Canadian hacker admits to Snowflake data thefts that hit 165 companies and 100 million people
Connor Moucka pleaded guilty to stealing terabytes from Snowflake customer accounts that had no second login step, extorting $2.5 million in bitcoin from victims including AT&T and Ticketmaster.

Key points
- Connor Riley Moucka, 26, pleaded guilty in a US court to breaking into at least 165 company accounts on cloud data warehouse Snowflake between February and October 2024.
- Accounts fell because they had no multi-factor authentication, meaning a stolen password alone was enough to get in.
- Victims include AT&T, Ticketmaster, Santander, Advance Auto Parts and Neiman Marcus, among others.
- Moucka and co-defendant John Erin Binns extorted at least $2.5 million in bitcoin from three victims; Moucka collected a further $495,000 selling stolen data on hacker forums.
- The US Department of Justice says more than 100 million people had personal data exposed and victim companies lost more than $9.5 million.
A 26-year-old Canadian has pleaded guilty to one of the messiest cloud breaches in recent memory. The failure mode is embarrassingly simple: customer accounts on Snowflake, a cloud data warehouse used by large enterprises to store analytics data, were left without a second login step while infostealer malware quietly harvested their passwords.
Connor Riley Moucka, who used the handles Alexander Moucka and Waifu online, admitted to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy. Arrested on 30 October 2024, he's scheduled for sentencing on 27 October and faces a maximum of 32 years. Co-defendant John Erin Binns was arrested in Turkey; a local court approved the US extradition request, though Binns has contested it.
We've followed the Snowflake account-theft campaign since it surfaced: this is our third story on the subject since early August 2026.
How did the hackers get in?
They logged in with stolen passwords. That is the whole trick.
Moucka and Binns pulled credentials from computers already infected with infostealer malware, a type of software that silently copies saved logins from a victim's browser and ships them to the attacker. Those credentials were then tried against Snowflake customer accounts. Where multi-factor authentication, the second check like a code from a phone app, had not been switched on, the password alone opened the door.
Once inside, court documents reported by BleepingComputer show they ran custom software to sweep each tenant for valuable material: organisation names, user roles and IP addresses, followed by the databases themselves. Terabytes walked out.
Who was hit and what was taken?
The affected companies span several major industries. AT&T, Ticketmaster, Santander, Pure Storage, Advance Auto Parts, the Los Angeles Unified School District, QuoteWizard/LendingTree and Neiman Marcus all appear in the case.
| Detail | Figure |
|---|---|
| Companies breached | at least 165 |
| People affected | more than 100 million |
| Bitcoin extortion paid | at least $2.5 million |
| Data sold on forums | at least $495,000 |
| Reported victim losses | more than $9.5 million |
Stolen records included call and text history (not message content), banking details, payroll files, driver's licence numbers, passport numbers and Social Security numbers, along with Drug Enforcement Administration registration numbers that doctors use to prescribe controlled substances.
Prosecutors say Moucka returned to at least one victim for a second extortion attempt, using stolen data belonging to a government officer and that officer's immediate family as the threat.
Should ordinary customers worry?
If you were an AT&T or Ticketmaster customer in 2024, your data's probably in this pile. Freeze your credit if you're in the US, turn on two-step login for email and banking, and treat any call or text that references details a stranger shouldn't have as suspect.
The post-mortem here is unambiguous: this wasn't a Snowflake platform flaw. Individual customer tenants inside Snowflake were sitting on password-only logins while infostealers harvested those passwords from employee machines for months. After the breaches came to light, Snowflake said it would enforce MFA and require passwords of at least 14 characters. Both should've been the default from day one.
The real story is how long single-factor access to production cloud storage was treated as acceptable. If a single stolen password can reach your data warehouse, you don't have a cloud security programme. You have a billing relationship.



