Canadian Man Pleads Guilty in Massive Snowflake Data Breach and Extortion Scheme
A Canadian man has pleaded guilty to his role in a large-scale data theft and extortion scheme targeting customers of cloud storage provider **Snowflake**. The breaches, which affected at least 165 organizations, led to the theft of millions of individuals' data and resulted in over $9.5 million in losses.
A significant cybersecurity case has seen 26-year-old **Connor Riley Moucka**, also known as **Alexander Moucka** and **Waifu**, plead guilty to charges related to accessing **Snowflake** customer accounts and orchestrating an extensive data extortion operation.
### The Modus Operandi
Between February and October 2024, **Moucka** and co-conspirator **John Erin Binns** exploited **Snowflake** accounts that lacked multi-factor authentication (MFA). Their method involved using login credentials previously stolen through infostealer malware.
Without MFA, threat actors could easily access customer accounts with just the correct usernames and passwords. Court documents reveal that custom software was used to identify valuable information, including organization names, user roles, and IP addresses, within the cloud storage instances.
### Extortion and Data Monetization
**Moucka** and **Binns** then proceeded to extort multiple companies after exfiltrating terabytes of data from their **Snowflake** tenant environments. They successfully obtained at least $2.5 million in Bitcoin from at least three victims.
The stolen data was comprehensive and highly sensitive, encompassing:
* Call and text history records (non-content)
* Banking and financial information
* Payroll records
* Drug Enforcement Administration (DEA) registration numbers
* Driverβs license numbers
* Passport numbers
* Social Security numbers
* Other personally identifiable information (PII)
Beyond direct extortion, **Moucka** also advertised the stolen information on various hacker forums, selling it for fiat currency or cryptocurrency and generating an additional $495,000.
### Aggravated Identity Theft and Re-Extortion
The U.S. Department of Justice (DoJ) highlighted particularly egregious acts, stating that **Moucka** re-extorted at least one victim. This re-extortion attempt involved threats of further disclosure of stolen data, specifically targeting a government officer and immediate family members of a former government officer.
The **DoJ** estimates that victim companies incurred more than $9.5 million in losses, and over 100 million individuals were impacted by these **Snowflake** attacks.
### Legal Proceedings and Consequences
**Moucka** pleaded guilty to four counts: computer fraud, wire fraud, aggravated identity theft, and a related conspiracy. He is scheduled for sentencing on October 27 and faces a maximum prison sentence of 32 years.
**Binns**, who resided in Turkey at the time of the attacks, was arrested there. While a local court approved a U.S. extradition request, it has been contested.
### Impacted Organizations and Industry Response
The list of companies affected by these breaches is extensive and includes major players such as **AT&T**, **Ticketmaster**, **Santander**, **Pure Storage**, **Advance Auto Parts**, **Los Angeles Unified**, **QuoteWizard/LendingTree**, and **Neiman Marcus**.
In response to these widespread data breaches, **Snowflake** announced it would enforce MFA protection and mandate all passwords to be at least 14 characters long, a critical step towards enhancing customer security.