Connor Riley Moucka stole data on roughly 100 million people and earned his syndicate over $2.5 million in ransom payments from companies like AT&T and Ticketmaster. Now the 26-year-old Canadian has pleaded guilty in a U.S. federal court, admitting to a hacking spree that stands as one of 2024's most significant cloud compromises according to SecurityWeek. He faces over 30 years in prison.

Snowflake Hacker Admits $2.5M Ransom Plot
XOOMAR Intelligence
Analyst Take
Moucka, extradited from Canada in July 2025 following his late 2024 arrest, pleaded guilty on August 5 to charges of computer fraud, wire fraud, aggravated identity theft, and a related conspiracy. Court documents confirm his central role in a campaign by the threat group UNC5537, which hacked into the Snowflake accounts of at least 165 organizations between February and October 2024.
A $2.5 Million Ransom Heist Fueled by Stolen Passwords
The attackers’ method was simple but devastatingly effective. Moucka and his co-conspirators used stolen login credentials to breach Snowflake customer accounts that lacked mandatory multi-factor authentication. This was not a sophisticated software exploit but a brute-force credential attack.
“Hiding behind a screen is no shield from justice,” said Assistant Director Brett Leatherman of the FBI’s Cyber Division. “Moucka learned that when he was arrested just months after he began targeting U.S. companies.”
Once inside, they exfiltrated billions of sensitive records and terabytes of data. The haul included customer call records from AT&T, payroll data, Social Security numbers, driver's license details, and even Drug Enforcement Administration registration numbers.
The group's business model was extortion: threaten to publish the data unless paid. The U.S. Department of Justice stated the conspirators received over $2.5 million in ransom payments. Moucka personally profited by selling stolen data on cybercrime forums like BreachForums and Telegram, netting at least $495,000. In one egregious act, he re-extorted a victim using stolen personal data of a government officer and their family. This aligns with our previous coverage of the Canadian Hacker’s Snowflake Heist Nets $2.5 Million Ransom.
Victims included a who’s who of corporate America:
- AT&T (over 100 million customer call records)
- Ticketmaster
- Santander Bank
- Advance Auto Parts
- Neiman Marcus
- Anheuser-Busch
- State Farm and Progressive
The DOJ pegged direct losses to these companies at over $9.5 million, a figure that excludes the incalculable costs for the at least 100 million individuals whose data was stolen.
The Co-Conspirator Network and a Notorious Online Persona
Moucka, who operated under aliases including “Judische” and “Waifu,” did not act alone. His guilty plea sheds light on a network of alleged accomplices.
- Cameron “Kiberphant0m” Wagenius: A U.S. Army soldier who pleaded guilty last year to extorting AT&T and Verizon. Prosecutors consider him a co-conspirator in the Snowflake campaign. He is scheduled for sentencing in September 2026.
- John Erin Binns (aka “IRDev”): Indicted for the massive 2021 T-Mobile breach, Binns is named as the third alleged conspirator. Sources indicate he recently obtained Turkish citizenship, complicating any potential U.S. extradition.
Researchers link these individuals to The Com, a sprawling online criminal network known for harassment, sextortion, and data theft. Moucka’s online behavior was brazen and erratic. Security researcher Allison Nixon of Unit 221B noted, “His behavior was bizarre throughout. Even while stealing data and extorting victims, he did many unnecessary things like threatening me because he thought I was working on his case.”
Nixon argues Moucka’s legacy is one of “failure” that poisoned the well for other extortionists. “He extorted and then scammed his victims by not deleting the data, casting doubt on all future pay-or-leak extortion gangs,” she told CyberScoop.
From Guilty Plea to a Decades-Long Prison Term
With the guilty plea entered, the focus shifts to sentencing and precedent. Moucka is scheduled to be sentenced on October 27. He faces a mandatory minimum of two years for aggravated identity theft and a statutory maximum of 30 years for the other charges, meaning he could potentially serve over three decades behind bars.
