Snowflake hacker pleads guilty to stealing data from 165 organizations, faces 32 years in prison
Connor Riley Moucka pleaded guilty to hacking Snowflake accounts, stealing data from 165 organizations, and extorting millions. He faces up to 32 years in prison.
A Canadian man pleaded guilty on August 5, 2026, to orchestrating a massive data theft campaign targeting cloud storage provider Snowflake. Connor Riley Moucka, 26, admitted to accessing accounts at Snowflake and stealing data from at least 165 organizations, then extorting victims for millions of dollars.
Between February and October 2024, Moucka and co-conspirator John Erin Binns used login credentials stolen via infostealer malware to break into Snowflake customer accounts that lacked multi-factor authentication. They stole call and text history records, banking and financial information, payroll records, driver's license numbers, passport numbers, Social Security numbers, and other personally identifiable information from companies including AT&T, Ticketmaster, Santander, Pure Storage, Advance Auto Parts, Los Angeles Unified, QuoteWizard/LendingTree, and Neiman Marcus.
Extortion and re-extortion tactics
Moucka and Binns attempted to extort multiple companies after stealing terabytes of data from their Snowflake environments. They obtained at least $2.5 million in bitcoin from at least three victims. Moucka also advertised stolen data on hacker forums, earning at least $495,000 from sales. In at least one instance, Moucka re-extorted a victim by threatening to disclose stolen data belonging to a government officer and members of a former government officer's immediate family.
- Victim companies suffered more than $9.5 million in losses.
- More than 100 million individuals had their data compromised.
- Moucka pleaded guilty to four counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy.
- He faces a maximum sentence of 32 years in prison, with sentencing scheduled for October 27, 2026.
- Binns was arrested in Turkey and is contesting extradition to the United States.
Industry response and fallout
Following the breaches, Snowflake announced it would enforce multi-factor authentication for all accounts and require passwords to be at least 14 characters long. The attacks highlighted the vulnerability of cloud storage services when customers fail to enable basic security protections. The U.S. Department of Justice noted that Moucka's actions affected over 100 million individuals and caused significant financial harm to victim companies. The case underscores the ongoing threat from infostealer malware and the importance of MFA adoption across enterprise cloud environments.
Moucka's sentencing in October will determine whether he serves the maximum 32-year term. The case also raises questions about how cloud providers can better protect customers who neglect security basics, and whether stricter regulations or liability frameworks are needed to prevent similar large-scale data thefts in the future.
Fact check
-
Connor Riley Moucka pleaded guilty on August 5, 2026, to hacking Snowflake accounts and stealing data from at least 165 organizations.
verified · source
-
Moucka and Binns obtained at least $2.5 million in bitcoin from at least three victims.
verified · source
-
Victim companies suffered more than $9.5 million in losses and more than 100 million individuals were affected.
verified · source
-
Moucka faces a maximum sentence of 32 years in prison.
verified · source
-
Snowflake announced it would enforce MFA and require passwords to be at least 14 characters long after the breaches.
verified · source
Source reporting (2)
Related Articles
AI Agents From OpenAI and Anthropic Breach Real Websites During Security Tests
Aug 5, 2026
AI Agent Security Startups Zenity and Horizon3.ai Raise $375M Combined as SentinelOne Expands Autonomous SOC
Aug 3, 2026
OpenAI and Anthropic Reveal Multiple AI Agents Escaped Containment, Hacked Outside Firms
Aug 1, 2026
0 Comments
No comments yet
Be the first to share your thoughts on this article.