Hacker Linked to Ticketmaster Snowflake Breach Pleads Guilty in 165-Company Attack | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Ticketmaster logo over a dark background with simulated computer code in green text.

A Canadian hacker tied to the sprawling 2024 cyberattack campaign that included the massive Ticketmaster data breach has pleaded guilty to four federal charges, admitting his role in the theft of billions of sensitive records and an extortion scheme that collected millions of dollars from victim companies.

Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty Aug. 5 to computer fraud, wire fraud, aggravated identity theft and a related conspiracy, according to the U.S. Department of Justice. He is scheduled to be sentenced Oct. 27.

The plea marks a significant development in a hacking campaign that first drew widespread attention in the ticketing industry after data associated with hundreds of millions of Ticketmaster customers was offered for sale online in 2024.

According to prosecutors, Moucka and his co-conspirators used stolen login credentials between February and October 2024 to gain unauthorized access to cloud-hosted data belonging to at least 165 customers of a U.S.-based software-as-a-service company. The Justice Department does not name the cloud provider in its latest announcement, but the campaign has previously been identified as targeting customer accounts hosted by Snowflake.

That distinction has been a point of contention since the Ticketmaster breach first surfaced. Snowflake said in June 2024 that investigators had found no evidence that a vulnerability or security failure within its underlying platform caused the attacks. Instead, investigators said attackers appeared to be using credentials obtained elsewhere to target accounts that lacked multi-factor authentication.

Prosecutors now say the group used that access to steal terabytes of data containing billions of records, including financial information, payroll records, driver’s license and passport numbers, Social Security numbers, call and text-history records and other personally identifiable information.

The attackers then threatened to publish stolen information unless victims paid ransoms and separately advertised data for sale on cybercrime forums and Telegram, according to DOJ.

The conspiracy generated more than $2.5 million in ransom payments, with Moucka personally receiving at least $495,000, prosecutors said. DOJ puts the direct losses suffered by victim companies at more than $9.5 million, excluding losses suffered by their customers. Prosecutors said the affected companies collectively had at least 100 million individual customers whose information was implicated in the conduct admitted as part of the case.

Ticketmaster Breach Put Snowflake Campaign in Spotlight

TicketNews began covering the Snowflake attacks in May and June 2024 after hackers advertised a massive cache of data purportedly taken from Ticketmaster.

At the time, the group ShinyHunters claimed to possess approximately 1.3 terabytes of Ticketmaster data associated with as many as 560 million customers worldwide, including names, addresses, phone numbers, payment information and other account data. Live Nation Entertainment subsequently confirmed in an SEC filing that it had identified unauthorized activity in a third-party cloud database containing Ticketmaster data on May 20, although the company did not independently confirm all of the hackers’ claims about the scope of the stolen material.

Ticketmaster later notified affected customers that it had determined an unauthorized third party obtained information from a database hosted by a third-party data services provider. The company said its investigation placed the unauthorized activity between April 2 and May 18, 2024.

As the breach unfolded, hackers made additional claims involving Ticketmaster ticket inventory and barcodes, including assertions that they possessed hundreds of thousands of Taylor Swift tickets. Ticketmaster disputed some of those claims and said its rotating SafeTix barcodes could not simply be copied and reused.

The criminal investigation eventually put names to individuals prosecutors said were behind the broader Snowflake campaign.

Canadian authorities arrested Moucka in October 2024 at the request of the United States. He and alleged co-conspirator John Erin Binns were subsequently indicted in the Western District of Washington on charges involving computer fraud, wire fraud, aggravated identity theft and related conspiracies.

Moucka initially fought the U.S. case from Canada before consenting to surrender for extradition in March 2025. DOJ says he was extradited to the United States in July 2025, where he initially pleaded not guilty before changing his plea this month.

His guilty plea carries a mandatory minimum sentence of two years on the aggravated identity theft charge, while the remaining counts carry maximum penalties of up to 30 years in prison. The eventual sentence will be determined by a federal judge under federal sentencing guidelines.

The case is not entirely finished. Binns, Moucka’s co-defendant, is not currently in U.S. custody, according to the Justice Department’s case docket.



Click Here For The Original Source.

——————————————————–

..........

.

.