Summary
- Connor Moucka pleaded guilty over a campaign that compromised cloud data belonging to more than 165 organisations.
- Earlier Mandiant investigations traced Snowflake customer compromises to stolen credentials rather than a breach of Snowflake's corporate environment.
- Prosecutors put direct organisational losses above $9.5 million, excluding losses suffered by affected customers.
A Canadian man has pleaded guilty over a cloud data theft and extortion campaign that compromised more than 165 organisations, bringing a criminal accountability milestone to one of the most consequential identity-driven cloud incidents of 2024.
Connor Riley Moucka, 26, pleaded guilty in the United States on 5 August to computer fraud, wire fraud, aggravated identity theft, and conspiracy offences. The US Department of Justice said Moucka and co-conspirators used stolen login credentials between February and October 2024 to access cloud-hosted data belonging to customers of a US software-as-a-service provider.
The Justice Department does not name the provider in its announcement. The case corresponds to the widely documented campaign against customer instances on Snowflake, which Mandiant tracked as UNC5537.
Mandiant and Snowflake notified approximately 165 potentially exposed organisations during the original investigation. Known affected organisations included Santander, providing a direct European link to a campaign that also affected major US companies.
According to prosecutors, the conspirators stole terabytes of data containing billions of sensitive records and then attempted to extort victim organisations or sell information through cybercrime forums. The Justice Department said the material included banking and financial records, payroll information, identity documents, and communications data.
Victim organisations suffered more than $9.5 million in actual losses, excluding losses incurred by their customers. Prosecutors said at least 100 million people were affected, while the conspirators received more than $2.5 million in ransom payments.
The criminal case adds scale and financial consequences to a technical history already established in 2024. Mandiant found no evidence that unauthorised access to the affected customer accounts originated from a breach of Snowflake’s enterprise environment. The incidents it investigated were traced to compromised customer credentials.
Those credentials had frequently been harvested earlier by information-stealing malware. Some had been exposed years before attackers used them against Snowflake, and the affected accounts in Mandiant’s investigations did not have multi-factor authentication enabled.
Network allow lists were also absent from affected customer instances, allowing valid credentials to be used from locations that could otherwise have been restricted.
The campaign therefore exposed a difficult boundary in cloud responsibility. Snowflake operated the platform, while organisations controlled identities and access policies inside their own instances. Stolen credentials remained enough to reach large datasets because stronger authentication and network restrictions were not consistently applied.
The age of some stolen credentials is equally significant. Endpoint compromise and cloud compromise can be separated by years. Malware that harvests a password from a personal or contractor device may disappear long before the credential is assembled into an access broker’s dataset and used against a corporate SaaS service.
That weakens incident models that treat an infostealer infection as a contained endpoint problem once the infected device is rebuilt. Credentials, browser sessions, tokens, and other identity material can retain value independently from the malware that originally collected them.
Snowflake has since strengthened authentication requirements, including measures intended to move human users away from single-factor password access. The changes reduce the specific conditions that helped the 2024 campaign scale, although cloud identity remains dependent on enrolment, recovery, service accounts, and the security of connected endpoints.
Moucka is due to be sentenced on 27 October. The aggravated identity-theft offence carries a mandatory two-year sentence, while the remaining offences carry substantial additional maximum terms.
The guilty plea does not alter the technical cause of the customer compromises. It provides a legal outcome and a clearer accounting of their consequences: previously stolen identities were sufficient to turn access to individual cloud tenants into a campaign affecting more than 165 organisations.



