Particle.news

Canadian Pleads Guilty in Massive Snowflake Cloud Breach

The plea signals growing U.S. law-enforcement focus on criminal use of stolen cloud credentials and the potential for stiffer penalties for cross-border data extortion.

Overview

  • Connor Riley Moucka pleaded guilty on Wednesday to four federal counts for his role in a 2024 campaign that compromised at least 165 customer environments on a U.S. cloud data platform.
  • Prosecutors say Moucka and co-conspirators used logins stolen by infostealer malware to access accounts that lacked multi-factor authentication and then automated discovery and download of terabytes of high-value data.
  • The group stole records tied to more than 100 million people, extorted victims for roughly $2.5 million in cryptocurrency, and Moucka personally received at least $495,000 according to court filings.
  • Victim companies reported more than $9.5 million in direct losses and named firms affected included AT&T, Ticketmaster and Santander; Moucka faces a mandatory two-year term on identity-theft charges and up to decades more at sentencing on Oct. 27, 2026.
  • The case was built with help from police in Canada, Australia, Spain, Ukraine and Turkey and is part of broader FBI efforts to disrupt cybercrime, a development that has already pushed vendors to require stronger password rules and enforce multi-factor authentication.