Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Canadian pleads guilty to Snowflake cloud data-theft attacks

    August 5, 2026

    Ransom Cartel ransomware creator sentenced to 16 years in prison

    August 5, 2026

    The SEC Bought Airline Data to Monitor Flights Worldwide

    August 5, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Canadian pleads guilty to Snowflake cloud data-theft attacks
    News

    Canadian pleads guilty to Snowflake cloud data-theft attacks

    adminBy adminAugust 5, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Canadian pleads guilty to Snowflake cloud customer breaches

    A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims.

    ​26-year-old Connor Riley Moucka, also known as Alexander Moucka and Waifu, was arrested on October 30, 2024, for stealing data of hundreds of millions of individuals from companies using Snowflake’s storage service.

    Between February and October 2024, Moucka and John Erin Binns, also indicted for these attacks, accessed Snowflake accounts not protected by multi-factor authentication (MFA) using logins stolen via infostealer malware.

    image

    Without MFA enabled, the threat actor needed only the correct usernames and passwords to log into customer accounts.

    According to court documents, the unauthorized access was used to identify valuable information (e.g., organization name, user roles, IP addresses) in cloud storage instances using custom software.

    Moucka and Binn tried to extort multiple companies after stealing terabytes of data from their Snowflake tenant environments and obtained at least $2.5 million in bitcoin from at least three victims.

    The following information was stolen from the breached accounts:

    • Call and text history records (non-content)
    • Banking and financial information
    • Payroll records
    • Drug Enforcement Administration (DEA) registration numbers
    • Driver’s license numbers
    • Passport numbers
    • Social Security numbers
    • Other personally identifiable information (PII)

    They also advertised on various hacker forums to sell the information for fiat currency or cryptocurrency, and Moucka obtained at least $ 495,000 this way.

    In a press release today, the U.S. Department of Justice says that “in at least one instance, Moucka re-extorted a victim with threats of further disclosure of the victim’s stolen data.”

    “Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt.”

    The DoJ says that victim companies suffered more than $9.5 million in losses and more than 100 million individuals have been affected by the Snowflake attacks.

     

    Moucka pleaded guilty to four counts of the indictment (computer fraud, wire fraud, aggravated identity theft, and a related conspiracy) and is scheduled for sentencing on October 27.

    He faces a maximum sentence of 32 years in prison.

    At the time of the attacks, Binns resided in Turkey, where he was arrested. A local court approved an extradition request from U.S. prosecutors but it was contested.

    The list of impacted companies includes AT&T, Ticketmaster, Santander, Pure Storage, Advance Auto Parts, Los Angeles Unified, QuoteWizard/LendingTree, and Neiman Marcus.

    Following these data breaches, Snowflake announced it would enforce MFA protection and require all passwords to be at least 14 characters long.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleRansom Cartel ransomware creator sentenced to 16 years in prison
    admin
    • Website

    Related Posts

    News

    Ransom Cartel ransomware creator sentenced to 16 years in prison

    August 5, 2026
    News

    The SEC Bought Airline Data to Monitor Flights Worldwide

    August 5, 2026
    News

    Apple’s ‘Private Relay’ Is Exposing Users’ Real IP Addresses

    August 5, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202635 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202635 Views
    Our Picks

    Canadian pleads guilty to Snowflake cloud data-theft attacks

    August 5, 2026

    Ransom Cartel ransomware creator sentenced to 16 years in prison

    August 5, 2026

    The SEC Bought Airline Data to Monitor Flights Worldwide

    August 5, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.