Key Takeaways
- Connor Riley Moucka pleaded guilty in a Seattle federal court to computer fraud, wire fraud, aggravated identity theft and conspiracy related to the 2024 Snowflake‑customer breaches.
- The intrusions compromised at least 165 organizations and exposed data from roughly 100 million individuals, with Moucka personally profiting about $495,000 from ransom payments and data sales.
- Attackers gained access using old, unrotated passwords harvested years earlier by infostealer malware; the compromised accounts had multi‑factor authentication disabled and no network allow‑lists.
- No software flaw or exploit was involved—the breach stemmed entirely from credential hygiene failures.
- Mandiant and Snowflake traced every incident to credentials stolen by infostealers, some as old as November 2020, highlighting the persistence of stolen data in underground markets.
- Victim losses exceeded $9.5 million (excluding downstream customer impacts); the case also involved re‑extortion threats against a government officer and family members.
- Snowflake has begun enforcing MFA by default for new accounts and plans to block password‑only logins for all remaining human and service users by late 2026.
Background of the Guilty Plea
On Wednesday, August 6 2026, Connor Riley Moucka, a 26‑year‑old from Kitchener, Ontario, entered a guilty plea in Seattle federal court to charges of computer fraud, wire fraud, aggravated identity theft and a related conspiracy. The plea stems from the large‑scale 2024 breach of customer accounts hosted on a major U.S. software‑as‑a‑service (SaaS) platform later identified as Snowflake. Moucka’s admission marks a significant step in the Justice Department’s effort to hold individuals accountable for credential‑based cyber intrusions that affected hundreds of organizations and tens of millions of individuals.
Scale of the Intrusion
Prosecutors allege that the attackers accessed at least 165 organizations, exposing records belonging to roughly 100 million people. The compromised data included non‑content call and text histories, payroll records, DEA registration numbers, passport and Social Security numbers, among other sensitive information. Moucka personally profited from the scheme, collecting at least $495,000 through ransom payments and the sale of stolen data on underground markets.
Legal Consequences and Sentencing Outlook
Moucka is scheduled to be sentenced on October 27 2026. He faces a mandatory minimum of two years imprisonment on the aggravated identity theft count, with the remaining charges carrying a maximum possible sentence of up to 30 years. The case also involves co‑defendant John Erin Binns, who remains outside U.S. custody as of the court’s August 4 update, and former Army soldier Cameron John Wagenius, who pleaded guilty in a related matter in July 2025.
How the Attackers Gained Access
The intrusion did not rely on any software vulnerability or zero‑day exploit. Instead, the threat actors used credentials that had been harvested years earlier by infostealer malware and never rotated. Many of the compromised accounts had multi‑factor authentication (MFA) disabled and lacked network allow‑lists, allowing the attackers to log in simply with stolen usernames and passwords. This highlights a fundamental breach of basic credential hygiene rather than a sophisticated technical attack.
Credential Sources and Persistence
Mandiant’s investigation, conducted alongside Snowflake and tracked under the alias UNC5537, determined that every incident traced back to customer credentials stolen by infostealers. Some of these credentials were harvested as far back as November 2020 and remained valid for up to four years. Approximately 79.7 % of the accounts used by the attackers had prior exposure in credential‑dumping forums, underscoring the longevity and reuse of stolen login details in cybercriminal ecosystems.
Nature of the Campaign
According to Mandiant, the campaign “is not the result of any particularly novel or sophisticated tool, technique, or procedure.” Its success stemmed from the sheer volume of credentials available in the infostealer market and the failure of organizations to rotate passwords or enable MFA over extended periods. The attackers capitalized on stale, widely circulated login details rather than developing new exploits.
Clarifying the Victim Count
The figure of 165 organizations has evolved since the initial disclosures. Originally, it represented the number of entities Mandiant and Snowflake notified as potentially exposed. Prosecutors now use it to denote the number of customers that were actually compromised. The Justice Department’s release cites “over 165 organizations” in the body, while an official statement from Assistant Attorney General A. Tysen Duva references “over 150,” reflecting the ongoing refinement of the impact assessment as forensic analysis continues.
Types of Data Exfiltrated
The stolen information varied widely across victims. It included non‑content call and text logs, payroll data, DEA registration numbers, passport numbers, Social Security numbers and other personally identifiable information. Notably, AT&T confirmed in July 2024 that call and text records for nearly all its cellular customers between May 1 and October 31 2022 were taken from its workspace on a third‑party cloud platform, illustrating how even telecom giants were affected through their SaaS usage.
Additional Extortion Tactics
Beyond the initial data theft, Moucka re‑extorted at least one victim. Prosecutors allege he threatened further disclosure of the stolen data involving a government officer and members of that officer’s immediate family. FBI Special Agent in Charge W. Mike Herrington described these tactics as “calculated and predatory,” emphasizing the attackers’ willingness to leverage sensitive personal information for additional financial gain.
Broader Financial Impact
The direct financial losses incurred by the victim organizations exceeded $9.5 million. This figure excludes indirect costs such as fraud suffered by the organizations’ customers, regulatory fines, remediation expenses and reputational damage. The case underscores how credential‑based breaches can generate substantial monetary harm even when no sophisticated malware or zero‑day exploits are involved.
Snowflake’s Response and Ongoing Security Measures
In response to the breach, Snowflake has implemented MFA by default for all human users on accounts created after October 2024. However, password‑only authentication remains permissible for older accounts. The company’s documentation indicates that the final phase of blocking password‑only sign‑ins for every remaining human and service user will be rolled out account‑by‑account between August and October 2026, with reader and trial accounts exempted from this restriction. Until then, organizations using legacy Snowflake accounts must enforce their own MFA policies and rotate credentials regularly to mitigate similar risks.

