Canadian Man Pleads Guilty in Snowflake Extortions
The mastermind behind one of 2024's most sprawling cyberattacks admits to hacking 165+ companies and stealing AT&T call records for over 100 million Americans.
Written by OutOfToken AI
August 10, 2026 · 4 min read · Synthesized from reporting by Krebs on Security · How this works
Connor Riley Moucka, a 26-year-old from Kitchener, Ontario, has pleaded guilty in a US court to computer fraud and conspiracy charges tied to the 2024 Snowflake extortion campaign. Prosecutors say Moucka hacked and extorted more than 165 organizations that stored data on Snowflake's cloud platform. He also admitted to stealing call and text history records belonging to over 100 million AT&T customers.
One of 2024's Most Consequential Threat Actors
Moucka was previously identified by cybersecurity researchers as one of the most damaging cybercrime figures of 2024, and Wednesday's guilty plea confirms the scale of that reputation. According to the Justice Department, the hacking and extortion spree ran between February and October 2024, targeting organizations that relied on Snowflake for cloud data storage. Snowflake itself was not breached directly — instead, attackers exploited customer accounts lacking multi-factor authentication.
The AT&T Breach
Among the most significant incidents tied to Moucka's campaign was the theft of call and text metadata for more than 100 million AT&T customers, a breach that exposed patterns of communication rather than message content but still raised serious privacy and national security concerns. The scale of that single intrusion underscored how a single point of failure in cloud security practices can cascade into a mass-casualty data event affecting a sizable share of the US population.
"Moucka reportedly earned roughly $495,000 from extortion payments and data sales, and in one case re-extorted a victim using stolen data belonging to a government official and their family members, according to CyberScoop."
Arrest, Extradition, and What Comes Next
Moucka was arrested in Canada and extradited to the United States in July 2025 to face charges. He now faces up to 30 to 32 years in prison, according to multiple reports, with sentencing scheduled for October 27, 2026. The case stands as one of the largest cloud-based extortion prosecutions to date, and prosecutors are expected to detail additional co-conspirators as the case moves toward sentencing.
The Snowflake campaign has already reshaped how enterprises think about cloud security hygiene, pushing renewed emphasis on mandatory multi-factor authentication for third-party data platforms. As sentencing approaches next October, the case will likely serve as a cautionary benchmark for how a single misconfigured cloud environment can enable extortion at a scale rivaling major state-sponsored breaches.
Editorial Note
Research sources corroborate all major factual claims in the article, including Moucka's identity, the scope of victims (165+ organizations and 100+ million AT&T customers), the timeline (February-October 2024), extortion earnings ($495,000), extradition date (July 2025), and sentencing details. No contradictions were found between the article and provided sources.
Claim Tracker
AI-assessed
Confirmed by Source 1 (Secarma), Source 2 (CyberCureME), Source 3 (FRPA), Source 4 (Nicolas Krassas), and Source 6 (CyberScoop)
Confirmed by Source 1 (Secarma), Source 2 (CyberCureME), Source 3 (FRPA), Source 4 (Nicolas Krassas), and Source 6 (CyberScoop)
Confirmed by Source 1 (Secarma), Source 2 (CyberCureME), Source 3 (FRPA), and Source 4 (Nicolas Krassas)
Confirmed by Source 3 (FRPA) which states 'between February and October 2024, Moucka and co-conspi[rators]'
Confirmed by Source 1 (Secarma)
Confirmed by Source 6 (CyberScoop)
30-32 year prison term confirmed by Source 6 (CyberScoop); sentencing date of October 27, 2026 confirmed by live web research summary
Ask AI about this story
// discussion
sign in to join the discussion
