SEATTLE, Aug. 6, 2026 - Canadian national Connor Riley Moucka has pleaded guilty in U.S. federal court to charges arising from a large data-theft and extortion campaign that compromised customer environments hosted on the Snowflake cloud platform.
Moucka, 26, entered the plea on Wednesday in the Western District of Washington to offences reported as including computer fraud, wire fraud, aggravated identity theft and conspiracy. He is scheduled to be sentenced on Oct. 27 and faces a potential maximum measured in decades, with reports placing the combined exposure at up to 32 years. The actual sentence will be determined under federal law and sentencing guidelines, not by adding statutory maximums as if they were automatic.
Prosecutors say the campaign accessed data belonging to at least 165 organisations and used the threat of publication to demand money. The stolen information affected major companies and, indirectly, large numbers of customers. Moucka was accused of helping obtain and transfer data, communicate with victims and profit from extortion. His guilty plea is an admission of his own criminal conduct; it does not by itself determine the guilt of every alleged co-conspirator.
The phrase "Snowflake breach" can be misleading. Mandiant and Snowflake said they found no evidence that attackers exploited a vulnerability in Snowflake's production environment or broke into the company's central network. The campaign targeted customer accounts using valid usernames and passwords that had been stolen previously, often by infostealer malware on computers outside Snowflake.
Three conditions appeared repeatedly in affected environments: credentials exposed by malware were still active, multifactor authentication was not enabled, and network policies did not limit logins to trusted locations. With a valid password and no second factor, an attacker could appear to the cloud service as an authorised user. The intruder could then query or export data using tools that may resemble legitimate administrative activity.
That does not mean the incident was simply the customer's fault. Cloud security follows a shared-responsibility model. Customers control identities, access rights and much of their data configuration, while providers design defaults, logging, authentication options and alerts. If a secure feature is available but difficult to enforce across an organisation, adoption may remain weak. Providers can reduce risk by making phishing-resistant MFA standard, flagging impossible travel, limiting legacy authentication and helping administrators identify dormant credentials.
Infostealer malware is the first link in many such attacks. It can capture browser-stored passwords, authentication cookies and files from an infected laptop. Credentials may sit in criminal markets for years and remain useful if a company never rotates them. Defenders should therefore treat an infected endpoint as an identity breach, revoke sessions, reset exposed secrets and search for access across every service used by that person - not merely clean the device.
The case also shows why data warehouses are attractive extortion targets. They centralise customer, transaction and operational information for analysis. A single over-privileged account can reach far more data than the employee needs for daily work. Least-privilege roles, short-lived credentials, network restrictions, query monitoring and limits on bulk export can reduce the impact even after an account is compromised.
Incident response should focus on evidence and affected people. Organisations need to preserve login history, query logs and file-transfer records, determine exactly which tables were accessed and notify regulators and individuals under applicable law. Paying an extortion demand does not guarantee deletion. A criminal may retain copies, sell them later or use them for fraud, so recovery must assume the data is permanently exposed.
The guilty plea is important for deterrence because cross-border cybercrime often appears consequence-free. Moucka was arrested in Canada and brought into the U.S. legal process, demonstrating cooperation between jurisdictions. Still, one conviction will not dismantle the market for stolen credentials. Reducing opportunity through stronger identity controls is more reliable than expecting arrests after data has been copied.
At sentencing, the court can consider the scale of loss, number of victims, identity-theft conduct, cooperation and Moucka's individual role. Maximum penalties describe legal exposure, not a prediction. Victim organisations may submit impact information, but claims about the number of affected people should distinguish records copied from people who suffered measurable fraud. The court record, rather than promotional statements by security vendors, will be the best source for the criminal conduct admitted and any restitution order.
For executives, the practical lesson is specific: identify every cloud account without MFA, rotate credentials exposed in historic infostealer collections, remove inactive users, restrict access by role and network, and alert on unusually large queries or downloads. Boards should ask for measurable closure dates rather than accept a general statement that MFA is "available."
The accurate headline is therefore not that a hacker broke Snowflake itself. Moucka admitted participating in attacks on Snowflake customer accounts and an extortion campaign built on stolen credentials and weak identity controls. That distinction assigns the technical failure correctly and points directly to the safeguards that could prevent the next incident.


