Interestana
Home/News/Canadian Man Pleads Guilty in Massive Snowflake Data Extortion Scheme
Krebs on Security5 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Canadian Man Pleads Guilty in Massive Snowflake Data Extortion Scheme

Canadian Man Pleads Guilty in Massive Snowflake Data Extortion Scheme

Connor Riley Moucka, a 26-year-old Canadian national from Kitchener, Ontario, has pleaded guilty to federal charges of computer fraud and conspiracy. These charges are directly linked to his significant role in a sophisticated cybercrime operation that compromised and extorted over 165 organizations utilizing the cloud data storage services of Snowflake Inc. In addition to the Snowflake-related offenses, Moucka also admitted to unlawfully accessing and stealing the call and text history records of more than 100 million customers of AT&T, one of the largest telecommunications companies in the United States. A surveillance photograph of Moucka, dated October 21, 2024, nine days before his arrest, was presented as evidence in an affidavit filed by an investigator with the Royal Canadian Mounted Police (RCMP). This image captured Moucka, who was known to operate under various aliases, including "Judische" and "Waifu."

The U.S. Department of Justice detailed that between February and October 2024, Moucka and his co-conspirators systematically exploited stolen login credentials to gain unauthorized access to cloud-hosted data. Their primary targets were at least 165 customers of Snowflake, a prominent U.S.-based software-as-a-service (SaaS) company that provides cloud data warehousing solutions. The attackers specifically focused on compromising Snowflake customer accounts where multi-factor authentication (MFA), a critical security layer designed to verify user identity, was not enforced. By bypassing this essential security control, the cybercriminals were able to steal sensitive data and subsequently extort or attempt to extort a range of high-profile companies. Notable victims of this scheme included Ticketmaster, a global leader in ticketing, Lending Tree, an online marketplace for financial services, Advance Auto Parts, a major automotive aftermarket parts retailer, and Neiman Marcus, a luxury department store chain. In the wake of these widespread security incidents, Snowflake implemented enhanced security measures, including increasing password complexity requirements and mandating multi-factor authentication across its platform to bolster customer data protection.

Moucka was characterized by his frequent adoption of new online nicknames, often managing multiple identities concurrently to evade detection. "Judische" and "Waifu" were among his most recognized and frequently used monikers. His involvement in the Snowflake data breaches was first brought to public attention by KrebsOnSecurity, a reputable cybersecurity news outlet, in a September 2024 report. This investigative piece highlighted a disturbing overlap between Western, English-speaking cybercriminals and extremist groups that engage in the harassment and extortion of minors. The September 2024 article specifically identified "Judische" as a software engineer based in Ontario who had been implicated in a series of data breaches and voice phishing attacks targeting U.S. companies since at least 2020. Approximately one month after the publication of this report, Canadian authorities successfully arrested Moucka based on a provisional warrant, marking a significant development in the ongoing efforts to prosecute individuals involved in sophisticated cybercrime targeting cloud infrastructure and sensitive customer data.

Original source — read the full reporting at the publisher:

Read on Krebs on Security

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next