Canadian cybercriminal pleads guilty in massive Snowflake data extortions
Connor Riley Moucka, a 26-year-old Canadian from Kitchener, Ontario, pleaded guilty to hacking Snowflake customers between February and October 2024. He admitted stealing call and text history records for over 100 million AT&T customers and extorting victims including TicketMaster, Lending Tree, and Neiman Marcus. The U.S. Justice Department documented Moucka used stolen credentials from Snowflake accounts without multi-factor authentication to target at least 165 customers, stealing sensitive data like social security numbers, banking details, and government records. Moucka and co-conspirators made over $2.5 million in ransom payments, re-extorting victims by threatening to publish stolen data—including from government officials. Moucka faces a mandatory minimum of two years in prison for aggravated identity theft.
This incident highlights how unsecured cloud infrastructure creates friction in digital security. When critical systems lack robust authentication, attackers can systematically extract vast personal data, directly undermining financial privacy and identity safety for millions. The case shows that even major cloud providers remain vulnerable to sophisticated extortions when security protocols are inadequate.
The source reports all victim and data quantities per U.S. Justice Department statements. This brief reflects the material’s scope—detailing the scale and mechanism without extrapolation.
Source: Krebs on Security
MANY MINDED