News.Bloomberglaw Canadian Hacker Pleads Guilty in Massive Snowflake Data Breach and Extortion Case
Article Content
- •Connor Moucka pleaded guilty to hacking and extortion involving over 165 organizations.
- •The breach exploited accounts lacking multi-factor authentication, leading to massive data theft.
- •Victims suffered over $9.5 million in losses, affecting around 100 million individuals.
Connor Riley Moucka, a 26-year-old from Kitchener, Ontario, pleaded guilty to a hacking conspiracy that compromised over 165 organizations using Snowflake's cloud services. The attacks occurred between February and October 2024, exploiting accounts without multi-factor authentication (MFA) to steal billions of sensitive records. Moucka and his co-conspirators extorted victims for more than $2.5 million, threatening to publish stolen data online. The breach affected major companies, including AT&T and Ticketmaster, impacting an estimated 100 million individuals. Moucka faces a minimum of two years and a maximum of 32 years in prison, with sentencing scheduled for October 27, 2026. Snowflake has since mandated MFA for all customer accounts to enhance security.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (20)
Following this threat?
Track 23andMe in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…