Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driver’s license numbers, and DEA registration numbers.
Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflake’s SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Connor Riley Moucka pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and related conspiracy charges tied to the Snowflake-linked hacking and extortion campaign. The Justice Department announced the plea on August 5, 2026.
After agreeing to surrender for extradition, Moucka arrived in the Western District of Washington and made his first U.S. court appearance. The Justice Department-linked reporting dates that appearance to July 3, 2025.
Cameron John Wagenius, a former Army soldier tied by prosecutors to the same Snowflake-linked intrusions, pleaded guilty in a related case. The reference dates that plea to July 2025.
According to prosecutors, Moucka and co-conspirators used stolen login credentials to access cloud-hosted data and Snowflake customer accounts between February and October 2024. The campaign affected at least 165 organizations and led to theft of terabytes of sensitive data.
Mandiant said the earliest infostealer infection associated with a credential later used in the Snowflake customer compromise campaign dated to November 2020. It also reported that hundreds of Snowflake credentials had been exposed via infostealers since 2020.
Authorities arrested Connor Riley Moucka in Canada in late 2024 in connection with the cloud hacking and extortion campaign. One source places the arrest in October 2024, while another reports it in November 2024.
Mandiant reported that UNC5537 primarily relied on previously exposed Snowflake credentials stolen by infostealer malware, with at least 79.7% of accounts used in the campaign showing prior credential exposure. It also described attacker tradecraft including use of SnowSight, SnowSQL, FROSTBITE, and DBeaver Ultimate for access and reconnaissance.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
20 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcecio.com
Open sourcecio.com
Open sourcemalware.news
Open sourcetherecord.media
Open sourcedarkwebinformer.com
Open sourcejustice.gov
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.