XOOMAR
Wooden tiles spelling 'phishing' highlight cybersecurity themes.
CybersecurityAugust 9, 2026· 5 min read· By XOOMAR Insights Team

Snowflake Hacker Admits $2.5M Ransom Plot

Share
Updated on August 9, 2026

Connor Riley Moucka stole data on roughly 100 million people and earned his syndicate over $2.5 million in ransom payments from companies like AT&T and Ticketmaster. Now the 26-year-old Canadian has pleaded guilty in a U.S. federal court, admitting to a hacking spree that stands as one of 2024's most significant cloud compromises according to SecurityWeek. He faces over 30 years in prison.

XOOMAR Intelligence

Analyst Take

64/ 100
Moderate
4 sources analyzedLow confidenceTrend10Freshness99Source Trust85Factual Grounding84Signal Cluster20

A $2.5 Million Ransom Heist Fueled by Stolen Passwords

The attackers’ method was simple but devastatingly effective. Moucka and his co-conspirators used stolen login credentials to breach Snowflake customer accounts that lacked mandatory multi-factor authentication. This was not a sophisticated software exploit but a brute-force credential attack.

“Hiding behind a screen is no shield from justice,” said Assistant Director Brett Leatherman of the FBI’s Cyber Division. “Moucka learned that when he was arrested just months after he began targeting U.S. companies.”

Once inside, they exfiltrated billions of sensitive records and terabytes of data. The haul included customer call records from AT&T, payroll data, Social Security numbers, driver's license details, and even Drug Enforcement Administration registration numbers.

The group's business model was extortion: threaten to publish the data unless paid. The U.S. Department of Justice stated the conspirators received over $2.5 million in ransom payments. Moucka personally profited by selling stolen data on cybercrime forums like BreachForums and Telegram, netting at least $495,000. In one egregious act, he re-extorted a victim using stolen personal data of a government officer and their family. This aligns with our previous coverage of the Canadian Hacker’s Snowflake Heist Nets $2.5 Million Ransom.

Victims included a who’s who of corporate America:

  • AT&T (over 100 million customer call records)
  • Ticketmaster
  • Santander Bank
  • Advance Auto Parts
  • Neiman Marcus
  • Anheuser-Busch
  • State Farm and Progressive

The DOJ pegged direct losses to these companies at over $9.5 million, a figure that excludes the incalculable costs for the at least 100 million individuals whose data was stolen.

The Co-Conspirator Network and a Notorious Online Persona

Moucka, who operated under aliases including “Judische” and “Waifu,” did not act alone. His guilty plea sheds light on a network of alleged accomplices.

  • Cameron “Kiberphant0m” Wagenius: A U.S. Army soldier who pleaded guilty last year to extorting AT&T and Verizon. Prosecutors consider him a co-conspirator in the Snowflake campaign. He is scheduled for sentencing in September 2026.
  • John Erin Binns (aka “IRDev”): Indicted for the massive 2021 T-Mobile breach, Binns is named as the third alleged conspirator. Sources indicate he recently obtained Turkish citizenship, complicating any potential U.S. extradition.

Researchers link these individuals to The Com, a sprawling online criminal network known for harassment, sextortion, and data theft. Moucka’s online behavior was brazen and erratic. Security researcher Allison Nixon of Unit 221B noted, “His behavior was bizarre throughout. Even while stealing data and extorting victims, he did many unnecessary things like threatening me because he thought I was working on his case.”

Nixon argues Moucka’s legacy is one of “failure” that poisoned the well for other extortionists. “He extorted and then scammed his victims by not deleting the data, casting doubt on all future pay-or-leak extortion gangs,” she told CyberScoop.

From Guilty Plea to a Decades-Long Prison Term

With the guilty plea entered, the focus shifts to sentencing and precedent. Moucka is scheduled to be sentenced on October 27. He faces a mandatory minimum of two years for aggravated identity theft and a statutory maximum of 30 years for the other charges, meaning he could potentially serve over three decades behind bars.

XOOMAR Analysis: The judge's final sentence will hinge on several factors.

  • Cooperation: Has Moucka provided substantial information on his co-conspirators or other operations to prosecutors?
  • Restitution: While the victim companies lost over $9.5 million, the court may consider his personal gain ($495k) versus the syndicate's total haul ($2.5M+) when ordering repayment.
  • Nature of the Crime: The scale, the re-extortion using a government official's family data, and the harassment of investigators are severe aggravating factors that will weigh against leniency.

