Snowflake Hacker Connor Moucka Pleads Guilty to Breaches Hitting 165 Organizations

Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty in Seattle federal court to the 2024 Snowflake customer-account breaches — at least 165 organizations and more than 100 million people exposed. He is set for sentencing on October 27.

Share
Courtroom scene representing the guilty plea of Snowflake hacker Connor Moucka, with a single red dot marking the case.

Connor Riley Moucka, the 26-year-old Canadian at the center of the 2024 Snowflake customer breaches, pleaded guilty in Seattle federal court on Wednesday to a hacking and extortion conspiracy that prosecutors say reached more than 165 organizations and exposed the personal records of at least 100 million people. Moucka, of Kitchener, Ontario, admitted to four felony counts — computer fraud, wire fraud, aggravated identity theft, and a related conspiracy — closing the U.S. criminal case against one of the men most closely tied to a campaign that ran through the account data of some of the largest companies in North America.

The plea, entered August 5 in the Western District of Washington and announced by the U.S. Department of Justice, is the clearest official accounting yet of a spree that unfolded across 2024. Between February and October that year, according to court documents, Moucka and his co-conspirators used stolen login credentials to break into cloud-hosted data belonging to at least 165 customers of a U.S. software-as-a-service company — the data-warehouse platform that reporting from The Hacker News, The Record, and CyberScoop identifies as Snowflake. The group stole billions of records, extorted victims for a combined total of more than $2.5 million, and, prosecutors say, netted Moucka at least $495,000 personally.

A Breach of Snowflake's Customers, Not Snowflake

One detail is worth stating plainly, because it is easy to get wrong: this was not a compromise of Snowflake's own infrastructure. The intruders did not crack the platform. They logged in. The accounts they reached belonged to Snowflake customers that had left multi-factor authentication switched off and were still relying on passwords that had, in many cases, been harvested years earlier by infostealer malware and never rotated. With a valid username and password and no second factor to stop them, the attackers moved through one customer environment after another. Snowflake itself was not charged with any wrongdoing; its customers' configuration choices are what turned stale credentials into a hundred-million-person data exposure.

What Moucka Admitted To

The data pulled from those accounts was not limited to marketing lists. Court documents describe the theft of non-content call and text records, banking and financial information, payroll records, Drug Enforcement Administration registration numbers, driver's license and passport numbers, and Social Security numbers. After stealing the data, Moucka and his co-conspirators threatened to publish it unless victims paid, advertised stolen datasets for sale on cybercrime forums including BreachForums, Exploit.in, and XSS.is, and marketed them on Telegram. In at least one instance, prosecutors say, Moucka re-extorted a victim — going back for a second payment — using the stolen data of a government officer and members of a former government officer's immediate family to apply pressure.

"Connor Moucka hacked over 150 companies and organizations, obtained extremely sensitive information, and extorted the victims for millions of dollars," said Assistant Attorney General A. Tysen Duva of the Justice Department's Criminal Division, adding that Moucka "was arrested just six months after these breaches began." Moucka was taken into custody in Canada and extradited to the United States in July 2025.

Case at a Glance
United States v. Connor Riley Moucka — Western District of Washington
The Plea
Guilty on four counts: computer fraud, wire fraud, aggravated identity theft, and a related conspiracy. Entered Aug. 5, 2026.
The Defendant
Connor Riley Moucka, 26, of Kitchener, Ontario. Extradited from Canada in July 2025.
The Access
Stolen credentials used against Snowflake customer accounts, February–October 2024. Not a breach of Snowflake's own platform.
The Scale
165+ victim organizations. Records of 100M+ people exposed. Billions of records stolen; terabytes downloaded.
The Money
$2.5M+ in ransom to the group; at least $495,000 personally to Moucka; $9.5M+ in company losses.
The Exposure
Up to 32 years: a two-year mandatory minimum plus up to 30 years. A statutory maximum, not a guaranteed sentence. Sentencing set for Oct. 27, 2026.
Source: U.S. Department of Justice, Aug. 5, 2026 (Press Release 26-891).

The Sentence He Faces, and the 32-Year Figure

Coverage has framed Moucka's exposure as up to 32 years, and that number is worth handling carefully. It is a statutory maximum, not a sentence. The aggravated identity theft count carries a mandatory minimum of two years; the remaining counts carry a combined maximum of up to 30 years. Stacked, that is the "up to 32 years" figure CyberScoop and others have cited. What Moucka actually receives will be decided by a federal judge weighing the U.S. Sentencing Guidelines and other statutory factors. Sentencing is scheduled for October 27, 2026 — a date that had not been set when the first accounts of the plea circulated and is now on the court's calendar.

Which Organizations Were Hit

The Justice Department has not released the full roster of 165 victim organizations, and much of it remains unconfirmed. Several names, though, have been public since the 2024 disclosures and appear again in this week's reporting: AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, along with what The Record describes as one of the largest school districts in the United States. Any list beyond those confirmed names is speculation, and unverified victim rosters should be treated with skepticism.

My Read

The prosecution's headline number — 165 organizations — is the part defenders should sit with. Not because it is large, but because every one of those breaches reportedly turned on the same two failures: a password that should have been dead, and an account that should have required a second factor. There was no zero-day here, no novel exploit chain. The 2024 Snowflake wave has become the reference case for identity-based cloud attacks precisely because it is so unremarkable technically. This plea also fits a wider run of accountability in the same broader cybercrime ecosystem — from Scattered Spider members entering guilty pleas in the U.K. to the extortion cases we have tracked across Snowflake's customer base — but a conviction changes nothing about the exposure that made the intrusions possible. The credentials that opened those 165 doors still sit in infostealer logs, and the configuration gaps that ignored them are still the default in more environments than anyone would like to admit.

What Snowflake Customers Should Still Verify

For any organization that ran a Snowflake environment in 2024 — or runs one now — this plea is a prompt to confirm three things rather than assume them:

  • MFA is enforced, not merely available. Confirm that multi-factor authentication is required on every account, including service and machine accounts, with no exceptions grandfathered in.
  • Historical access logs from the 2024 window have been reviewed. Audit authentication and query logs from February–October 2024 for access from unfamiliar locations or credentials, even where no alert fired at the time.
  • Credentials valid in that period have been rotated. Any password or key that was live during the exposure window should be treated as potentially compromised and rotated, especially for accounts that predate an MFA mandate.

The framing here is verification, not accusation. The point is to rule out lingering exposure, not to relitigate an old incident.

Primary Documents