Snowflake hacker's guilty plea shows what stolen-credential extortion actually costs
Cybersecurity

Snowflake hacker's guilty plea shows what stolen-credential extortion actually costs

Connor Riley Moucka admitted to breaching more than 165 Snowflake customer accounts using credentials that had been circulating since 2020, exposing data on at least 100 million people and facing up to 32 years in prison.

PublishedAugust 15, 2026
Read time5 min read
Share

A guilty plea that closes the loop on one of 2024's biggest breaches

Connor Riley Moucka, a 26-year-old from Kitchener, Ontario, pleaded guilty in a Washington state federal court on August 5 to computer fraud, wire fraud, aggravated identity theft, and conspiracy. The charges cover a campaign that ran from February through October 2024, when Moucka and co-conspirators accessed Snowflake customer environments using credentials stolen through prior infostealer infections, some of them years old by the time they were used, well before Snowflake or most of its customers had any reason to suspect exposure.

The company list reads like a cross-section of corporate America: AT&T, whose exposure covered call and text logs for more than 100 million customers, Ticketmaster, with roughly 560 million user records, plus Advance Auto Parts, Neiman Marcus, Santander, LendingTree, and a major U.S. school district. In total, prosecutors say Moucka's group breached more than 165 Snowflake customer accounts and exposed data belonging to at least 100 million people, making this one of the largest credential-driven breach campaigns ever prosecuted to a guilty plea in the United States.

Stolen credentials and missing MFA opened every door

Snowflake's platform held up throughout this campaign. The attackers used valid, stolen usernames and passwords against customer accounts that had not enabled multi-factor authentication and had not rotated credentials that were already circulating on criminal forums, harvested years earlier by infostealer malware on employee devices with no connection to Snowflake itself. That is a familiar and unglamorous failure mode, and it is exactly why it worked at scale: 165 separate customers making the same configuration choice is a systemic gap across an entire customer base, not a one-off mistake by a single security team.

Snowflake's response after the breaches became public was to push default MFA and network policy controls harder across its customer base, a fix that is correct but arrived after the damage was done. Every enterprise running data warehouses, SaaS backends, or any credential-gated cloud service should read this case as a direct argument for making MFA mandatory rather than optional at the account level, with no exceptions carved out for legacy integrations, service accounts, or partner access that predates the current security policy.

The money trail behind the extortion

Court filings put real numbers on what stolen enterprise data is worth to the people who steal it. Moucka's crew collected roughly 2.5 million dollars in ransom payments from victim companies attempting to prevent public release of their data. Separately, Moucka personally earned about 495,000 dollars advertising and selling the stolen data on forums including BreachForums, using the aliases Waifu and Judische, even after the group had already extracted ransom from some victims, and prosecutors say total losses to victim companies reached 9.5 million dollars once incident response, legal fees, and notification costs are included.

That re-extortion pattern, collecting a ransom and then monetizing the same data a second time on criminal markets, is the detail prosecutors emphasized most. FBI Special Agent W. Mike Herrington said Moucka's threats and re-extortion tactics were calculated and predatory, and that his actions did real harm both to the companies targeted for theft and extortion and to the millions of customers whose data was exposed as a result. That double monetization, ransom first and then a second payday from resale, is becoming a standard feature of extortion cases rather than an aggravating outlier.

What 32 years signals for the next case

Moucka was arrested in Canada in November 2024, extradited to the U.S. in July 2025, and now faces sentencing on October 27 with exposure of up to 32 years in prison. That sentencing range, for a scheme built on credential theft and account access rather than a software exploit, is a meaningful data point for prosecutors and defense counsel handling the next large-scale extortion case built the same way, and it signals that courts are willing to treat aggregated identity theft across many victim organizations as seriously as they treat a comparable ransomware deployment.

It also matters for enterprise risk modeling. Boards evaluating cyber insurance and incident response budgets often anchor their thinking on ransomware payouts and remediation costs. This case puts a concrete number on the other side of the ledger: how much criminal upside a single unsecured cloud account, chained across 165 customers, generates for the people exploiting it, and how seriously federal prosecutors are now willing to pursue that upside after the fact, years after the initial credential theft that made it all possible.

The roadmap implication: identity is still the perimeter that matters

None of the technology involved in this case was exotic. No zero-day, no novel malware family, just stolen passwords, absent MFA, and patient reconnaissance across a large customer base that shared the same platform and the same gap in default configuration. That is the least reassuring part of the story for any CTO reviewing their own SaaS and data platform footprint, because it means the fix was always available and always cheap relative to the outcome, and 165 separate security teams still did not apply it before the campaign ran its course.

The practical takeaway for the next planning cycle is to treat MFA enforcement, credential rotation, and session monitoring on every data platform vendor as a floor, not a discretionary hardening step, and to specifically audit any account whose credentials may have been exposed in an infostealer log at any point in the past, since this case shows attackers are willing to sit on stolen credentials for years before using them. A credential that looks stale from the inside can still be live ammunition sitting on a criminal forum, waiting for the right moment.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#snowflake#credential-stuffing#extortion#connor-riley-moucka#data-theft-prosecution#criminal-sentencing