tied to the extortion payments, aggravated identity theft for misuse of stolen personal information, and conspiracy for the coordinated nature of the campaign. (The Hacker News)
The Snowflake breach chain worked because customer tenants were accessible with credentials that lacked multi-factor authentication. Moucka did not exploit a vulnerability in Snowflake's platform itself. He used stolen or purchased credentials, obtained through infostealer malware and credential dumps circulating in criminal markets, to authenticate directly into customer environments. Any Snowflake customer that had enforced MFA or used key-based authentication was not affected. That distinction matters, because it places responsibility for the bulk of these compromises on identity and access management posture rather than on a platform-level security failure.
The re-extortion tactic Herrington referenced is worth attention. After companies paid ransom to prevent data publication, Moucka returned to the same victims demanding additional payments, leveraging the fact that the stolen data remained in his possession. This is not novel in principle, but the scale and brazenness here, applied across more than 165 targets, suggests a deliberate operational model rather than opportunistic pressure.
The $9.5 million in documented losses, against $2.5 million in ransom collected and $500,000 in data sales, understates the real damage. Those figures capture direct financial impact and extortion revenue, not the downstream costs of breach remediation, regulatory penalties, customer notification, credit monitoring, or reputational harm. For AT&T, the exposure of call and text records for over 100 million customers alone carries compliance and litigation costs that dwarf the DOJ's aggregate loss figure. The full cost will surface over years, not in a press release.
Moucka's plea closes the criminal phase of one of 2024's most damaging breach campaigns. Co-conspirators were referenced in the DOJ's filings but not named in the announcement, leaving the question of additional charges open. Snowflake itself was not charged and cooperated with the investigation. The company subsequently moved to enforce MFA requirements across its customer base, a step that addresses the specific access gap Moucka exploited but arrives after the damage was done.


