Moucka pleads guilty in Snowflake customer account breach case

Connor Riley Moucka, a 26-year-old from Kitchener, Ontario, has pleaded guilty in Seattle federal court to computer fraud, wire fraud, aggravated identity theft and a related conspiracy connected to the 2024 compromise of Snowflake customer accounts. Prosecutors said the intrusions affected at least 165 organisations and exposed records belonging to at least 100 million people.
Moucka personally received at least $495,000 from ransoms and sales of stolen data, the U.S. Department of Justice said. He is scheduled to be sentenced on October 27. The aggravated identity theft charge carries a mandatory minimum sentence of two years, while the remaining counts can bring sentences of up to 30 years.
Stolen passwords, not a platform exploit
The case centres on credentials collected by infostealer malware years before the campaign. Those passwords had not been rotated, and multi-factor authentication was disabled on the affected accounts. The Justice Department did not identify the SaaS provider in its announcement or in the October 2024 indictment, but Snowflake and Mandiant identified the platform in 2024.
Mandiant, which tracks the activity as UNC5537, said every incident it investigated led back to customer credentials stolen by infostealers. Some credentials had been harvested as early as November 2020 and remained valid. At least 79.7% of the accounts used by the group had been exposed previously, and the compromised instances lacked network allow lists.
The investigation therefore reinforces the pattern described in borrowed trust in cybersecurity as attackers continue to turn already-compromised identities into access paths for high-value systems. Mandiant said the campaign did not depend on a novel or particularly sophisticated technique; its scale reflected the broad infostealer market and credentials left unchanged for up to four years.
Scope, losses and remaining authentication changes
Prosecutors put victim companies' actual losses at more than $9.5 million, excluding downstream losses suffered by their own customers. Stolen information included non-content call and text history, payroll records, DEA registration numbers, passport numbers and Social Security numbers. AT&T said in July 2024 that call and text records covering nearly all of its cellular customers between May 1 and October 31, 2022 had been taken from its workspace on a third-party cloud platform.
The figures have shifted since 2024: 165 initially represented organisations notified as potentially exposed by Mandiant and Snowflake, while prosecutors now use it for customers actually compromised. The Justice Department release cites more than 165 organisations in its body, although Assistant Attorney General A. Tysen Duva referred to more than 150.
Snowflake has enforced MFA by default for human users on accounts created since October 2024. Its documentation says the final phase of blocking passwords as a sole factor for remaining human and service users is scheduled to roll out account by account between August and October 2026; reader and trial accounts are exempt.
For businesses, the practical implication is to treat infostealer exposure as an immediate credential-rotation event, require MFA, and apply network allow lists before an old password becomes a route into cloud data.

