Skip to main content

Canadian Threat Actor Pleads Guilty in Snowflake Extortions

3 min read Runtime Rebel Intel
Primary source: krebsonsecurity.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Immediate impact: Over 165 organizations suffered major data thefts and subsequent extortions following cloud credential compromise.
  • Affected systems: Snowflake cloud customer accounts lacking mandatory multi-factor authentication and AT&T customer records.
  • Remediation: Enforce robust multi-factor authentication across all cloud accounts and eliminate reliance on single-factor authentication.

Advertisement

Overview of the Snowflake Extortion Case

A 26-year-old Canadian national has entered a guilty plea to federal charges stemming from a massive campaign targeting cloud-hosted environments. According to KrebsOnSecurity, Connor Riley Moucka—previously known online by monikers such as “Judische” and “Waifu”—admitted to computer fraud, wire fraud, aggravated identity theft, and conspiracy. The campaign compromised data belonging to more than 165 organizations utilizing the cloud provider Snowflake.

The admissions outline a multi-month operation spanning from February to October 2024. During this timeframe, the threat actors leveraged stolen login credentials to access cloud storage environments, exfiltrating terabytes of sensitive files and subsequently demanding ransom payments under threat of public data exposure.

Technical Details and Attack Methodology

The primary attack vector relied on harvesting valid user credentials rather than exploiting complex software zero-days. Attackers specifically hunted for enterprise accounts belonging to Snowflake customers that failed to enforce multi-factor authentication. By utilizing these exposed credentials, the conspirators accessed environments belonging to prominent brand names, including Ticketmaster, Advance Auto Parts, LendingTree, and Neiman Marcus.

Scope of Stolen Data

The operation resulted in the theft of billions of sensitive records containing:

  • Non-content call and text history records impacting over 100 million AT&T customers
  • Banking and financial account details
  • Personally identifiable information including passport numbers, driver’s licenses, and social security numbers
  • Drug Enforcement Administration (DEA) registration numbers

The Department of Justice noted that the conspirators amassed over $2.5 million in ransom payments. In certain instances, the threat actors engaged in re-extortion, leveraging stolen data belonging to government officials and their family members to pressure victims further.

Co-Conspirators and Global Reach

Investigators identified multiple individuals operating alongside Moucka:

  • Cameron Wagenius, operating as “Kiberphant0m,” a U.S. Army soldier who admitted to extorting telecommunication providers and leaking high-profile call logs. Wagenius is scheduled for sentencing in September 2026.
  • John Erin Binns, known as “IRDev” and “IntelSecrets,” an American fugitive indicted for a prior breach at T-Mobile. Sources indicate Binns acquired Turkish citizenship to evade foreign extradition.

Moucka’s sentencing is scheduled for October 27, where he faces mandatory minimum penalties for aggravated identity theft alongside potential decades-long imprisonment for remaining counts.

Actionable Recommendations

Security teams managing cloud environments must prioritize foundational hygiene controls to prevent credential-based intrusions:

  • Mandate Multi-Factor Authentication: Enforce phishing-resistant multi-factor authentication across all administrative and user accounts without exception.
  • Credential Monitoring: Implement continuous monitoring for exposed corporate credentials on dark web forums and underground messaging channels.
  • Access Governance: Apply the principle of least privilege to cloud data storage, ensuring that downstream systems only retain access to necessary operational data.

Related: Snowflake Hacker Pleads Guilty: Analyzing the UNC5537 Data Breach, Smoke#Screen RMM Takeover Campaign Targets Enterprise Networks

Advertisement

Advertisement