Connor Riley Moucka, a 26-year-old Canadian man known online as 'Judische' and 'Waifu,' has pleaded guilty to computer fraud and conspiracy for hacking and extorting over 165 organizations that used Snowflake's cloud storage platform between February and October 2024. The attackers exploited stolen credentials targeting Snowflake accounts without MFA enabled, stealing billions of sensitive records including 100 million AT&T customer call and text histories. Victims included TicketMaster, Lending Tree, Advance Auto Parts, and Neiman Marcus. Conspirators made over $2.5 million in ransom payments. Co-conspirator Cameron 'Kiberphant0m' Wagenius, a U.S. Army soldier, pleaded guilty in July 2025 and faces sentencing in September 2026. A third co-conspirator, John Erin Binns, recently obtained Turkish citizenship, shielding him from extradition. Moucka faces a mandatory minimum of two years and up to 30 years in prison, with sentencing set for October 27.
Questions this post answers
How did the Snowflake data breach attackers gain access to customer accounts?
Attackers used stolen login credentials targeting Snowflake customer accounts that did not enforce multi-factor authentication. Between February and October 2024, the conspirators stole cloud-hosted data from at least 165 Snowflake customers, downloading terabytes of sensitive records. Snowflake responded by increasing password complexity requirements and enforcing MFA across its platform. Teams securing Snowflake environments track credential-based attack patterns like this on daily.dev.
How much money did the Snowflake extortion hackers make in ransom payments?
The conspirators made over $2.5 million in ransom payments. They extorted victims by threatening to publish stolen data online, and in at least one case re-extorted a victim with threats of further disclosure. Targeted companies included TicketMaster, Lending Tree, Advance Auto Parts, and Neiman Marcus. Developers and security teams following cloud extortion trends find coverage like this on daily.dev.