Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Ekurhuleni killings: Grim discoveries of murdered women spark fear in South Africa

    September 20, 2026

    Feeling ‘forced out’ by Badenoch? Lib Dems conference welcomes young Tory defectors | Liberal Democrat conference

    September 20, 2026

    Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems

    September 20, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Ekurhuleni killings: Grim discoveries of murdered women spark fear in South Africa
    • Feeling ‘forced out’ by Badenoch? Lib Dems conference welcomes young Tory defectors | Liberal Democrat conference
    • Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems
    • Why Legendary Investor Bill Miller IV Has “Never Been More Bullish On Bitcoin”
    • New nanoparticles make hidden chemical differences light up
    • Trump ramps up feud with press after week of setbacks
    • German state elections: Chancellor Friedrich Merz vows to stay on despite ‘disaster’ in polls
    • Lib Dems use conference to set out £2bn plan to cut fuel duty | Liberal Democrats
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, September 20
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Canadian pleads guilty to Snowflake cloud data-theft attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 6, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims.

    ​26-year-old Connor Riley Moucka, also known as Alexander Moucka and Waifu, was arrested on October 30, 2024, for stealing data of hundreds of millions of individuals from companies using Snowflake’s storage service.

    Between February and October 2024, Moucka and John Erin Binns, also indicted for these attacks, accessed Snowflake accounts not protected by multi-factor authentication (MFA) using logins stolen via infostealer malware.

    image

    Without MFA enabled, the threat actor needed only the correct usernames and passwords to log into customer accounts.

    According to court documents, the unauthorized access was used to identify valuable information (e.g., organization name, user roles, IP addresses) in cloud storage instances using custom software.

    Moucka and Binn tried to extort multiple companies after stealing terabytes of data from their Snowflake tenant environments and obtained at least $2.5 million in bitcoin from at least three victims.

    The following information was stolen from the breached accounts:

    • Call and text history records (non-content)
    • Banking and financial information
    • Payroll records
    • Drug Enforcement Administration (DEA) registration numbers
    • Driver’s license numbers
    • Passport numbers
    • Social Security numbers
    • Other personally identifiable information (PII)

    They also advertised on various hacker forums to sell the information for fiat currency or cryptocurrency, and Moucka obtained at least $ 495,000 this way.

    In a press release today, the U.S. Department of Justice says that “in at least one instance, Moucka re-extorted a victim with threats of further disclosure of the victim’s stolen data.”

    “Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt.”

    The DoJ says that victim companies suffered more than $9.5 million in losses and more than 100 million individuals have been affected by the Snowflake attacks.

     

    Moucka pleaded guilty to four counts of the indictment (computer fraud, wire fraud, aggravated identity theft, and a related conspiracy) and is scheduled for sentencing on October 27.

    He faces a maximum sentence of 32 years in prison.

    At the time of the attacks, Binns resided in Turkey, where he was arrested. A local court approved an extradition request from U.S. prosecutors but it was contested.

    The list of impacted companies includes AT&T, Ticketmaster, Santander, Pure Storage, Advance Auto Parts, Los Angeles Unified, QuoteWizard/LendingTree, and Neiman Marcus.

    Following these data breaches, Snowflake announced it would enforce MFA protection and require all passwords to be at least 14 characters long.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    attacks Canadian cloud datatheft guilty pleads Snowflake
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Malicious npm packages evade install-script defenses at runtime

    Researchers escape OpenAI Codex sandbox to run commands on host

    Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

    Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

    CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

    SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Ekurhuleni killings: Grim discoveries of murdered women spark fear in South Africa

    September 20, 2026

    Feeling ‘forced out’ by Badenoch? Lib Dems conference welcomes young Tory defectors | Liberal Democrat conference

    September 20, 2026

    Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems

    September 20, 2026

    Why Legendary Investor Bill Miller IV Has “Never Been More Bullish On Bitcoin”

    September 20, 2026
    Latest Posts

    Primary Elections Live Updates: Race Too Close to Call in Democratic Primary for Michigan Senate Seat

    August 5, 2026

    Europe has the defense budget. The test now is delivery. – POLITICO

    August 5, 2026

    As Spain grieves, recurrent heatwaves stir fears of more wildfires | Weather News

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Ekurhuleni killings: Grim discoveries of murdered women spark fear in South Africa

    September 20, 2026

    Feeling ‘forced out’ by Badenoch? Lib Dems conference welcomes young Tory defectors | Liberal Democrat conference

    September 20, 2026

    Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems

    September 20, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.