Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Government & Policy » Canadian Hacker Pleads Guilty in Snowflake Data Theft Campaign Affecting Millions

Canadian Hacker Pleads Guilty in Snowflake Data Theft Campaign Affecting Millions

Last updated:August 7, 2026
Human Written
  • 26-year-old Connor Moucka, who hails from Kitchener in Ontario, Canada, has pleaded guilty to hacking more than 165 firms through Snowflake’s cloud storage system.

  • The attack allowed them to steal confidential information from companies such as AT&T and Ticketmaster, compromising 100 million individuals.

  • Muoka conspired with another man to extort millions of dollars worth of bitcoin. He’ll likely spend up to 32 years in jail.

Canadian Hacker Pleads Guilty in Snowflake Data Theft Campaign Affecting Millions

A 26-year old Canadian man has admitted to his involvement in what’s considered one of the biggest cloud data thefts in recent years.

Connor Moucka pleaded guilty to charges of computer fraud, wire fraud, aggravated identity theft, and conspiracy on August 5, 2O26. He, along with others, went after companies that relied on Snowflake’s cloud storage. They stole call logs, banking info, social security numbers—details from hundreds of millions of people.

Moucka’s Massive Hacking Campaign

Connor Riley Moucka, who hails from Kitchener, Ontario, committed the hacking attacks along with his fellow hacker, John Erin Binns. Between February and October 2O24, the two were able to get into the Snowflake accounts without using multi-factor authentication (MFA).

They gained entry into the accounts by stealing login credentials using infostealer malware to infect people’s devices. Due to the absence of MFA, the hackers simply had to have the right username and password combination to hack into the accounts.

Moucka crafted custom software to facilitate the identification of information of high value. The program scanned for organization names, user roles, and IP addresses in cloud storage instances. Once they found valuable data, they exfiltrated terabytes of information from Snowflake tenant environments.

Stolen Data and Extortion

The hackers stole an alarming range of sensitive information. Their haul included call and text history records, banking and financial information, payroll records, and Drug Enforcement Administration (DEA) registration numbers. They also took driver’s license numbers, passport numbers, Social Security numbers, and other personally identifiable information (PII).

The attackers used this stolen data to extort money from their victims. They received at least $2.5 million in bitcoin from three victims. But they didn’t stop there. In at least one instance, Moucka used threats of further disclosure to re-extort one victim.

In a similar extortion attempt, the ShinyHunters group targeted Rockstar Games, and threatened to leak data allegedly stolen from the company’s Snowflake instance through Anodot, a third-party analytics platform. He specifically used data he stole from a government officer and some immediate family members of a former government officer in this attempt.

The hackers also advertised the stolen information on various hacker forums. They sold the data for fiat currency or cryptocurrency. Moucka personally obtained at least $495,000 this way.

The Scope of Impact and Victims

The damage from these attacks has been staggering. The victim companies suffered more than $9.5 million in losses. The Snowflake data breach affected over a hundred million individuals.

Several major companies reported falling victim to the attack. The list includes AT&T, Ticketmaster, Advance Auto Parts, Santander, Pure Storage, Neiman Marcus, QuoteWizard/LendingTree, and Los Angeles Unified. AT&T alone had call and text metadata for approximately 109 million U.S. customers stolen.

The attacks exploited a simple weakness. The compromised firms did not activate the multi-factor authentication feature available from Snowflake as an optional security configuration choice.

The incident resulted in enhanced security for Snowflake. The company now enforces MFA protection by default and requires all passwords to be at least 14 characters long.

Moucka’s arrest happened at a Kitchener home on October 30, 2O24. Then on July 2O25, authorities extradited him to the United States. His accomplice, John Erin Binns, hailed from Turkey when the attacks took place. An approval was made by a local court for the extradition application filed by U.S. prosecutors, though it was challenged.

This guilty verdict is a clear message to cyber criminals. “Today’s guilty plea is a message to all cyber criminals, no matter where they reside, that there is nowhere to hide behind the anonymity wall,” Asst Attorney General A. Tysen Duva said. Moucka’s sentencing comes up on October 27, and he’s likely to get up to 32 years in prison.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.