Protect.Computer
NEWS

Canadian Hacker Pleads Guilty to Snowflake Data-Theft Attacks

· 2 min read · Data hijack
Canadian Hacker Pleads Guilty to Snowflake Data-Theft Attacks

A Canadian man known online as “Waifu” has pleaded guilty to one of the most damaging data-theft sprees in recent memory. Connor Riley Moucka, 26, was arrested in Canada in October 2024 and has now admitted to breaking into cloud storage accounts at Snowflake — a platform used by thousands of large companies to store data — at 165 organizations between February and October 2024. The U.S. Department of Justice says victims suffered more than $9.5 million in losses and that more than 100 million individuals had their personal data exposed as a result of the attacks.

The method was straightforward and devastatingly effective: Moucka and his co-conspirator John Erin Binns obtained usernames and passwords for Snowflake corporate accounts through infostealer malware — software that silently harvests browser-saved credentials from infected computers. Because many of the targeted Snowflake tenants had no multi-factor authentication enabled, those stolen passwords were all Moucka needed to log straight in. Once inside, custom software automatically scanned the cloud environments for high-value data — employee records, customer databases, payment details — which was then used to extort companies. The DOJ says Moucka obtained at least $2.5 million in bitcoin from three extortion victims and another $495,000 by selling stolen data on criminal forums. In at least one case he re-extorted a victim a second time, threatening further exposure, and used stolen data tied to a government official’s family members to apply pressure. Among the companies breached were Ticketmaster and AT&T, whose exposure of nearly all customer call records made headlines in 2024.

How to check if you’re affected

Affected products include any corporate Snowflake tenant. If your organization uses Snowflake, log into the Snowflake console and review the Account > Login History and Sessions pages for logins from unfamiliar IP addresses or regions, particularly from late 2024. Enable multi-factor authentication on all Snowflake accounts if it is not already active — Snowflake made MFA mandatory for human users in November 2024, but service accounts created before that change may still be unprotected. Individuals who had data at Ticketmaster or AT&T during 2024 may have received breach notification letters; monitor your credit reports and consider a credit freeze if you received one.

Sources

Related reading