This case is a stark marker for cross-border cyber enforcement. Moucka was arrested in Canada within months of the attacks and extradited within a year, a relatively swift timeline for international cybercrime cases. It signals that high-impact, financially motivated attacks against U.S. corporations will trigger rapid, coordinated international law enforcement action.

For affected companies, the legal fallout is likely just beginning. While Moucka's prosecution addresses the criminal act, the breach’s root cause, customers not enforcing multi-factor authentication on a core platform, opens Snowflake and its clients to potential civil litigation and regulatory scrutiny over security practices. The final sentence on October 27 will close one chapter, but the saga of responsibility for one of the cloud's largest-ever data heists is far from over.

The Bottom Line

  • The case highlights critical security vulnerabilities in cloud systems lacking multi-factor authentication, endangering vast amounts of sensitive data.
  • The successful extradition and guilty plea signal stronger international legal collaboration against cybercriminals, setting a precedent for future cases.
  • Organizations handling customer data are now under increased scrutiny to implement stronger security measures to prevent similar large-scale breaches.

UNC5537's Snowflake Hacking Impact

Organizations Hacked
$165
People Affected
$100,000,000
Ransom Revenue
$2,500,000
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

A cybersecurity professional monitors data systems in a dark room, emphasizing protection and vigilance.Cybersecurity

Canadian Hacker’s Snowflake Heist Nets $2.5 Million Ransom

A hacker's guilty plea for the Snowflake data breach reveals a $2.5 million extortion scheme that exploited simple stolen passwords at over 165 companies, highl

Aug 8, 20268 min
Halted dairy production line with cyber locks and code suggesting ransomware disruption.Cybersecurity

Fairlife Ransomware Attack Freezes Coca-Cola Dairy Lines

A ransomware attack halted Fairlife's US production, turning Coca-Cola's cyber incident into an investor-visible operations risk.

Jul 17, 20267 min
Stopped dairy factory line surrounded by ransomware visuals, locks, shields, and dark cybersecurity effects.Cybersecurity

Fairlife Ransomware Attack Freezes US Dairy Production

A ransomware attack forced Coca-Cola to halt Fairlife's U.S. dairy production, with no restart date and Canada spared so far.

Jul 16, 20265 min
Secure AI gateway controlling enterprise agents, model access, and data flows in a dark cybersecurity settingCybersecurity

Runaway AI Agents Face Snowflake Cortex AI Gateway

Snowflake wants Cortex AI Gateway to rein in agent access and model spend before pilots turn into costly enterprise sprawl.

Aug 2, 20268 min
Cyberattack imagery over U.S. water and energy infrastructure with shields, locks, and data streams.Cybersecurity

Iran-Linked Hackers Breach U.S. Water, Energy Controls

U.S. agencies say Iran-linked hackers are breaching exposed utility controls, turning water and energy networks into pressure points.

Jul 23, 20267 min
Close-up of a vintage globe focusing on Canada and the USA with a warm tone.Global Trends

Canada Mocks Trump's Conspiracy Rhetoric Amid Trade War

PM Mark Carney publicly ridiculed Trump's conspiracy claims, marking a sharp diplomatic break as a serious trade cold war escalates between the US and Canada.

Aug 9, 20265 min
Detailed political map showing Europe and Asia with countries and capitals.Global Trends

Saudi Arabia Hedges US Security in Mutual Defense Pact

Saudi Arabia signed a new defense pact with Turkey and Pakistan, a strategic hedge that reveals Riyadh's fading faith in unconditional US protection.

Aug 8, 20265 min
Female engineer working on laptop reviewing technical engineering presentation.Technology

Amazon's Gas Plant Permits 33 Million Tons of CO2

Amazon's planned Texas data center, powered by a dedicated natural gas plant, has a permit to emit 33 million tons of CO2 annually, potentially making it the la

Aug 8, 20267 min
Abstract 3D render of blue and pink digital blocks. Perfect for technology-themed content.Technology

Google Blogger Seizes Hundreds of Legitimate User Websites

Google's automated malware scanner wrongly locked hundreds of Blogger sites, threatening permanent deletion and exposing creators' total dependence on unchecked

Aug 9, 20266 min
A close-up of a toy boat on a wooden map with a compass, representing travel and navigation.Global Trends

Ebola River Ship Quarantined After Five Mysterious Deaths

A major river ferry in the DRC has been quarantined with 255 people on board after five deaths, as authorities desperately screen for Ebola to prevent the virus

Aug 9, 20265 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.