
Canadian hacker Connor Riley Moucka has pleaded guilty to a cybercrime campaign that compromised more than 165 organizations, stole billions of records and generated millions of dollars through extortion and data sales. The 26-year-old from Kitchener, Ontario, admitted to computer fraud, wire fraud, aggravated identity theft and conspiracy charges.
The attacks took place between February and October 2024 and targeted customer accounts hosted by cloud data platform Snowflake. Moucka and his co-conspirators used stolen login credentials to access the affected systems rather than breaching Snowflake’s own corporate network.
Attackers Stole Billions of Sensitive Records
According to the U.S. Department of Justice, the group downloaded terabytes of data containing call and text records, banking information, payroll data, driver’s license numbers, passport numbers, Social Security numbers and other personal information.
Among the companies affected during the broader Snowflake campaign were AT&T, Ticketmaster and LendingTree. The DOJ said the compromised organizations collectively served at least 100 million customers, although customer losses are not included in its financial damage estimate.
Google-owned cybersecurity firm Mandiant previously tracked the campaign as UNC5537. Its investigation found that attackers primarily relied on credentials stolen through infostealer malware, often targeting accounts that did not have multi-factor authentication enabled.
Ransom Payments Exceeded $2.5 Million
Moucka and his accomplices received more than $2.5 million in ransom payments, according to prosecutors. They also advertised stolen information for sale through BreachForums, Exploit.in, XSS.is and Telegram.
The DOJ said Moucka personally received at least $495,000 from selling stolen data. Victim companies suffered more than $9.5 million in direct losses, excluding losses experienced by their customers.
Prosecutors also said Moucka used re-extortion tactics in at least one case, threatening further disclosure after an initial extortion attempt. The stolen information involved a government officer and relatives of a former government official.
Sentencing Scheduled for October
Moucka was arrested in Canada in late 2024 and extradited to the United States in July 2025. The investigation involved the FBI along with authorities in Canada, Australia, Spain, Ukraine and Turkey.
He is scheduled to be sentenced on October 27. The aggravated identity theft conviction carries a mandatory minimum sentence of two years, while the remaining charges carry maximum penalties of up to 30 years in prison.
The Snowflake campaign previously prompted Mandiant and Snowflake to notify about 165 potentially exposed organizations and recommend stronger security measures, including mandatory multi-factor authentication, credential rotation and restrictions on network access.
Featured image credits: Wikimedia Commons
For more stories like it, click the +Follow button at the top of this page to follow us.