XOOMAR Analysis: The judge's final sentence will hinge on several factors.
- Cooperation: Has Moucka provided substantial information on his co-conspirators or other operations to prosecutors?
- Restitution: While the victim companies lost over $9.5 million, the court may consider his personal gain ($495k) versus the syndicate's total haul ($2.5M+) when ordering repayment.
- Nature of the Crime: The scale, the re-extortion using a government official's family data, and the harassment of investigators are severe aggravating factors that will weigh against leniency.
This case is a stark marker for cross-border cyber enforcement. Moucka was arrested in Canada within months of the attacks and extradited within a year, a relatively swift timeline for international cybercrime cases. It signals that high-impact, financially motivated attacks against U.S. corporations will trigger rapid, coordinated international law enforcement action.
For affected companies, the legal fallout is likely just beginning. While Moucka's prosecution addresses the criminal act, the breach’s root cause, customers not enforcing multi-factor authentication on a core platform, opens Snowflake and its clients to potential civil litigation and regulatory scrutiny over security practices. The final sentence on October 27 will close one chapter, but the saga of responsibility for one of the cloud's largest-ever data heists is far from over.
The Bottom Line
- The case highlights critical security vulnerabilities in cloud systems lacking multi-factor authentication, endangering vast amounts of sensitive data.
- The successful extradition and guilty plea signal stronger international legal collaboration against cybercriminals, setting a precedent for future cases.
- Organizations handling customer data are now under increased scrutiny to implement stronger security measures to prevent similar large-scale breaches.
UNC5537's Snowflake Hacking Impact
Sources
Written by
XOOMAR Insights Team
Research and Editorial Desk
The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.
Explore More Topics
Related Articles
CybersecurityCanadian Hacker’s Snowflake Heist Nets $2.5 Million Ransom
A hacker's guilty plea for the Snowflake data breach reveals a $2.5 million extortion scheme that exploited simple stolen passwords at over 165 companies, highl
CybersecurityFairlife Ransomware Attack Freezes Coca-Cola Dairy Lines
A ransomware attack halted Fairlife's US production, turning Coca-Cola's cyber incident into an investor-visible operations risk.
CybersecurityFairlife Ransomware Attack Freezes US Dairy Production
A ransomware attack forced Coca-Cola to halt Fairlife's U.S. dairy production, with no restart date and Canada spared so far.
CybersecurityRunaway AI Agents Face Snowflake Cortex AI Gateway
Snowflake wants Cortex AI Gateway to rein in agent access and model spend before pilots turn into costly enterprise sprawl.
CybersecurityIran-Linked Hackers Breach U.S. Water, Energy Controls
U.S. agencies say Iran-linked hackers are breaching exposed utility controls, turning water and energy networks into pressure points.
Global TrendsCanada Mocks Trump's Conspiracy Rhetoric Amid Trade War
PM Mark Carney publicly ridiculed Trump's conspiracy claims, marking a sharp diplomatic break as a serious trade cold war escalates between the US and Canada.
Global TrendsSaudi Arabia Hedges US Security in Mutual Defense Pact
Saudi Arabia signed a new defense pact with Turkey and Pakistan, a strategic hedge that reveals Riyadh's fading faith in unconditional US protection.
TechnologyAmazon's Gas Plant Permits 33 Million Tons of CO2
Amazon's planned Texas data center, powered by a dedicated natural gas plant, has a permit to emit 33 million tons of CO2 annually, potentially making it the la
TechnologyGoogle Blogger Seizes Hundreds of Legitimate User Websites
Google's automated malware scanner wrongly locked hundreds of Blogger sites, threatening permanent deletion and exposing creators' total dependence on unchecked
Global TrendsEbola River Ship Quarantined After Five Mysterious Deaths
A major river ferry in the DRC has been quarantined with 255 people on board after five deaths, as authorities desperately screen for Ebola to prevent the virus
Don't miss the signal
Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.
Free forever. No spam. Unsubscribe anytime.