READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Canadian Hacker Pleads Guilty to Breaching 165+ Companies Through Snowflake, Including AT&T and Ticketmaster

Canadian Hacker Pleads Guilty to Breaching 165+ Companies Through Snowflake, Including AT&T and Ticketmaster
Connor Moucka, 26, pled guilty this week to hacking more than 165 companies by exploiting weak security on customer accounts tied to cloud provider Snowflake. He and his accomplices extorted victims for $2.5 million and caused $9.5 million in losses, according to the Department of Justice. He faces sentencing on October 27 and decades in prison.

A 26-year-old Canadian citizen has pled guilty to one of the largest corporate data-theft campaigns in recent memory. Connor Moucka admitted to hacking more than 165 companies by exploiting customer accounts on Snowflake, a major cloud data-storage provider, according to a Department of Justice press release issued Wednesday.

Moucka, who went by the online handles "Waifu" and "Judische," and his co-conspirators didn't breach Snowflake's own systems. They broke into individual customer accounts, according to the DOJ. That gave them access to troves of sensitive data sitting in the cloud.

The victim list is a corporate who's-who. AT&T, LendingTree, and Ticketmaster were among the companies hit, according to the DOJ. Moucka personally stole records from more than 100 million AT&T customers, including call and text logs, banking details, driver's license numbers, and Social Security numbers pulled from other breaches.

The Money

Moucka and his accomplices collected more than $2.5 million in ransom payments from victims over the course of the scheme, according to the DOJ. He personally pocketed roughly $500,000 more by selling stolen data on hacking forums, including the notorious marketplace BreachForums.

The DOJ says total victim losses hit $9.5 million.

FBI Special Agent W. Mike Herrington, who worked the case, didn't mince words. "Connor Moucka's threats and re-extortion tactics were calculated and predatory, and his actions did real harm to his victims, be they companies targeted for theft and extortion or the millions of everyday people who are their customers," Herrington said in the DOJ statement.

"Re-extortion" is significant in that sentence. According to the DOJ, this points to Moucka and his accomplices' pattern of extortion tactics against victims.

Timeline

Moucka was arrested in Canada at the end of 2024, just months after the Snowflake breaches, according to the DOJ. Austin Larsen, a senior researcher at Google's cybersecurity firm Mandiant, who investigated the breaches at the time, called Moucka "one of the most consequential" hackers of 2024.

Moucka is now scheduled for sentencing on October 27 and faces decades in prison, according to the DOJ.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
TechCrunchHacker pleads guilty to stealing data from more than 165 Snowflake customers