A Canadian Man’s Guilty Plea Exposes Widespread Data Theft from Snowflake Cloud Storage Provider
Connor Riley Moucka, a 26-year-old Canadian, has pleaded guilty to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations. The scheme, which unfolded between February and October 2024, resulted in the theft of hundreds of millions of individuals’ sensitive information, including Social Security numbers, passport numbers, and banking details.
Moucka’s accomplice, John Erin Binns, was also implicated in the attacks but remains at large after being arrested in Turkey. The two men used stolen login credentials to access Snowflake accounts that lacked multi-factor authentication (MFA). Without MFA enabled, an attacker needs only a user’s correct username and password to gain access to customer accounts.
Once inside, Moucka and Binns used custom software to identify valuable information stored in cloud storage instances. They then extorted multiple companies by threatening to disclose the stolen data unless they paid millions of dollars in bitcoin. At least three victims were forced to pay out $2.5 million, while Moucka also sold the stolen data on hacker forums for an additional $495,000.
The scope of the attacks is staggering, with over 100 million individuals affected and victim companies suffering losses exceeding $9.5 million. The list of impacted organizations includes well-known brands like AT&T, Ticketmaster, Santander, and Neiman Marcus.
Snowflake’s response to the breach has been swift, with the company announcing that it will now enforce MFA protection and require all passwords to be at least 14 characters long. This move is a welcome step towards improving cloud security, but it highlights the importance of proactive measures in preventing such attacks from happening in the first place.
In this case, Moucka’s guilty plea serves as a stark reminder that even with robust security protocols in place, human error and lack of vigilance can still leave organizations vulnerable to attack. The fact that Snowflake accounts without MFA were targeted suggests that many companies may be neglecting basic security best practices.
This incident underscores the need for businesses to regularly test their defenses and stay one step ahead of attackers. By doing so, they can reduce the risk of falling victim to similar data breaches in the future. As the cybersecurity landscape continues to evolve, it’s essential for organizations to remain vigilant and prioritize robust security measures to protect sensitive information.
In light of this case, companies would do well to review their cloud storage configurations and ensure that all accounts have MFA enabled. Regularly testing security controls and staying up-to-date with industry best practices can also help mitigate the risk of similar attacks in the future.
Source: Bleeping Computer — 2026-08-05