Industry News

Canadian Man Admits Role in Massive Snowflake Data Extortion Spree

Krebs on Security · 7 Aug 2026
Key Takeaway Before trusting a cloud provider with your business data, confirm they enforce strong access controls like multi-factor authentication, since a breach at their end can expose your data too.

Connor Riley Moucka, a 26-year-old man from Kitchener, Ontario, has pleaded guilty to computer fraud and conspiracy charges linked to one of 2024's most significant cybercrime campaigns. Moucka admitted to hacking and extorting more than 165 organisations that used the cloud data storage platform Snowflake, one of many businesses relying on cloud services to store customer and operational data.

Among the most damaging incidents tied to Moucka was the theft of call and text history records belonging to more than 100 million AT&T customers. The scale of the campaign highlights how attackers increasingly target third-party cloud service providers rather than individual businesses, since a single successful breach can expose data from dozens or hundreds of downstream customers at once.

This case is a reminder that even businesses that don't manage their own servers are exposed to risk through the cloud vendors and platforms they use. Small businesses using cloud storage or software-as-a-service providers should understand how their vendors secure customer data and what safeguards, such as multi-factor authentication and access monitoring, are in place to prevent unauthorised access.

Summarised by CISO AI from Krebs on Security. We link back to every original so you can read it yourself.