Connor Riley Moucka, a 26-year-old from Kitchener, Ontario, entered a guilty plea in a Seattle federal court on Wednesday. The charges against him include computer fraud, wire fraud, aggravated identity theft, and conspiracy. These charges stem from his involvement in the 2024 breaches of customer accounts belonging to the U.S. software-as-a-service provider Snowflake.
The breaches affected at least 165 organizations and compromised data of over 100 million individuals. Moucka reportedly gained at least $495,000 through ransoms and data sales. His sentencing is scheduled for October 27, where he faces a mandatory minimum of two years for identity theft and up to 30 years for the other charges.
Details of the Cyber Intrusion
The cyber attackers exploited old credentials that had been collected by infostealer malware and never updated. Additionally, the compromised accounts had multi-factor authentication (MFA) turned off, allowing easy access despite the absence of any platform vulnerabilities. The Justice Department did not name the victim company in its announcements, but Snowflake and Mandiant identified themselves in 2024.
Beyond the initial breach, Moucka was involved in re-extorting at least one victim by threatening further data exposure. The FBI’s Seattle field office special agent, W. Mike Herrington, described these actions as “calculated and predatory.”
Investigation Insights
The cybersecurity firm Mandiant, in collaboration with Snowflake, discovered that all incidents involved customer credentials previously stolen by infostealer malware. These credentials, some dating back to November 2020, were still active. A significant 79.7% of the compromised accounts had a history of credential exposure, and the affected systems lacked network allow lists.
Mandiant emphasizes that these breaches did not involve any new or sophisticated cyber tools or techniques. Instead, the widespread impact was attributed to the neglected rotation of credentials and the vast infostealer market.
Impact and Future Measures
The breaches resulted in more than $9.5 million in losses for the affected companies, excluding their customers’ losses. Compromised data included sensitive information such as call and text history, payroll records, DEA numbers, and Social Security numbers. AT&T confirmed in 2024 that call and text records for nearly all its cellular customers were accessed via a third-party cloud platform.
Following the breaches, Snowflake has implemented MFA by default for all new human user accounts since October 2024. However, password-only logins have not been entirely phased out. The final phase of eliminating password-only access is planned between August and October 2026, with exceptions for reader and trial accounts.
While Moucka is in U.S. custody, his accomplices, including John Erin Binns, remain at large. Another individual, Cameron John Wagenius, pleaded guilty in a related case in July 2025. These developments underscore the ongoing challenges in cybersecurity and the importance of robust authentication measures.
