A padlock and cloud representing the Snowflake data breach
The Snowflake extortion campaign breached more than 165 organizations and exposed data tied to over 100 million people.

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to a sprawling hacking and extortion conspiracy that targeted more than 165 organizations using the cloud platform Snowflake.

Connor Riley Moucka, of Kitchener, Ontario, entered the plea in Seattle federal court on Wednesday, August 5, 2026, admitting to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy. He also admitted to stealing the call and text history records of more than 100 million AT&T customers.

One of the Most Consequential Hackers of 2024

Moucka, known online under the aliases "Waifu" and "Judische", was described by Google's Mandiant as one of the most consequential threat actors of 2024. Investigators track the campaign under the moniker UNC5537. Between February and October 2024, Moucka and his co-conspirators used stolen login credentials to compromise cloud-hosted data belonging to at least 165 customers of a U.S.-based software-as-a-service provider.

Publicly identified victims included AT&T, Ticketmaster, Santander Bank, Advance Auto Parts, Neiman Marcus, LendingTree's QuoteWizard, Ticketek, Pure Storage, the Los Angeles Unified School District, and Bausch Health.

"Connor Moucka hacked over 150 companies and organizations, obtained extremely sensitive information, and extorted the victims for millions of dollars." — Assistant Attorney General A. Tysen Duva, DOJ Criminal Division

Billions of Records, Terabytes of Data

The conspirators stole billions of sensitive customer records and downloaded terabytes of information, including:

  • Non-content call and text history records (about 50 billion records from AT&T alone)
  • Banking and other financial information
  • Payroll records
  • Drug Enforcement Administration (DEA) registration numbers
  • Driver's license numbers, passport numbers, and Social Security numbers

According to prosecutors, the scheme generated more than $2.5 million in ransom payments, with Moucka personally obtaining at least $495,000 from ransoms and data sales on cybercrime forums including BreachForums, Exploit.in, and XSS.is, as well as via Telegram.

'Calculated and Predatory' Re-Extortion

Perhaps the most disturbing element of the case is that Moucka and his accomplices returned to squeeze at least one victim a second time. After a victim paid a ransom in May 2024, the conspirators returned months later demanding more money, threatening to publish or sell the stolen customer data.

"Moucka used the stolen data of a government officer and members of a then-former government officer's immediate family in this re-extortion attempt," the Justice Department said. Moucka also threatened and harassed government officials and security researchers who were helping track him down.

FBI Special Agent in Charge W. Mike Herrington called Moucka's tactics "calculated and predatory," noting the real harm done to both targeted companies and "the millions of everyday people who are their customers."

Cybercrime and dark web hacking concept
Stolen data was advertised for sale on BreachForums, Exploit.in and XSS.is, and via Telegram.

Not Sophisticated — Just Negligent Credentials

Perhaps the most important lesson from the Snowflake campaign is that it did not rely on novel or sophisticated hacking techniques. Mandiant found that every incident it investigated traced back to customer credentials stolen by infostealer malware. Some had been harvested as far back as November 2020 and were still valid years later.

The campaign, Mandiant wrote, "is not the result of any particularly novel or sophisticated tool, technique, or procedure." It succeeded because of the size of the infostealer market and credentials left unrotated for as long as four years. Crucially, many Snowflake customer accounts did not enforce multi-factor authentication (MFA).

Snowflake responded by increasing password-complexity requirements and enforcing MFA. At least 79.7% of the accounts the group used had prior credential exposure, and compromised instances had no network allow lists.

The Co-Conspirators

Moucka was not alone. One admitted co-conspirator is Cameron "Kiberphant0m" Wagenius, a U.S. Army soldier who pleaded guilty in July 2025 to extorting AT&T and Verizon for customer account data. He is set to be sentenced on September 3, 2026.

The third alleged co-conspirator is John Erin Binns, 26, an elusive American indicted for his admitted role in a 2021 T-Mobile breach that exposed the personal information of at least 76 million customers. Binns has reportedly resurfaced online and obtained Turkish citizenship, under which he may not be extraditable.

Arrest, Extradition and Sentencing

Canadian law enforcement, acting on a U.S. arrest warrant, arrested Moucka in Ontario in November 2024 — just months after the breaches began. He agreed to be extradited to the United States, and appeared in Seattle federal court in July 2025.

Moucka pleaded guilty to four counts and is scheduled to be sentenced on October 27, 2026. He faces a mandatory minimum of two years on the aggravated identity-theft count and a maximum of 30 years in prison on the remaining counts. He has agreed to forfeit the money he made, and could be ordered to pay restitution for victim incident-response and ransom costs that totaled at least $9.5 million.

What this means for you: The Snowflake case is a stark reminder that many of the largest data breaches begin not with exotic exploits, but with stolen or reused credentials. Enable multi-factor authentication on every account that supports it, use a password manager to avoid reusing passwords, rotate credentials regularly, and restrict access with network allow lists. VUNVAULT offers penetration testing and cloud security assessments to help identify and close these gaps before attackers do.