# The 26-Year-Old Who Emptied 165 Companies Just Told a Federal Judge He Did It


Connor Riley Moucka walked into a Seattle federal courtroom on Wednesday and admitted what security researchers had suspected for over a year: he was the person behind one of the most consequential breach campaigns in the history of cloud computing. A hundred million people. A hundred sixty-five organizations. Nearly half a million dollars personally pocketed. And the technique? Credential stuffing — the digital equivalent of trying stolen keys until one opens the door.


Moucka, 26, of Kitchener, Ontario, pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy charges stemming from a 2024 wave of intrusions into Snowflake customer accounts. The guilty plea closes the criminal chapter on a campaign that exposed something the cloud industry had been quietly hoping wouldn't become a news story: an enormous data warehouse sitting behind a username and password, waiting to be robbed.


## What Actually Happened in Those 165 Breaches


The Snowflake campaign was not a zero-day. Nobody found a flaw in Snowflake's platform architecture. There was no sophisticated supply chain attack, no custom malware implant delivered through a trusted vendor. Moucka and his co-conspirators — including John Erin Binns, already in custody — used credentials harvested by infostealer malware. Lumma, Redline, Raccoon — the standard commercial tools sold in underground markets for a few hundred dollars a month. Infostealers vacuum up saved browser credentials and session tokens from infected machines. If an employee's personal laptop picks up an infostealer, their work credentials go to market.


The attackers then pointed those credentials at Snowflake tenant environments. Any account without multi-factor authentication was an open door. And remarkably, across 165 corporate victims, a significant number of those doors were unlocked.


## Who Got Hit — and Why the Scale Matters


The victim list reads like a who's-who of companies that exist to hold data about people. AT&T confirmed its breach covered call records for nearly all of its wireless customers — essentially a complete map of who called whom across the United States for years. Ticketmaster, owned by Live Nation, lost hundreds of millions of customer records including partial payment data. Advance Auto Parts. Santander Bank. LendingTree. Pure Storage. Neiman Marcus. The common thread wasn't industry; it was a decision to use Snowflake's data cloud without enforcing MFA.


That's what makes the "100 million people" figure so hard to contextualize. It's not 100 million people who were customers of one company. It's 100 million people who were customers of many different companies — healthcare providers, telecom giants, retailers, financial institutions — each of whom independently decided that password-only access to a cloud database full of sensitive records was acceptable.


## Snowflake's Uncomfortable Position


Snowflake was explicit: the platform itself was not compromised. That's technically true and contextually incomplete. When your product becomes the repository for hundreds of millions of people's most sensitive records, the "it's not our vulnerability" defense only stretches so far. The company faced pointed criticism from security researchers who noted that Snowflake had not enforced MFA by default, had not flagged unusual access patterns to customers with sufficient urgency, and had been slow to communicate the scope of the campaign to affected organizations.


Snowflake has since moved toward stronger authentication requirements — a change that, had it been in place earlier, would likely have made this campaign impossible. The lesson landed. The timing of the lesson is harder to forgive.


## A Rare Win for Criminal Accountability


Federal prosecution of cybercriminals remains frustratingly rare, particularly when the perpetrators operate outside US jurisdiction. Moucka was arrested in Canada in late 2024 at the United States' request — a reminder that the extradition process, while slow, does sometimes produce results. His guilty plea avoids a trial that would have required extensive technical testimony and international coordination.


The $495,000 Moucka personally extracted is a notable data point. It confirms the campaign was financially motivated rather than state-sponsored, and it puts a floor on the economics: at least half a million dollars in personal proceeds extracted from a breach affecting a hundred million people. The asymmetry between attacker gain and victim harm is jarring. For Moucka, this was a profitable two-year run that ended in a courtroom. For AT&T customers, it was the quiet exposure of years of call history to someone they'd never consented to share it with.


Sentencing has not yet been scheduled.


---


## HackWire Analysis


The Snowflake breach campaign is the most important cloud security case study of the decade, and the Moucka guilty plea gives us a clean moment to say what other coverage keeps tiptoeing around.


This was an entirely preventable catastrophe caused by a systemic failure of cloud security defaults — not by sophisticated tradecraft. The attackers weren't nation-state actors with zero-days. They were credential buyers. The defensive requirement wasn't cutting-edge; it was MFA. The fact that 165 enterprise organizations collectively failed to enforce MFA on a cloud environment containing records for over 100 million people isn't bad luck. It's a governance failure, and it's one that continues to play out in cloud environments globally right now.


The deeper problem is the abstraction layer cloud data warehouses create. When data moves off-premise and into a SaaS environment, it can fall into a gap between the security team that managed on-premise databases and the data engineering team that stood up the cloud warehouse. Nobody thinks they own the authentication policy. IT Security thinks it's a data team decision. The data team thinks it's an IT Security decision. The credentials go unprotected.


This campaign should fundamentally change how enterprises think about MFA enforcement policies. "Recommended" is not sufficient. Any cloud environment holding more than a threshold of sensitive records should require MFA as a condition of provisioning — not as a best practice document buried in an admin panel.


For CISOs specifically: audit your Snowflake environments today. Check every service account, every human account, every integration token. Then do the same for your other cloud data platforms. The technique Moucka used will outlast his case.


The guilty plea is justice. What the industry needs is the lesson.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)