Connor Riley Moucka, a 26-year-old Canadian from Kitchener, Ontario, pleaded guilty this week in Seattle federal court to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy over the 2024 intrusions into Snowflake customer accounts. The campaign reached at least 165 organizations and exposed the records of more than 100 million people, with victim losses exceeding $9.5 million.
How Stale Credentials Drove the Snowflake Account Intrusions
The break-ins were built on credentials, not an exploit. Passwords had been harvested years earlier by infostealer malware — some dating back to 2020 — and were never rotated, while MFA was switched off on the accounts. Mandiant, tracking the actor as UNC5537, found that at least 79.7% of the accounts used had prior credential exposure and that compromised instances had no network allow lists. There was no platform flaw behind the campaign, and Snowflake itself was not breached. The intrusions relied on the cumulative failure of credential hygiene across dozens of customer tenants, which made an otherwise protected data platform reachable through ordinary stolen passwords.
The Scale of the Damage and the Data at Risk
Moucka, also known as Alexander Moucka and “Waifu,” and co-defendant John Erin Binns obtained at least $2.5 million in bitcoin from at least three victims, with Moucka personally taking at least $495,000 from ransoms and data sales. The stolen material included non-content call and text history, banking and financial information, payroll records, DEA registration numbers, and identity documents such as driver’s licenses, passports, and Social Security numbers, spread across victims including AT&T, Ticketmaster, Santander, Pure Storage, Advance Auto Parts, and the Los Angeles Unified School District.
Re-Extortion of Victims Using Officials’ Family Data
Federal prosecutors described the pressure tactics as calculated. Moucka re-extorted at least one victim, threatening further disclosure of stolen data belonging to a government officer and to members of a then-former government officer’s immediate family, conduct the FBI’s special agent in charge called “calculated and predatory.”
The Criminal Case and What Remains Pending
Moucka faces a two-year mandatory minimum on the identity-theft count and up to 30 years on the remaining charges, with sentencing scheduled for October 27. His co-defendant Binns remains outside U.S. custody, and Cameron John Wagenius, a former Army soldier tied to the intrusions, pleaded guilty in a related case last year. The scale of the affected population was driven by a handful of outsized tenants, most visibly AT&T, which confirmed that call and text records of nearly all of its cellular customers had been taken — a single element of a campaign that by the Department of Justice’s accounting affected more than 100 million individuals.
Snowflake’s Response and the Push to Phase Out Password-Only Sign-Ins
Snowflake has enforced MFA-by-default for human users on accounts created since last fall and requires passwords of at least 14 characters, and it plans to block password-only sign-ins entirely in a final phase running through this year. The remediation has focused on removing the exact failure that made the campaign possible.
What the Snowflake Plea Says About Cloud Credential Hygiene
The case stands as one of the largest cloud-data theft campaigns by scale, and it ran on the most mundane of failures: credentials that should have been rotated and MFA that should have been on. For cloud tenants, the data store is only as protected as the identities that can reach it, and infostealer-collected passwords stay dangerous until accounts are re-seeded and second factors enforced.
Credential lifetime is a security decision, not an administrative one: the attacker’s economics favor stale identities, so account-level controls — rotation cadence, MFA enforcement, and network restrictions — set the effective boundary for platform security, and a breach’s magnitude depends less on the vendor’s infrastructure than on the weakest tenant identity it serves. The pending October sentencing and the separate Wagenius case keep the accountability pipeline running.