prison door
Image: Syarafina Yusof via Unsplash

Canadian man pleads guilty to Snowflake hacks that led to 165 breaches

A Canadian national is facing decades in prison for participating in the hacking of data storage platform Snowflake. 

Connor Riley Moucka, 26, pleaded guilty to computer fraud, wire fraud, aggravated identity theft and a related conspiracy on Wednesday in a Washington state federal court. He will be sentenced on October 27 and is facing up to 32 years in prison.

Moucka and others used stolen login credentials to breach Snowflake and steal troves of information from at least 165 companies. 

The hackers stole billions of files from large companies including AT&T, Ticketmaster, Advance Auto Parts, one of the largest school districts in the U.S., Neiman Marcus, Santander, LendingTree and more.

The AT&T breach involved the logs of calls and texts to more than 100 million customers. The Ticketmaster breach involved about 560 million users

Moucka, from Kitchener, Ontario, was eventually arrested in November 2024 and extradited to the U.S. in July 2025. 

Prosecutors said Moucka and his co-conspirators breached Snowflake between February and October 2024 — allowing them to steal banking records, financial information, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, Social Security numbers and more. 

The hackers then attempted to extort victim companies with threats of publishing the stolen information online. The crew earned about $2.5 million in ransom payments, and court documents showed Moucka extorted at least one victim a second time. 

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” prosecutors said. 

Moucka earned another $495,000 by advertising some of the stolen data on cybercriminal forums like BreachForums and XSS.is. Court documents said victim companies suffered about $9.5 million in losses related to the breaches. 

“Connor Moucka’s threats and re-extortion tactics were calculated and predatory, and his actions did real harm to his victims, be they companies targeted for theft and extortion or the millions of everyday people who are their customers,” said FBI Special Agent in Charge W. Mike Herrington.

After the breaches came to light, Snowflake hired Google’s Mandiant unit to investigate the incident and confirmed that there was no issue with the platform’s security. The hackers, according to Mandiant, stole still-valid credentials dating back to 2020 and were able to access company accounts through those login details.

Mandiant said at the time that the hackers behind the campaign are “based in North America, and collaborates with an additional member in Turkey.” 

At least one of the alleged Turkey-based hackers, John Erin Binns, was detained by Turkish authorities in 2024 after being indicted for his role in a previous hack of telecom T-Mobile.

Before his arrest, Moucka allegedly spoke to news outlet 404Media, telling them that he expected to be arrested and had been destroying evidence in advance of his detainment.

Get more insights with the
Recorded Future
Intelligence Cloud.
Learn more.
Recorded Future
No previous article
No new articles
Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.