enforcementtrade-pressNewsThe Broadside1 min read

Moucka pleads guilty in 165-firm Snowflake breach campaign

The re-extortion of a victim using a government official's family data shows how far past credential theft this ring went.


TL;DR

Connor Riley Moucka pleaded guilty Wednesday in Seattle federal court to computer fraud, wire fraud, aggravated identity theft, and conspiracy for his role in the 2024 Snowflake breach campaign. The 26-year-old Canadian faces up to 32 years at sentencing on October 27. Moucka and co-conspirators used stolen credentials, some valid since 2020, to access Snowflake accounts at 165 companies including AT&T, Ticketmaster, and Santander, netting about $2.5 million in ransoms. Prosecutors said Moucka re-extorted at least one victim using stolen data from a government officer's family. He's the third ring member to face accountability after former U.S. soldier Cameron Wagenius's guilty plea last July and John Binns's detention in Turkey.

Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty Wednesday in Seattle federal court to computer fraud, wire fraud, aggravated identity theft, and conspiracy. Sentencing is set for October 27; the statutory maximum is 32 years, though guideline sentences typically run lower. Moucka was arrested in Canada in October 2024 and extradited to the U.S. in July 2025.

The breach campaign didn't exploit a Snowflake vulnerability. Mandiant, retained by Snowflake in May 2024, found the attackers used valid login credentials, some dating to 2020, stolen through infostealer malware and never rotated or protected by multifactor authentication. That credential hygiene failure gave the group access to 165 companies' customer data: Social Security numbers, passport numbers, driver's license records, DEA registration numbers, and more.

The downstream numbers are staggering. AT&T lost call and text logs for over 100 million customers. Ticketmaster exposed roughly 560 million user records. Total direct losses to victim companies: $9.5 million. The crew pulled in about $2.5 million in ransom payments. Moucka separately earned roughly $495,000 selling stolen data on BreachForums and XSS.is.

Prosecutors flagged re-extortion as an aggravating feature. Moucka targeted at least one victim twice, using stolen data from a government officer and that officer's family members. The FBI's W. Mike Herrington called the tactics "calculated and predatory."

Moucka is the third ring member to face consequences. Cameron John Wagenius, a former U.S. Army soldier, pleaded guilty in July 2025 and faces up to 27 years. John Erin Binns, the alleged Turkey-based co-conspirator, was detained in 2024. Moucka told 404Media before his arrest that he expected to be caught and was destroying evidence.


Published ·Updated ·Deep Fathom