Canadian pleads guilty to Snowflake cloud data-theft attacks

A Canadian Man Pleads Guilty to Extortion Scheme Involving Stealing Data from 165 Organizations on Snowflake Cloud Storage

Connor Riley Moucka, a 26-year-old Canadian man also known as Alexander Moucka and Waifu, has pleaded guilty to his role in a brazen extortion scheme that targeted over 165 organizations using Snowflake’s cloud storage service. The scheme, which spanned several months from February to October 2024, resulted in the theft of sensitive data belonging to hundreds of millions of individuals.

Moucka and his co-conspirator, John Erin Binns, exploited a glaring security vulnerability on Snowflake: the lack of multi-factor authentication (MFA) protection for some customer accounts. Without MFA enabled, the duo could access company accounts using nothing more than stolen login credentials obtained via infostealer malware. Once inside, they used custom software to identify valuable information stored in cloud storage instances.

The data theft was staggering, with terabytes of sensitive information compromised from each targeted organization. The list of affected companies includes high-profile names such as AT&T, Ticketmaster, and Neiman Marcus. Moucka and Binns then attempted to extort these companies by threatening to release the stolen data, obtaining at least $2.5 million in bitcoin from three victims.

The scope of the damage is staggering: over 100 million individuals have been affected, and victim companies suffered losses exceeding $9.5 million. In one particularly egregious case, Moucka used stolen data to re-extort a victim by threatening further disclosure of sensitive information.

In a press release announcing Moucka’s guilty plea, the U.S. Department of Justice highlighted the severity of the crimes: “Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt.” The DoJ also noted that victim companies suffered more than $9.5 million in losses.

Following these high-profile breaches, Snowflake announced plans to enforce MFA protection for all customer accounts and require passwords to be at least 14 characters long. This move highlights the importance of robust security measures in preventing similar attacks.

The takeaway from this case is clear: even the most seemingly secure cloud storage services can be vulnerable if left unpatched or unprotected. Organizations must prioritize strong security practices, including MFA protection, regular software updates, and rigorous threat detection protocols to prevent such breaches. By staying vigilant and testing their defenses regularly, companies can avoid becoming the next victim of a data theft scheme like this one.


Source: Bleeping Computer — 2026-08-05