Canadian hacker pleads guilty in Snowflake data breach case, stealing data and extorting people for millions | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Listen to this article

Estimated 3 minutes

The audio version of this article is generated by AI-based technology. Mispronunciations can occur. We are working with our partners to continually review and improve the results.

A Canadian man has pleaded guilty to his role in the widespread hacking case known as the Snowflake data breach, in which information was stolen from 165 organizations and victims were extorted for millions of dollars.

Connor Moucka, 26, of Kitchener, Ont., pleaded guilty Wednesday in U.S. District Court for the Western District of Washington to four charges: computer fraud, wire fraud, aggravated identity theft and a related conspiracy.

He is scheduled to be sentenced Oct. 27. The aggravated identity theft count carries a mandatory minimum sentence of two years in prison, while the remaining counts carry a maximum penalty of 30 years.

“Today’s guilty plea serves as a reminder to all cybercriminals, regardless of where they live, that they cannot hide behind a wall of anonymity. You will be found and brought to justice,” assistant attorney general A. Tysen Duva of the U.S. Department of Justice’s Criminal Division said in a release Wednesday.

2024 breach

In 2024, Moucka and his co-conspirators accessed the cloud storage of Snowflake Inc. customers — including telecommunications company AT&T, Live Nation’s Ticketmaster and Santander Bank.

Another man, John Erin Binns, was charged in the case in April 2025.

WATCH | Ticketmaster says customer contact and payment data was exposed in 2024 breach:

Ticketmaster says customers’ personal information affected by data breach

In an email to customers, Ticketmaster said an ‘unauthorized third party’ obtained customers’ personal information — including names, basic contact information and payment card information — in a ‘data security incident’ between April 2 and May 18. The email says Ticketmaster is investigating and co-operating with U.S. federal law enforcement authorities.

The U.S Department of Justice said Moucka “obtained extremely sensitive information and extorted the victims for millions of dollars” between February and October 2024.

Moucka was arrested at a Kitchener home on Oct. 30, 2024.

A plea agreement filed Wednesday says Moucka and his co-conspirators profited in several ways, including by extorting 36 bitcoin, worth about $2.5 million US at the time, from at least three victims.

In other cases, they offered to sell stolen data on cybercriminal forums and sought at least $6 million US for the information.

Moucka “personally profited from this scheme by receiving at least $495,000 USD in bitcoin (as measured at the time of payment),” the court document says.

Moucka also developed a computer program that automated the process of identifying valuable information, including names, roles, IP addresses and banking details. 

The hackers used that information to determine who “likely had valuable data worth exfiltrating so they could extort the victims or sell stolen data on cybercriminal forums.”

WATCH | Cybersecurity expert shares 3 steps for those affected by data breach:

Caught in a data breach? 3 tips for what to do next

Cybersecurity expert Robert Falzon, Canadian head of engineering at Check Point Software Technologies, shares his top three tips of what students and staff impacted by the Canvas cyber incident should be doing next.

“In total, [Moucka] and his co-conspirators caused the victim companies more than $9.5 million in actual losses, which included ransoms paid and costs of responding to the breaches,” the plea agreement said.

Moucka used several aliases to conceal his identity, including Alexander Moucka, judische, catist, ellyel8 and waifu.

FBI Cyber Division assistant director Brett Leatherman said Moucka learned that “hiding behind a screen is no shield from justice.”

Leatherman said Moucka’s arrest and subsequent guilty plea also highlight the FBI’s “commitment to protecting American businesses and consumers from cybercrime and reflects our strong partnership with the Royal Canadian Mounted Police and other international law enforcement agencies.”

The Australian Federal Police, Spain’s Guardia Civil, the Security Service of Ukraine and the Turkish National Police were also involved in the case.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW