Canadian Hacker Pleads Guilty in $2.5M Snowflake Data Breach Extortion
Connor Riley Moucka, of Kitchener, Ontario, has pleaded guilty to computer fraud and conspiracy charges stemming from a massive 2024 extortion campaign that compromised more than 165 organizations using the Snowflake cloud platform. Between February and October 2024, Moucka and co-conspirators exploited stolen login credentials for Snowflake customer accounts that did not enforce multi-factor authentication, breaching well-known companies including Ticketmaster, Lending Tree, Advance Auto Parts, and Neiman Marcus. The operation netted over $2.5 million in ransom payments and resulted in the theft of billions of sensitive records from a single U.S.-based SaaS provider.
The stolen dataset included non-content call and text history records of more than 100 million AT&T customers, alongside banking and financial information, payroll records, DEA registration numbers, driver's license numbers, passport numbers, and Social Security numbers. In response, Snowflake enforced mandatory MFA across its platform and increased password complexity requirements. Defenders should treat this case as a reminder to audit their own hygiene: verify whether corporate or personal credentials have appeared in known dumps with an email breach checker, and test password strength using a password checker before reusing secrets across services.
Moucka operated under multiple aliases, most notably "Judische" and "Waifu," frequently rotating identities while sometimes maintaining several concurrently. His involvement in data breaches and voice phishing attacks against U.S. companies dates to at least 2020, according to a September 2024 KrebsOnSecurity investigation that first publicly linked his Judische persona to the Snowflake thefts. Canadian authorities arrested Moucka in late October 2024 on a provisional U.S. warrant following an RCMP investigation, and the U.S. Justice Department has now secured a guilty plea on federal charges carrying significant prison time.
Beyond corporate extortion, Moucka and co-conspirators harassed government officials and security researchers attempting to track them, at one point leveraging stolen personal data belonging to a government officer and their immediate family in a re-extortion attempt against an already-compromised victim. Court filings also link Moucka to extremist groups that target and extort minors online. Given the breadth of exposed PII, affected individuals and security teams should run a privacy checkup to evaluate digital exposure, rotate any reused credentials, and ensure hardware-backed MFA is enabled on every account that supports it.