Canadian Hacker Pleads Guilty in Snowflake Attack That Stole Data from 165+ Organizations
Connor Riley Moucka, a 26-year-old Canadian national, has pleaded guilty in U.S. federal court for his role in a large-scale cyberattack targeting customer accounts of Snowflake, impacting more than 165 organizations and leading to the theft of massive volumes of sensitive customer data. The stolen data was later used for extortion and sold on underground cybercrime markets.
The U.S. Department of Justice (DOJ) announced on August 5, 2026, that Moucka admitted to participating in a widespread cyber intrusion campaign that affected over 100 million individuals and caused an estimated $9.5 million in damages to victim organizations.
How the Snowflake Attack Happened
The attack took place in 2024, when Moucka and his associates used stolen credentials to access Snowflake customer accounts. Once inside, they systematically explored internal environments and exfiltrated several terabytes of data.
The stolen information included highly sensitive datasets such as:
- Call records and message history
- Banking and financial information
- Salary and payroll data
- Driver’s license numbers
- Passport numbers
- Social Security numbers
- Personally Identifiable Information (PII)
- Customer and business operational data
According to the DOJ, the attackers compromised data belonging to more than 100 million individuals, with the total dataset reaching billions of records.
Extortion and Dark Web Sales
Rather than deploying traditional ransomware encryption, the attackers used a data extortion model. Victims were threatened with public exposure or sale of stolen data unless ransom payments were made.
The stolen datasets were also advertised and sold through cybercrime forums and channels, including platforms such as BreachForums, Exploit.in, XSS.is, and Telegram-based marketplaces.
As a result of the operation, the group reportedly collected more than $2.5 million in ransom payments, while Moucka personally received at least $495,000 from extortion and data sales.
Impact on Major Global Organizations
One of the most notable aspects of the incident is the scale of affected organizations—over 165 companies across multiple industries. Several high-profile victims were publicly identified in connection with the campaign, including:
AT&T, Ticketmaster, Santander, Advance Auto Parts, LendingTree, Neiman Marcus, Pure Storage, and Bausch Health
The incident highlights how a single compromised credential can escalate into a large-scale data breach when used to access cloud environments with broad permissions.
Key Insight: Cloud Attacks Don’t Always Start with Cloud Vulnerabilities
The Snowflake incident serves as a critical case study for modern cybersecurity. The root cause was not a cloud infrastructure flaw, but a failure in Identity and Credential Security.
Attackers leveraged stolen credentials to gain legitimate access to victim environments. Once inside, they were able to move laterally and extract large volumes of sensitive data due to excessive access privileges.
This reinforces a key principle: Cloud security is not limited to infrastructure protection. It must also include identity management, authentication controls, access governance, and behavioral monitoring.
5 Cybersecurity Lessons for Organizations
- Enforce Multi-Factor Authentication (MFA)
Passwords alone are no longer sufficient to protect sensitive systems.
Organizations should enforce MFA across all critical accounts, especially administrator and privileged users with access to cloud environments and sensitive data.
- Continuously Monitor for Stolen Credentials
Credentials are frequently stolen through infostealer malware and reused in cloud attacks.
Organizations must implement continuous monitoring for exposed credentials and establish rapid reset or revocation processes when compromise is suspected.
- Apply the Principle of Least Privilege
Users should only have access to the data and systems required for their roles.
Limiting permissions significantly reduces the blast radius in the event of account compromise.
- Detect Abnormal Cloud Activity
Unusual login locations, large-scale data downloads, or access patterns inconsistent with normal behavior may indicate account takeover.
Organizations should deploy monitoring and detection systems capable of analyzing cloud activity in real time.
- Prepare Incident and Breach Response Plans
When data is exfiltrated, rapid response is critical.
Organizations must be able to immediately disable compromised accounts, revoke sessions and credentials, and assess what data was accessed or stolen.
A well-tested Incident Response Plan can significantly reduce both damage and attacker dwell time.
BigFishTec Insight: Identity Is the New Security Perimeter
The Snowflake breach demonstrates that protecting cloud environments cannot rely solely on infrastructure security.
Modern cybersecurity must be built around an integrated model:
Identity → Authentication → Endpoint → Cloud → Data → Detection & Response
As organizations increasingly adopt cloud and SaaS platforms, employee credentials have become one of the most targeted attack vectors for cybercriminals.
Implementing MFA, enforcing Least Privilege, monitoring credential exposure, and deploying threat detection and response systems are essential to reducing the risk of account takeover and large-scale data breaches.
The case of Connor Moucka illustrates how a cyberattack that begins with stolen credentials can escalate into a massive cloud data breach affecting hundreds of millions of individuals.
For organizations, the key takeaway is clear: “Cloud security starts with identity security.”
Without strong identity protection and real-time detection capabilities, even the most advanced cloud infrastructure can be compromised through a single stolen credential.