# The Man Who Drained 165 Companies Pleads Guilty. The Method Should Haunt Every Cloud Team.


Connor Riley Moucka didn't need a zero-day. He didn't need nation-state infrastructure or months of reconnaissance. He needed a list of stolen passwords and a cloud platform where a hundred major corporations had helpfully concentrated their most sensitive data in one place.


That's the story behind Tuesday's guilty plea in federal court, where Moucka, 26, admitted his role in one of the largest data theft campaigns in recent memory — a campaign that compromised 165 organizations, exposed records belonging to at least 100 million people, and netted roughly $2.5 million in ransom payments. The technical method was embarrassingly simple. The damage was not.


## The Plea and What's Coming


Moucka pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy. He's looking at more than 30 years in federal prison when he's sentenced on October 27. The Justice Department says targeted companies suffered direct losses exceeding $9.5 million — and pointedly notes that figure excludes what their customers lost, a number that's almost certainly larger and likely impossible to calculate.


His path to an American courtroom took a year. Arrested in Canada in late 2024, Moucka fought extradition before being transferred to US custody in July 2025. He'd been operating under the alias "Alexander Connor Moucka" — loose enough digital hygiene that investigators had little trouble building a case once they had him.


He personally cleared about $500,000, primarily from selling stolen data on hacking forums. By cybercrime standards, that's a respectable haul. By the standards of what he actually cost — nine-figure corporate losses plus the downstream harm to over a hundred million people — it's almost comic.


## What UNC5537 Actually Did


The threat group Mandiant tracks as UNC5537 didn't exploit Snowflake's software. There was no CVE, no supply chain compromise, no fancy implant. The attackers used infostealer-harvested credentials to log in to Snowflake tenant environments that weren't protected by multi-factor authentication.


That's it. That was the whole technique.


Snowflake had offered MFA as an option. Requiring it was left to individual customers. The 165 organizations that got hit had apparently weighed that option and kept going without it — because enforcing MFA on data warehouse accounts is annoying, and because nobody really thinks their cloud analytics environment is a high-value target until it is.


The victim list tells you everything about why this was attractive. AT&T. Ticketmaster. Santander Bank. Advance Auto Parts. Neiman Marcus. Anheuser-Busch. Allstate. Mitsubishi. Progressive. State Farm. These aren't organizations that store a little customer data — they store *a lot* of it, often in centralized platforms exactly like Snowflake, precisely because aggregated data is useful. The same aggregation that makes analytics fast and cheap makes a successful breach catastrophic.


## The AT&T Thread Keeps Pulling


One detail buried in the original reporting deserves attention: a former US Army soldier who pleaded guilty roughly a year ago to hacking AT&T and Verizon systems is also believed to have participated in the Snowflake campaign.


The AT&T breach has been litigated in the press extensively, but the connection between UNC5537 and a US military insider is still underreported. It raises uncomfortable questions about how the group recruited and whether there's more to the story than pure financial motivation. The DOJ hasn't fully articulated the relationship publicly, and that gap matters.


## The Corporate Loss Number Is the Wrong Number


The DOJ's $9.5 million in corporate losses is a floor, not a ceiling, and it's arguably the least important number in this case.


A hundred million people had their personal and financial information stolen, then sold on hacking forums by a 26-year-old collecting half a million dollars in the process. Incident response costs and legal fees are finite. The actual harm to those people — fraud, identity theft, the years of monitoring and cleanup — compounds indefinitely and shows up in places that never get attributed back to the original breach.


This is the accounting problem that cybercrime enforcement consistently struggles with: the numbers in DOJ press releases reflect what's legible to prosecutors, not what was actually lost. The real cost of this campaign is probably an order of magnitude higher than what Moucka is being sentenced for.


---


## HackWire Analysis


The Snowflake campaign closure lands at an interesting moment in cloud security posture. Over the past 18 months, the major cloud platforms have been steadily tightening default security controls — AWS moved aggressively on S3 bucket permissions, Microsoft has been pushing Conditional Access harder, and even Snowflake quietly updated its authentication documentation after this incident. The industry's self-regulatory response to UNC5537 has been real, if belated.


But the deeper lesson isn't about MFA. It's about what happens when enterprises treat cloud data warehouses like internal network shares — environments where access controls are an afterthought because the data is "just analytics." The credential-stuffing vector that UNC5537 used is completely blunt-force. It works because the economics favor it: infostealer logs are cheap, cloud tenant URLs are often discoverable, and the authentication surface is enormous. Running through a hundred thousand credential pairs against Snowflake logins costs almost nothing. Getting one hit against AT&T's analytics environment is worth millions.


Security teams should be asking a pointed question right now: which cloud tenants in their environment are holding sensitive data but protected only by username and password? The answer is almost certainly "more than you think." Shadow IT and departmental data pipelines frequently bypass the IAM governance applied to core infrastructure.


The Moucka plea also signals that US law enforcement is meaningfully closing the gap on extradition timelines for financially-motivated cybercrime. Canada-to-US delivery in roughly eight months is faster than the historical norm. If you're building a threat model that assumes foreign jurisdictions provide durable cover, that assumption is getting riskier.


Prosecutors got a guilty plea. That's accountability in the narrow sense. But 100 million people are still living with the downstream consequences of a campaign that exploited no technical vulnerability whatsoever — just the gap between what organizations *could* require and what they actually bothered to enforce.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)