INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Canadian Hacker Pleads Guilty to Extortion Campaign Against Snowflake
| 2026-08-06 10:15 MEDIUM LOW RANSOMWARE & EXTORTION DATA BREACH LAW ENFORCEMENT
Executive Summary
AI-generated
A Canadian cybercriminal, Connor Riley Moucka, pleaded guilty in a US court to involvement in the widespread compromise of Snowflake customer accounts, which enabled an extortion campaign. The attack began between February and October 2024, with at least 165 customers compromised, resulting in over $9.5m in actual losses for victim companies, and potentially affecting up to 100 million individual customers. Moucka used stolen login credentials to access sensitive customer records, then extorted victims by threatening to publish data online, receiving more than $2.5m in ransom payments from the campaign. The attackers advertised victims' data for sale on cybercrime forums, with Moucka personally obtaining at least $495,000 from sales.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign
MouckaCampaign
Moucka
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
October 2024
A Canadian hacker, Moucka, pleaded guilty to extortion over a Snowflake campaign that resulted in estimated losses of $9.5m for victim companies and $2.5m in ransom payments received by the hackers.
Click on any entity below to view its context and source!
financial
$2.5 Stolen / Extorted Funds
The court documents stated that the hackers received more than $2.5m in ransom payments from the campaign.
financial
$495,000 Moucka
Moucka personally obtained at least $495,000 from sales on these platforms.
July 2025
Threat actors used stolen login credentials to compromise at least 165 customers of Snowflake between February and October 2024.
Click on any entity below to view its context and source!
victims
165 customers
A Lucrative Extortion Campaign
Moucka and his co-conspirators were found to have used stolen login credentials to compromise at least 165 customers of the data warehousing provider between February and October 2024.
Tactical Metrics
Metrics
victims
165
Customers
Click for context!
A Lucrative Extortion Campaign
Moucka and his co-conspirators were found to have used stolen login credentials to compromise at least 165 customers of the data warehousing provider between February and October 2024.
Metrics
financial
2,500,000
Stolen / Extorted Funds
The court documents stated that the hackers received more than $2.5m in ransom payments from the campaign.
Metrics
financial
495,000
Moucka
Moucka personally obtained at least $495,000 from sales on these platforms.
Intelligence Sources
Infosecurity-Magazine
2026-08-06
Canadian Hacker Pleads Guilty Over Snowflake Extortion Campaign
Infosecurity-Magazine
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T08:58
Comprehensive Tactical Telemetry
Highly Correlated Entities
10x
timeline
Temporal Reference
July 2025
date
8x
organisation
Identified Entity
AT&T
entity
5x
target region
Target Country
United States
country
2x
industry
Targeted Sector
Government
sector
Contextual Telemetry
Context Block
8 METRICS
tactic
Cyber Operation Type
Extortion
tactic
source region
Origin Country
Canada
country
campaign
Campaign
Campaign
Moucka
operation
victims
Customers
165
customers
attribution
Attributing Entity
Mandiant
authority
financial
Stolen / Extorted Funds
2,500,000
$
financial
Moucka
495,000
moucka
general metric
People
100,000,000
people
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.