LIVE·

Global News & Market Intelligence · Verified Official Dispatches

Editions:
LIVEMARKETS:
S&P 500 5,640.20 (+0.45% )|NASDAQ 17,855.10 (+0.62% )|BRENT CRUDE $82.40 (-0.85% )|BITCOIN $64,250.00 (+1.90% )
S&P 500 5,640.20 (+0.45% )|NASDAQ 17,855.10 (+0.62% )|BRENT CRUDE $82.40 (-0.85% )|BITCOIN $64,250.00 (+1.90% )
Breaking
Cybersecurity· 🌍 Global

Canadian National Pleads Guilty to Massive Snowflake Data Extortion

Connor Riley Moucka has entered a guilty plea for orchestrating a series of cyberattacks against 165 Snowflake customers, resulting in the theft of vast amounts of data.

By Technology & AI Intelligence Desk·Published ·⏱️ 2 min read (377 words)
⚡ AI-Synthesized Briefing · Verified Editorial

Key Story Metrics & Context

Industry Sector:Cloud Computing, Telecommunications, Retail
Companies Impacted:Snowflake, AT&T, TicketMaster, Lending Tree, Advance Auto Parts, Neiman Marcus
Geographic Scale:Canada 🇨🇦, USA 🇺🇸
Reporting Status:✓ Multi-Source Verified
Canadian National Pleads Guilty to Massive Snowflake Data Extortion

Executive Brief & Verified Analysis

✓ OFFICIAL SOURCES REVIEWED

Executive Summary

Connor Riley Moucka has entered a guilty plea for orchestrating a series of cyberattacks against 165 Snowflake customers, resulting in the theft of vast amounts of data.

Why This Matters

Key strategic implication: Connor Riley Moucka pleaded guilty to hacking 165 Snowflake client organizations.

Market Impact

Verified for Snowflake, AT&T, TicketMaster, Lending Tree, Advance Auto Parts, Neiman Marcus. Primary market adjustment vector.

Source Verification

Cross-referenced across regulatory dispatches, official press releases, and verified wire filings.

Operational context for Canadian National Pleads Guilty to Massive Snowflake Data Extortion
📸 Figure 1.2 · Operational Context
Figure 1.2: Secondary sector visual for Cybersecurity briefing on Canadian National Pleads Guilty to Massive Snowflake Data Extortion.Skyline Intelligence

Strategic Implications

  • Connor Riley Moucka pleaded guilty to hacking 165 Snowflake client organizations.
  • The breaches resulted in the theft of call and text records for over 100 million AT&T customers.
  • Criminals generated over $2.5 million in illicit ransom payments.
  • The crimes occurred over a period between February and October 2024.
  • Snowflake has since mandated multi-factor authentication for its users.

Connor Riley Moucka, a 26-year-old resident of Kitchener, Ontario, has officially entered a guilty plea regarding his role in a prolific cybercrime campaign targeting the cloud storage firm Snowflake. According to Krebs on Security, the defendant faced charges related to conspiracy and computer fraud, admitting to the compromise of 165 organizations that relied on the cloud platform for data management. In addition to the Snowflake breaches, Moucka confessed to the exfiltration of sensitive call and text history logs belonging to more than 100 million AT&T customers.

Incident Statistics and Data Scope

The U.S. Department of Justice investigation determined that the criminal activity occurred between February and October 2024. Moucka, known in various digital circles by the monikers "Judische" and "Waifu," utilized stolen credentials to bypass systems that failed to implement multi-factor authentication. The scope of the stolen data was extensive, including banking details, payroll records, DEA registration numbers, government-issued IDs, and passport documentation. The conspirators successfully extorted over $2.5 million in ransom payments.

MetricFigure
Organizations Targeted (Snowflake)165
AT&T Customers Affected100,000,000+
Ransoms Paid$2,500,000+
Operational PeriodFeb 2024 - Oct 2024

Official Context

Law enforcement interest in the suspect accelerated following reports from Krebs on Security in September 2024, which linked "Judische" to a history of data breaches and phishing attacks against U.S. entities dating back to 2020. The Royal Canadian Mounted Police (RCMP) arrested Moucka shortly thereafter, acting on a provisional warrant issued by the United States. Following the breaches, Snowflake took technical measures to harden customer accounts by enforcing stricter password policies and mandatory multi-factor authentication protocols.

Why It Matters

This case underscores a fundamental vulnerability in the shared responsibility model of cloud computing. While providers like Snowflake offer infrastructure, the failure of client-side entities to enforce basic identity hygiene—specifically multi-factor authentication—remains the primary vector for mass-scale exfiltration. The diversification of extortion tactics, which included re-extortion and the targeting of researchers, signals a shift toward more aggressive, psychological warfare within the cybercrime ecosystem. Organizations must move beyond static security perimeters and prioritize granular credential monitoring to mitigate the threat of automated credential stuffing operations.

Deployment Roadmap & Timeline

2020

Suspect involved in data breaches and phishing against U.S. companies.

February 2024

Start of the specific Snowflake data theft campaign.

September 2024

Krebs on Security documents the activity of the 'Judische' identity.

October 2024

Canadian authorities arrest Moucka following a provisional U.S. warrant.

Expected Next Steps

  • 1Formal sentencing hearing for the defendant in U.S. federal court.
  • 2Ongoing forensic audits by the 165 affected Snowflake clients.
  • 3Potential expansion of investigation into co-conspirators mentioned by the DOJ.

Frequently Asked Questions

At least 165 organizations that used Snowflake as a cloud data storage provider were affected.

The defendant, Connor Riley Moucka, operated under the handles 'Judische' and 'Waifu'.

According to the U.S. Justice Department, the group successfully collected over $2.5 million in ransom payments.

Source Transparency & Verified Dispatches

✓ Verified Primary Data
U.S. Department of Justice💼 Corporate Dispatch
Source ↗
Royal Canadian Mounted Police (RCMP)💼 Corporate Dispatch
Source ↗
Snowflake💼 Corporate Dispatch
Source ↗

Reader Discussion & Insights

Leave a Comment

Loading discussion thread...

Get Breaking Global Intel in Your Inbox

Subscribe to the Skyline Wire AI Daily Briefing. Direct insights across Aviation, Tech, EVs, and Markets.

Original announcement link: Krebs on Security

cybersecuritysnowflakeextortiondata-breachjustice-department
snowflake data breachconnor riley mouckacyber extortionatt data theftcomputer fraud conspiracyjudischewaifumulti-factor authentication