Connor Moucka pleads guilty in attacks on 165 Snowflake customers

Connor Moucka, a 26-year-old Canadian citizen accused of compromising cloud provider Snowflake and accessing customer environments, has pleaded guilty to hacking more than 165 companies, stealing billions of records and extorting companies and individuals. The U.S. Department of Justice announced the plea on Wednesday.
The case involved dozens of Snowflake customers, including AT&T, LendingTree and Ticketmaster. Prosecutors said Moucka and his co-conspirators accessed victim data through the Snowflake-related campaign, with AT&T among the organisations affected.
Financial and personal data impact
The Justice Department said Moucka and his accomplices received more than $2.5 million in ransom payments over several years. Moucka also received roughly $500,000 from selling victims' data on hacking forums, including BreachForums.
Victims of the hacking activity suffered $9.5 million in losses, the DOJ said. The material taken included data on more than 100 million AT&T customers, including call and text records. Other breaches exposed banking information, drivers' licence numbers and Social Security numbers.
FBI special agent W. Mike Herrington said the threats and re-extortion tactics were “calculated and predatory” and caused harm to targeted companies as well as to millions of their customers.
Case timeline and sentencing
Moucka used the online aliases Waifu and Judische. Canadian authorities arrested him at the end of 2024, months after the Snowflake breaches. At the time, Mandiant senior researcher Austin Larsen described him as one of the most consequential hackers of 2024.
The guilty plea follows the case involving Snowflake attacks on 165 organisations, whose customer-access implications extended beyond a single organisation. Moucka is scheduled to be sentenced on October 27 and faces decades in prison.
Business implication
For businesses using cloud platforms, the case underlines the practical need to protect account access, monitor unusual activity and prepare to investigate potential customer-data exposure quickly when a service environment is targeted.

