Major Snowflake Extortion Campaign Dismantled: Canadian Threat Actor Pleads Guilty After Compromising 165+ Organisations
Connor Riley Moucka, a 26-year-old Canadian, pleaded guilty to orchestrating extortion attacks against over 165 organisations using Snowflake, and to stealing call and text records from more than 100 million AT&T customers. The resolution of this significant 2024 threat actor marks the operational conclusion of one of the year's most impactful data theft campaigns.
Affected
Connor Riley Moucka's guilty plea represents the formal closure of one of 2024's most consequential threat campaigns. The scale is notable: 165+ organisations using a single cloud platform (Snowflake) were simultaneously targeted for extortion, alongside the compromise of telecommunications metadata spanning over 100 million AT&T customers. This dual targeting suggests a sophisticated, multi-vector operation that exploited both commercial cloud weaknesses and carrier infrastructure vulnerabilities.
The campaign's success against Snowflake customers likely stemmed from a combination of weak credential management, inadequate secrets rotation, and insufficient detection of suspicious API usage patterns on the Snowflake platform. The AT&T telephony records theft indicates either compromised employee credentials or insider involvement at the carrier level. Moucka's characterisation as "one of the most consequential cybercrime threat actors of 2024" reflects the operational impact and scale of theft rather than novel techniques; the extortion model itself is conventional, but execution across so many targets simultaneously represents significant operational maturity.
For organisations reliant on Snowflake and other cloud data platforms, this case continued risk posed by credential compromise and the necessity of implementing strong multi-factor authentication, IP whitelisting, session monitoring, and alerts on unusual query patterns. The AT&T breach component raises questions about telecommunications carrier security posture and whether insider threat controls were adequate. The fact that a single actor or small group achieved this scale suggests either poor cross-organisational information sharing about compromised credentials, or insufficient real-time threat hunting in victim environments.
The guilty plea signals successful law enforcement investigation and prosecution, which should deter similar large-scale campaigns. However, the extortion-as-a-service model remains profitable and this case does not indicate whether Moucka was working independently, in collaboration with others, or as a contractor for a larger criminal enterprise. Attribution to specific nation-states or organised crime groups is not provided in the available information. Cloud platform operators must treat this as a watershed moment for implementing stronger default security controls, particularly around credential validation and anomaly detection in data query patterns.
Sources