Technology

The Hacker Who Hit 165 Companies Through a Cloud Provider Just Pleaded Guilty

Martin HollowayPublished 2d ago4 min readBased on 5 sources
Reading level
The Hacker Who Hit 165 Companies Through a Cloud Provider Just Pleaded Guilty
source:justice.gov

Connor Moucka, a 26-year-old Canadian who went by the online names "Waifu" and "Judische," pleaded guilty in a Seattle federal court to charges including computer fraud, wire fraud, aggravated identity theft, and conspiracy. The charges come from a hacking campaign that broke into more than 165 organizations through a cloud storage company called Snowflake. The U.S. Justice Department announced the guilty plea on August 5, 2026. Moucka faces up to 32 years in prison at sentencing, scheduled for October 27. (Justice Department)

Moucka admitted to hacking Snowflake, a company that stores data for other businesses. That access let him and his co-conspirators break into dozens of Snowflake's customers, including AT&T, LendingTree, and Ticketmaster. The campaign produced billions of stolen records. From AT&T alone, Moucka took call and texting records belonging to more than 100 million customers. Other breaches produced banking information, drivers' license numbers, and Social Security numbers. (TechCrunch)

The money trail was straightforward. Moucka and his accomplices collected more than $2.5 million in ransom payments from companies and individuals whose data they had stolen. Moucka separately earned about $500,000 selling victims' data on underground hacking forums, including one called BreachForums. The DOJ put victims' losses at $9.5 million. (TechCrunch)

Moucka was arrested in Canada at the end of 2024. FBI special agent W. Mike Herrington, who worked the case, described Moucka's threats and re-extortion tactics as "calculated and predatory." Austin Larsen, a senior researcher at Google's Mandiant, called Moucka "one of the most consequential" hackers of 2024. (TechCrunch)

The charges, filed in the Western District of Washington, cover the full scope of the conspiracy: unauthorized access to protected computers, wire fraud tied to the extortion payments, aggravated identity theft for misuse of stolen personal information, and conspiracy for the coordinated nature of the campaign. (The Hacker News)

The breach worked because some Snowflake customers were logging in with just a username and password, without multi-factor authentication turned on. Multi-factor authentication, or MFA, is a security step that asks for a second proof of identity beyond a password, like a code sent to your phone. Moucka did not find a flaw in Snowflake's own systems. Instead, he used stolen passwords, obtained through malware designed to steal login details from infected computers and from lists of stolen credentials sold in criminal markets, to log directly into customer accounts. Any Snowflake customer that had MFA turned on was not affected.

The broader context here is about where responsibility sits. Because Moucka exploited weak login practices rather than a flaw in Snowflake's platform, the bulk of these break-ins trace back to how individual companies managed their own account security, not to a failure in the cloud provider itself.

The re-extortion tactic Herrington referenced is worth attention. After companies paid ransom to keep their stolen data from being published, Moucka came back to the same victims and demanded more money, knowing the data was still in his hands. Imagine paying someone to return your stolen car, only for them to come back weeks later demanding another payment before they hand over the keys. This approach is not new in principle, but the scale here, applied across more than 165 targets, suggests a deliberate business model rather than last-minute pressure.

The $9.5 million in documented losses, against $2.5 million in ransom collected and $500,000 in data sales, does not capture the full picture. Those figures cover direct financial impact and extortion revenue, not the downstream costs like fixing the damage, regulatory fines, notifying customers, paying for credit monitoring, or the hit to a company's reputation. For AT&T, the exposure of call and text records for over 100 million customers alone carries compliance and legal costs that dwarf the DOJ's total loss figure. The full cost will surface over years, not in a press release.

Moucka's plea closes the criminal phase of one of 2024's most damaging breach campaigns. Co-conspirators were mentioned in the DOJ's filings but not named in the announcement, leaving the possibility of additional charges open. Snowflake itself was not charged and cooperated with the investigation. The company has since required multi-factor authentication across its customer base, a step that closes the specific gap Moucka exploited but arrives only after the damage was done.