Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2225+ Articles
157+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Canadian Pleads Guilty to Snowflake Cloud Data-Theft Attacks
Canadian Pleads Guilty to Snowflake Cloud Data-Theft Attacks
NEWS

Canadian Pleads Guilty to Snowflake Cloud Data-Theft Attacks

Connor Riley Moucka of Kitchener, Ontario pleaded guilty to orchestrating one of the largest cloud data-theft campaigns in history, stealing billions of records from 165 organizations including AT&T, Ticketmaster, and Santander.

Dylan H.

News Desk

August 6, 2026
3 min read

Connor Riley Moucka, 26, of Kitchener, Ontario — known online as "Waifu" and "Judische" — pleaded guilty on August 5, 2026 to federal charges stemming from one of the most consequential cloud data-theft campaigns ever documented. The attacks leveraged stolen credentials to breach Snowflake customer accounts at 165 organizations, exposing billions of sensitive records and netting millions in extortion payments.

How the Attack Worked

Between February and October 2024, Moucka and his co-conspirator, American John Erin Binns, executed a methodical campaign against Snowflake customer accounts that lacked multi-factor authentication (MFA). The attack chain was straightforward but devastatingly effective:

  1. Credential harvesting: Credentials were obtained via infostealer malware that had previously compromised employee devices
  2. Account access: MFA-absent Snowflake accounts were accessed using the stolen credentials
  3. Data identification: Custom tooling identified and extracted high-value datasets
  4. Extortion: At least 10 organizations received ransom demands ranging from $300,000 to $5 million

In at least one case, Moucka re-extorted a victim who had already paid, leveraging personal data belonging to a government official's family as additional pressure.

Scale of the Breach

The numbers are staggering:

MetricVolume
Victim organizations165
Call and text records stolen~50 billion
Individuals affected100+ million
Documented victim losses$9.5 million+
Bitcoin extorted36 BTC ($3.4M at time)

High-profile victims included AT&T, Ticketmaster, Santander, Pure Storage, Advance Auto Parts, Los Angeles Unified School District, QuoteWizard/LendingTree, and Neiman Marcus.

Arrest, Extradition, and Guilty Plea

Moucka was arrested in October 2024 through a collaborative operation involving Canadian, Australian, Spanish, Ukrainian, and Turkish law enforcement. He was extradited to the United States in July 2025.

His guilty plea covers multiple charges. Sentencing is scheduled for October 27, 2026. The aggravated identity theft count alone carries a mandatory minimum of two years; Moucka faces up to 32 years in total.

Co-conspirator John Erin Binns was separately indicted but has not yet pleaded.

The MFA Problem

The Snowflake campaign is a textbook example of what happens when cloud platforms and their customers treat MFA as optional. Snowflake itself was not breached — the platform's infrastructure remained intact. The attacks succeeded entirely because legitimate credentials, harvested through third-party infostealer infections, were used to log into accounts without any secondary verification.

In the aftermath, Snowflake introduced mandatory MFA enforcement policies and worked with customers to identify and remediate exposed accounts.

Key Takeaways

  • Infostealer malware feeding into cloud credential abuse remains one of the most effective attack vectors of 2024–2026
  • MFA on cloud data platforms is non-negotiable — its absence was the single enabling condition for all 165 breaches
  • Re-extortion of already-paid victims is an emerging tactic among ransomware and data extortion actors
  • Multi-country law enforcement coordination successfully tracked and apprehended actors operating across borders
  • Sentencing in October 2026 could result in one of the longest sentences handed down for cloud-focused cybercrime
#Cloud Security#Data Breach#Cybercrime#Snowflake

Related Articles

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

Connor Riley Moucka pleaded guilty in Seattle federal court to computer fraud, wire fraud, and aggravated identity theft over the 2024 Snowflake credential-stuffing campaign that breached 165+ organizations and exposed records belonging to at least 100 million people.

5 min read

Snowflake Customers Hit in Data Theft Attacks After SaaS

Over a dozen companies have suffered data theft attacks after a SaaS integration provider was breached and authentication tokens stolen, enabling...

5 min read

Biotech Giant Amgen Says Patient Data Stolen From Third-Party Cloud Systems

Amgen disclosed via SEC Form 8-K that threat actors accessed patient health information and proprietary company data through breaches of multiple third-party cloud environments, triggering dual HIPAA and SEC disclosure obligations.

5 min read
Back to all News