# The Snowflake Extortionist Who Made $2.5 Million Off Your Laziness About MFA


There is a version of this story where 165 companies never got hit. It's the version where someone enforced multi-factor authentication on their Snowflake accounts. Connor Riley Moucka didn't find a zero-day. He didn't compromise Snowflake's infrastructure. He walked through doors that shouldn't have been left unlocked and spent nine months stealing everything that wasn't nailed down.


On August 5, Moucka — a 26-year-old software engineer from Kitchener, Ontario who operated under the aliases "Judische" and "Waifu" — pleaded guilty to computer fraud and conspiracy charges in U.S. federal court. The Justice Department's case covers a campaign stretching from February through October 2024, during which Moucka and co-conspirators used stolen credentials to breach at least 165 Snowflake customers, extort a host of major corporations, and pull in over $2.5 million in ransom payments.


The victim list reads like a Fortune 500 highlight reel: TicketMaster, LendingTree, Advance Auto Parts, Neiman Marcus. The stolen data inventory is more troubling than the names — billions of records including call and text histories, payroll data, DEA registration numbers, Social Security numbers, passport numbers, and banking information. In AT&T's case alone, Moucka admitted to stealing call and text history records for more than 100 million customers.


## Credential Stuffing at Industrial Scale


The technical method here wasn't sophisticated, which makes it more infuriating in retrospect. Moucka and his crew obtained stolen credentials — likely from infostealer logs sold across criminal markets — and tested them against Snowflake tenant accounts. Where MFA wasn't enforced, they walked straight in.


Snowflake wasn't breached. Its own systems weren't compromised. The company was the storage layer; the point of failure was the customers who'd connected sensitive data warehouses to accounts without a second authentication factor. In some cases, these were accounts holding what amounts to a company's operational crown jewels — every customer record, every transaction, every employee payroll file.


After the campaign became public, Snowflake moved to increase password complexity requirements and enforce MFA across its platform. That's the right call. It should have been default years earlier.


## The Army Soldier in the Crew


The co-conspirator angle deserves more attention than it's gotten. Cameron Wagenius — online handle "Kiberphant0m" — is a U.S. Army soldier who pleaded guilty in July 2025 to extorting AT&T and Verizon for customer account data. Before his arrest, KrebsOnSecurity traced his various Telegram and Discord identities over the years, including posts in which the account owner stated they were in the military and stationed in South Korea.


Immediately after Moucka's arrest in October 2024, Kiberphant0m escalated. He posted on hacker forums what he claimed were AT&T call logs for then President-elect Donald Trump and then Vice President Kamala Harris, along with alleged schematics from a U.S. national security facility. Whether the data was genuine is a separate question. The behavior — a serving military member using potentially stolen national-security-adjacent data as a post-arrest intimidation play — is extraordinary.


This isn't the first case involving military personnel in cybercrime, but it remains rare enough to be remarkable. The security clearance implications alone should prompt serious questions from DoD.


## Re-Extortion: The Second Bite


The guilty plea includes something the initial reporting largely glossed over: Moucka re-extorted at least one victim after receiving ransom payment. He threatened further disclosure to extract additional payments, and in one instance used stolen data belonging to a government officer's immediate family in that re-extortion attempt.


This is a detail defenders should file away carefully. The conventional ransomware playbook — pay the ransom, recover, move on — was already showing cracks with the rise of data exfiltration as a parallel pressure tactic. Re-extortion adds another layer: payment doesn't terminate the relationship. The adversary retains the data, retains the leverage, and can return. Legal advisors and IR teams need to be honest with clients about this dynamic rather than treating ransom payment as a clean exit.


Wagenius engaged in the same pattern. Both men used victim data as a renewable weapon.


## HackWire Analysis


The Snowflake case is a watershed, but not for the reasons most coverage emphasizes.


Yes, 165 organizations is a stunning number of victims for a single campaign. Yes, Moucka was 25 years old during most of this. Yes, the haul — 100 million AT&T records, terabytes of data from name-brand companies — is extraordinary. But those numbers obscure what should be the central lesson: this entire campaign was predicated on a configuration failure that organizations could have remedied with an admin checkbox.


MFA enforcement on cloud data warehouses is not an advanced defensive posture. It's baseline hygiene. The fact that major enterprises — companies with security teams, compliance programs, and vendors screaming about credential theft for years — were running Snowflake tenants without it in 2024 is a governance failure, not a technical one.


The pattern here echoes the 2021 Colonial Pipeline attack, where an old VPN account without MFA served as the initial access point for DarkSide. It echoes the 2023 MOVEit campaign, where a single SQLi vulnerability cascaded across hundreds of organizations simultaneously. What connects them isn't just the scale — it's that each attack worked because a known control was either missing or not enforced. The threat intelligence community identifies these gaps constantly. Organizations still don't close them fast enough.


The broader trend Moucka represents is the professionalization of extortion-first attacks: don't encrypt, don't disrupt operations, just exfiltrate quietly and monetize the data. This approach is harder to detect, harder to attribute, and increasingly more profitable than ransomware. Defenders should be asking themselves right now which cloud storage accounts, SaaS integrations, and API connections in their environment lack enforced MFA — and whether they'd know if someone like Moucka had been sitting in one of them for three months.


The $2.5 million in ransom payments is the number prosecutors will cite. The real cost — litigation, regulatory exposure, remediation, reputational damage — will run orders of magnitude higher across 165 organizations.


— HackWire Editorial


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)