incident-responsetrade-pressNewsThe Broadside1 min read

Moucka pleads guilty in Snowflake extortion campaign

The plea pulls back the curtain on re-extortion tactics (using a victim's stolen government-official data to squeeze twice) that most breach narratives leave out.


TL;DR

Connor Moucka pleaded guilty Wednesday to computer fraud, wire fraud, and aggravated identity theft for his role in the 2024 Snowflake customer attack spree that compromised more than 165 environments and exposed records of over 100 million people. Moucka personally earned $495,000 of the $2.5 million in combined extortion payments; victim companies bore $9.5 million in losses. He faces up to 32 years at sentencing October 27. Co-conspirators John Binns and Cameron Wagenius remain unnamed in the plea but were indicted alongside him. The DOJ release is unusually specific about one tactic: Moucka re-extorted a victim using stolen data belonging to a government official and members of a former official's immediate family.

Moucka's guilty plea in the Western District of Washington is the first conviction to emerge from the Snowflake campaign, and the DOJ's factual account fills in details that the initial Mandiant attribution and the November 2024 indictment left opaque.

The re-extortion detail

The indictment described extortion and data sales. Wednesday's plea agreement goes further: after one victim paid, Moucka re-extorted them using stolen data of a government official and family members of a then-former official. That's not opportunistic, it's escalation as business model. The plea establishes that Moucka knew exactly whose data he had and used its sensitivity as leverage beyond the initial ransom.

The money

The $495,000 Moucka personally obtained is less than a fifth of the $2.5 million in combined extortion proceeds the DOJ attributes to the three co-conspirators. That split (one operative pocketing under 20%) suggests a structured arrangement, not a loose collective. The $9.5 million in victim losses, explicitly excluding downstream customer harm, puts a floor under the damage figure that the 100-million-records number has always implied but rarely quantified.

What's not in the plea

Snowflake is not named in the DOJ release, the standard "U.S. cloud storage provider" formulation, but the 165-customer figure matches Mandiant's June 2024 attribution to UNC5537. Moucka's aliases (Waifu, Judische, Catist, Ellyel8) are confirmed in the plea documents. Binns remains in Turkish custody; Wagenius, the U.S. Army soldier, filed a notice of intent to plead guilty in a separate matter earlier this year.

Sentencing realities

The 32-year maximum is statutory, not guidelines. Moucka's cooperation (the plea itself suggests it, and the consent-to-extradition timeline from March 2025 supports it) will weigh heavily at sentencing. The October 27 date gives the government roughly 14 months from extradition to sentencing, which is fast for a multi-defendant international cybercrime prosecution.


Published ·Updated ·Deep Fathom

Moucka pleads guilty in Snowflake extortion campaign — The Broadside