A Canadian man has admitted his involvement in a large-scale cybercrime operation that compromised cloud storage accounts belonging to at least 165 organizations, stole vast amounts of sensitive information, and generated millions of dollars through extortion and data sales.
The U.S. Department of Justice (DoJ) announced that Connor Riley Moucka, 26, pleaded guilty to multiple criminal charges connected to the attacks. Investigators allege that, between February and October 2024, Moucka and his alleged accomplice John Erin Binns targeted organizations using Snowflake’s cloud platform by exploiting accounts that lacked multi-factor authentication (MFA).
According to prosecutors, the attackers did not exploit a vulnerability in Snowflake itself. Instead, they used usernames and passwords previously stolen by information-stealing malware. Because many customer accounts were protected only by passwords, the stolen credentials were sufficient to gain unauthorized access to cloud environments.
Court documents state that the attackers used custom-built software to automatically examine compromised accounts, identifying valuable information such as organization names, user roles and network details before searching for sensitive data that could be monetized.
Authorities say the campaign resulted in the theft of terabytes of information from numerous organizations. The stolen data reportedly included call and text metadata, banking and payroll records, Drug Enforcement Administration registration numbers, passport and driver’s license details, Social Security numbers and other personally identifiable information. The exact categories of exposed information varied between victims.
After copying the data, the attackers allegedly contacted victim organizations and demanded ransom payments in exchange for not publishing or selling the stolen information. Prosecutors say at least three companies paid a combined $2.5 million in bitcoin. In addition to extortion, the stolen datasets were advertised for sale on cybercrime forums, where investigators believe Moucka received approximately $495,000 from data sales.
The Justice Department also alleges that one victim was targeted twice. According to prosecutors, after obtaining an initial payment, Moucka attempted to extort the same organization again by threatening additional disclosures. Officials further allege that this second attempt involved using personal information belonging to a government official and members of that individual’s family to increase pressure on the victim.
The investigation concluded that organizations affected by the campaign suffered more than $9.5 million in financial losses, while the stolen records related to more than 100 million individuals.
Moucka pleaded guilty to charges including computer fraud, wire fraud, aggravated identity theft and conspiracy. He is scheduled to be sentenced on October 27 and faces a maximum possible prison sentence of 32 years.
His alleged co-conspirator, John Erin Binns, was arrested in Turkey. Turkish authorities approved a request from the United States seeking his extradition, although legal proceedings challenging that decision have continued.
The campaign affected organizations across multiple industries. Companies publicly linked to the attacks include AT&T, Ticketmaster, Santander, Pure Storage, Advance Auto Parts, Los Angeles Unified School District, QuoteWizard/LendingTree and Neiman Marcus.
Following the incident, Snowflake announced several security changes intended to reduce the risk of similar attacks. The company introduced mandatory multi-factor authentication requirements for customer accounts and increased its minimum password length requirement to 14 characters, reflecting a broader industry shift toward stronger identity protection after one of the most significant cloud account compromise campaigns in recent years.
