Canadian hacker admits to Snowflake data thefts that hit 165 companies and 100 million people
Connor Moucka pleaded guilty to stealing terabytes from Snowflake customer accounts that had no second login step, extorting $2.5 million in bitcoin from victims including AT&T and Ticketmaster.

Key points
- Connor Riley Moucka, 26, pleaded guilty in a US court to breaking into at least 165 company accounts on cloud storage provider Snowflake between February and October 2024.
- The hackers got in by using stolen usernames and passwords on accounts that had no second login check, a protection called multi-factor authentication.
- Victims include AT&T, Ticketmaster, Santander, Advance Auto Parts, Neiman Marcus and the Los Angeles Unified School District.
- Moucka and his co-defendant John Erin Binns extorted at least $2.5 million in bitcoin from three victims, and Moucka made another $495,000 selling stolen data on hacker forums.
- The US Department of Justice says more than 100 million people had personal information exposed, with company losses topping $9.5 million.
A 26-year-old Canadian has pleaded guilty to one of the messiest cloud breaches of the last decade, and the failure mode here is embarrassingly simple: customer accounts on Snowflake, a big cloud data warehouse used by large companies to store analytics data, were left without a second login step.
Connor Riley Moucka, who also went by Alexander Moucka and Waifu online, admitted in court to computer fraud, wire fraud, aggravated identity theft and conspiracy. He was arrested in October 2024 and is due to be sentenced on 27 October. He faces up to 32 years in prison.
His co-defendant, John Erin Binns, was picked up in Turkey. A Turkish court approved a US extradition request, but Binns contested it.
How did the hackers get in?
They logged in with stolen passwords. That is the whole trick.
Moucka and Binns pulled usernames and passwords from computers already infected with infostealer malware, which is a type of virus that quietly copies saved logins from a victim's browser and sends them to the criminal. They then tried those logins against Snowflake customer accounts. Where the customer had not turned on multi-factor authentication, meaning a second check like a code from a phone app, the password alone let them in.
Once inside, according to court documents first reported by BleepingComputer, they ran custom software to sweep each account for valuable material: company names, staff roles, network addresses, and then the databases themselves. Terabytes of data walked out.
Who was hit and what was taken?
The victim list reads like a slice of the Fortune 500. AT&T, Ticketmaster, Santander, Pure Storage, Advance Auto Parts, the Los Angeles Unified School District, QuoteWizard/LendingTree and Neiman Marcus all appear in the case.
| Detail | Figure |
|---|---|
| Companies breached | at least 165 |
| People affected | more than 100 million |
| Bitcoin extortion paid | at least $2.5 million |
| Data sold on forums | at least $495,000 |
| Reported victim losses | more than $9.5 million |
Stolen records included call and text history (not the content of messages), banking details, payroll files, driver's licence numbers, passport numbers, Social Security numbers, and Drug Enforcement Administration registration numbers used by doctors to prescribe controlled drugs.
Prosecutors say Moucka went back to at least one victim for a second round of extortion, using stolen data belonging to a government officer and their family as leverage.
Should ordinary customers worry?
If you were an AT&T or Ticketmaster customer in 2024, your data is almost certainly in this pile already. In practice, the sensible steps are the same ones: freeze your credit if you are in the US, turn on two-step login for your email and bank, and be sceptical of any call or text that references details a stranger should not know.
One thing the post-mortem will say, clearly, is that this was not a Snowflake software flaw. Snowflake's platform was not broken into. Customer tenants, the individual company accounts inside it, were left with password-only logins while infostealer malware was quietly harvesting those passwords from employee laptops for months. After the breaches, Snowflake said it would force multi-factor authentication on and require passwords of at least 14 characters. That should have been the default years ago.
Operational takeaway: if your cloud provider lets a single stolen password reach production data, you do not have a cloud security programme, you have a billing relationship.



