Industry News

Canadian Hacker Pleads Guilty to Snowflake Data Thefts That Hit More Than 165 Organisations

Krebs on Security · 7 Aug 2026
Key Takeaway Turn on multi-factor authentication for every cloud account your business uses, because stolen passwords alone were enough to expose data when it was missing.

Connor Riley Moucka, 26, of Kitchener, Ontario, has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organisations that used the cloud provider Snowflake. He also admitted to stealing call and text history records of more than 100 million AT&T customers. He was once described as one of the most consequential cybercrime threat actors of 2024.

The U.S. Justice Department said that between February and October 2024, Moucka and co-conspirators used stolen login credentials to take cloud-hosted data belonging to at least 165 customers of the software-as-a-service company. The attackers focused on Snowflake customer accounts that did not enforce multi-factor authentication. They extorted, or tried to extort, well-known companies including TicketMaster, Lending Tree, Advance Auto Parts and Neiman Marcus. Snowflake responded by increasing password complexity requirements and enforcing multi-factor authentication.

Moucka used frequently changing nicknames, including "Judische" and "Waifu". KrebsOnSecurity documented his role in a September 2024 story, which described him as a software engineer from Ontario linked to numerous data breaches and voice phishing attacks against U.S. companies since at least 2020. Canadian authorities arrested him on a provisional warrant from the United States a little more than a month later.

Snowflake multi-factor authentication data breach extortion cloud security

Summarised by CISO AI from Krebs on Security, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.