Connor Riley Moucka, a 26-year-old resident of Kitchener, Ontario, has entered a guilty plea regarding his role in a large-scale cybercrime conspiracy. According to Security Affairs, the defendant admitted to compromising at least 165 organizations between February and October 2024. The U.S. Department of Justice (DOJ) confirmed that the operation involved the theft of billions of sensitive records from clients of a major U.S.-based software-as-a-service provider, identified as the cloud data platform Snowflake.
Moucka’s illicit activities relied on the exploitation of stolen login credentials, specifically targeting accounts that lacked multi-factor authentication (MFA). By bypassing these basic security controls, the conspirators gained unauthorized access to internal systems, enabling them to exfiltrate terabytes of data. This stolen information included personally identifiable information (PII) such as Social Security numbers, passport details, driver’s license data, payroll documents, and Drug Enforcement Administration (DEA) registration numbers. Financial and banking records were also targeted during the campaign.
Incident Impact Summary
| Metric | Figure |
|---|---|
| Organizations Compromised | 165+ |
| Individuals Affected | 100 million+ |
| Total Extortion Proceeds | > $2.5 million |
| Direct Losses to Victims | > $9.5 million |
| Personal Gain for Moucka | $495,000 |
Following the data theft, the group engaged in systematic extortion, threatening to release the sensitive information publicly unless ransom demands were met. In specific instances, the hackers intensified their pressure by using stolen data belonging to government officials and their family members. Beyond extortion, the conspirators sold datasets on various cybercrime forums and platforms, including Telegram.
Moucka now faces charges including computer fraud, wire fraud, conspiracy, and identity theft. He faces a potential sentence of up to 30 years in prison for his role in the operation.
Why It Matters
The Snowflake breach highlights a recurring failure in corporate cybersecurity architecture: the continued reliance on single-factor authentication. By failing to enforce MFA, organizations created a wide attack surface that a single threat actor could leverage for mass-scale exfiltration. The move toward 're-extortion'—a tactic where hackers demand payment even after initial compliance—signals a maturing, albeit criminal, business model. This case underscores that data privacy is no longer merely a compliance box-checking exercise but a survival requirement for cloud-native enterprises that host the world’s most sensitive administrative and financial records.

Reader Discussion & Insights