Snowflake Hacker Pleads Guilty in US Court, Faces Over 30 Years in Prison
Connor Riley Moucka, a 26-year-old Canadian national, has pleaded guilty to his role in a massive cybercrime campaign that targeted Snowflake data storage accounts of 165 organizations. The scheme, attributed to the threat actor UNC5537, resulted in the theft of billions of sensitive data records and led to extortion attempts against victims.
Moucka’s involvement in the campaign was significant, as he used stolen login credentials to access data stored by organizations, including major brands like AT&T, Advance Auto Parts, Ticketmaster, Santander Bank, Neiman Marcus, Anheuser-Busch, Allstate, Mitsubishi, Progressive, and State Farm. The hackers stole personal and financial information, extorted victims, and sold the stolen data on hacking forums, with Moucka earning half a million dollars.
The scale of the operation is staggering, with the Department of Justice (DOJ) estimating that over 100 million people were affected by the hack. In addition to the financial losses suffered by targeted companies – totaling more than $9.5 million – victims also faced significant personal data breaches. The hackers received a total of $2.5 million in ransom payments, highlighting the lucrative nature of these types of cybercrimes.
Moucka’s guilty plea comes after his arrest in late 2024 and extradition to the United States in July 2025. He now faces more than 30 years in prison for computer fraud, wire fraud, aggravated identity theft, and a related conspiracy. Sentencing is scheduled for October 27. The case also raises concerns about the involvement of former US soldier, who pleaded guilty roughly one year ago to hacking into AT&T and Verizon systems, in the Snowflake campaign.
The Snowflake hack highlights the vulnerability of cloud-based data storage solutions and the importance of robust security measures. Organizations must prioritize implementing multi-factor authentication, regular security audits, and employee education to prevent similar breaches from occurring. As cybersecurity threats continue to evolve, it’s essential for businesses and individuals alike to stay vigilant and proactive in protecting sensitive information.
In light of this case, organizations using Snowflake data storage should review their security protocols immediately and consider implementing additional safeguards to protect against future attacks. By prioritizing cybersecurity and staying informed about emerging threats, we can reduce the risk of similar hacks occurring in the future.
Source: SecurityWeek — 2026-08-06