Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Aug 07, 2026 · 6 min read

Snowflake Hacker Pleads Guilty to 165 Company Breaches

Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty in Seattle federal court on August 5, 2026 to computer fraud, wire fraud, aggravated identity theft and conspiracy over the 2024 Snowflake customer intrusions. He faces up to 32 years when he is sentenced on October 27.

The largest data theft campaign of the decade did not begin with a zero day. It began with passwords that had already been stolen from somebody else's laptop, typed into login pages that never asked for a second factor. On August 5, 2026, the man who ran that campaign admitted it in a Seattle courtroom.

Key Takeaways

  • Connor Riley Moucka, a 26 year old Canadian, pleaded guilty on August 5, 2026 in federal court in Seattle to four counts covering computer fraud, wire fraud, aggravated identity theft and conspiracy.
  • The campaign reached at least 165 organizations that used the Snowflake cloud data platform, including AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander and LendingTree.
  • Prosecutors say the stolen files covered records belonging to at least 100 million people and included Social Security numbers, driver's licenses, passports, banking records and DEA registration numbers.
  • The group collected more than $2.5 million in ransom payments, and Moucka personally took at least $495,000 from advertising the stolen data on criminal forums. Victim losses are estimated at roughly $9.5 million.
  • Sentencing is set for October 27, 2026. The aggravated identity theft count carries a mandatory minimum of two years, and the remaining counts add up to a maximum of 30 more.

What Did Connor Moucka Plead Guilty To?

Moucka pleaded guilty to four counts: computer fraud, wire fraud, aggravated identity theft and a conspiracy charge tying them together. The Record reported the plea was entered in Washington state federal court, closing out a case that started with his arrest in Canada in November 2024 and his extradition to the United States in July 2025.

He was not working alone. Prosecutors have named accomplices in North America and at least one operator based in Turkey, John Erin Binns, who was separately charged over the intrusions. The activity ran from roughly February to October 2024, which is the window during which a long series of apparently unconnected corporate breaches were disclosed one after another.

They were connected. They all shared a platform.

How Did the Snowflake Breaches Actually Work?

Snowflake itself was never breached. This is the detail that gets lost every time the story is retold, and it is the single most important thing to understand about the case.

Snowflake is a cloud data warehouse. Companies pour their customer records into it so analysts can query them. Each customer organization holds its own tenant, protected by its own credentials. What the attackers did was collect valid usernames and passwords for those tenants, some of them years old, and simply log in.

Where did the credentials come from? Infostealer malware. When an employee or a contractor installs a cracked application or clicks the wrong download, the malware sweeps every password saved in their browser and ships the lot to a marketplace. Those dumps circulate for years. We have written before about the scale of that supply, including a 24 billion credential dump assembled entirely from infostealer logs and a 48 million Gmail logins found circulating in the same ecosystem.

The accounts that fell were the ones with no multifactor authentication and no network allowlist. A password alone was enough. One hundred and sixty five times.

Empty federal courtroom gallery with rows of polished wooden benches and morning light from tall windows

Whose Data Was Taken?

Almost certainly yours, if you live in North America and have ever bought a concert ticket or held a phone contract.

The named victims read like a list of companies most households deal with: AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, LendingTree and a large United States school district. TechCrunch reported the AT&T portion alone covered more than 100 million customers, including call and text message metadata.

The categories prosecutors listed matter more than the company names. Social Security numbers. Driver's licenses. Passports. Banking records. DEA registration numbers, which identify individual prescribers. Those are not credentials you rotate. A password can be changed in ten seconds. Your date of birth cannot.

And sitting quietly in every one of those datasets, in the column nobody itemises in the press release, is your email address.

What Happens to Your Email Address After a Breach Like This?

It becomes an entry in a targeting list, and it stays there permanently.

An email address on its own is close to worthless to a criminal. An email address joined to the fact that you are an AT&T customer, that you bought tickets to a specific show, that you hold a loan through a specific lender, is worth a great deal more. That context is what turns a generic spam blast into a message that names your bank and quotes your last four digits.

The downstream economy is already visible. Leaked address dumps now feed sextortion campaigns that quote a real password to sell the threat, and breach corpora such as the 2.7 million addresses ShinyHunters dumped from Sysco get merged, deduplicated and resold long after the original incident is forgotten.

A guilty plea does not recall any of that. The files were copied, sold and copied again while the case was still pending.

Does a Guilty Plea Change Anything for Victims?

Legally, yes. Practically, very little.

The plea establishes a record, supports restitution claims and removes one prolific operator from circulation. The mandatory two year minimum on the aggravated identity theft count means prison time is not in question, only its length, and prosecutors have flagged a ceiling of 32 years across all four counts.

What it does not do is address the structural failure. No zero day was burned here. The attackers used the front door, and the door was unlocked because dozens of large organizations left a cloud tenant full of customer records protected by a reusable password. Snowflake has since pushed multifactor authentication far harder for its customers, but the same pattern, valid stolen credentials against an account with no second factor, remains the most productive intrusion technique in use.

What Should You Do Now?

Four things, in order of how much they actually help.

  • Turn on a phishing resistant second factor everywhere that offers one. A passkey or a hardware security key beats an SMS code, because a stolen password becomes useless rather than merely inconvenient. This entire campaign existed because that step had been skipped.
  • Check your addresses against Have I Been Pwned. The AT&T and Ticketmaster datasets have been indexed. Knowing which of your accounts appear tells you which pretexts a scammer is most likely to use on you.
  • Treat any message referencing a company on that victim list as hostile until proven otherwise. Do not click through from the email. Open the company's app or type the address yourself. Attackers with breach context write very convincing mail.
  • Freeze your credit if you are in the United States. Social Security numbers and driver's license numbers were in scope. A freeze is free, reversible and blocks the most common downstream fraud.

Sentencing lands on October 27, 2026. The data does not have a release date.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.