1. Executive summary
Connor Riley Moucka (26, of Kitchener, Ontario) pleaded guilty on 5 August 2026 in a Washington state federal court to computer fraud, wire fraud, aggravated identity theft, and conspiracy charges stemming from the 2024 Snowflake credential-theft campaign. Between February and October 2024, Moucka and co-conspirators used stolen login credentials — some dating back to 2020 — to access at least 165 victim environments hosted on the Snowflake cloud data platform, exfiltrating billions of files and extorting victims for approximately $2.5 million in payments. High-profile victims include AT&T (call/text logs of >100 million customers), Ticketmaster (~560 million users), Santander, LendingTree, Neiman Marcus, and Advance Auto Parts. Attribution to Moucka is confirmed via guilty plea; however, no MITRE ATT&CK profile exists for this actor, and the broader crew attribution (including a Turkey-based member identified as John Erin Binns) remains unconfirmed at the group level. EMEA financial services clients with Snowflake tenants or comparable cloud-data-platform deployments should treat this as a confirmed case study in credential-based cloud compromise and extortion — not a new vulnerability.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 28: ICT third-party risk — general principles | Victims were compromised through credentials on a cloud data platform (Snowflake), a shared ICT third-party service. | Clients must verify that credential hygiene, MFA enforcement, and account-monitoring controls are applied to Snowflake and equivalent cloud-data-platform tenants as part of third-party risk management. |
| DORA Art. 18: classification of ICT-related incidents and cyber threats | The campaign resulted in major ICT-related incidents at multiple financial-sector victims (e.g., Santander), involving large-scale data exfiltration and extortion. | Clients should ensure their incident classification methodology accounts for credential-compromise-driven cloud-platform breaches and that extortion demands trigger appropriate severity tiers. |
No specific NIS2 or UK NIS article is directly engaged beyond general incident-management obligations, as the trigger facts are not distinctive to those frameworks' specific articles.
3. Technical analysis & attack chain
This is a strategic/law-enforcement item. The attack chain is reconstructed from court records and Mandiant's investigation as reported by The Record.
How the operation worked
- Credential acquisition (pre-February 2024 – ongoing): Moucka and co-conspirators obtained stolen login credentials for Snowflake customer accounts. According to Mandiant's post-incident investigation, the credentials were "still-valid" and some dated back to 2020. The credentials were not obtained through a vulnerability in Snowflake's platform — Mandiant confirmed there was no platform security issue. The credentials were likely sourced from prior infostealer infections and credential dumps, though the source does not specify the exact acquisition method.
- Account access (February – October 2024): Using the stolen credentials, the crew accessed Snowflake customer environments directly. The source does not indicate whether MFA was absent on all accounts, but the use of stolen credentials as the sole access vector implies that affected accounts either lacked MFA or had MFA bypassed/defeated. No CVE, vulnerability exploit, or platform-level compromise was involved.
- Data exfiltration: Once inside, the attackers exfiltrated billions of files across at least 165 organisations. Exfiltrated data categories included banking records, financial information, DEA registration numbers, driver's licence numbers, passport numbers, and Social Security numbers. Specific victim impacts: AT&T (call/text logs of >100 million customers), Ticketmaster (~560 million users), Santander, LendingTree, Neiman Marcus, Advance Auto Parts, and a large U.S. school district.
- Extortion: The crew extorted victim companies with threats to publish stolen data online. They earned approximately $2.5 million in ransom payments. Moucka extorted at least one victim a second time ("re-extortion"), using stolen data belonging to a government officer and that officer's family members as leverage.
- Data monetisation: Beyond extortion, Moucka earned approximately $495,000 by advertising and selling stolen data on cybercriminal forums BreachForums and XSS.is.
- Attribution and arrest: Moucka was arrested in November 2024 in Canada and extradited to the U.S. in July 2025. A co-conspirator believed to be based in Turkey was identified in court documents as John Erin Binns, who was detained by Turkish authorities in 2024 after being indicted for a separate T-Mobile hack. Moucka allegedly told 404Media before his arrest that he expected to be arrested and had been destroying evidence. Total victim losses were approximately $9.5 million.
Confidence caveat: The technical details of the attack chain are single-sourced (The Record, citing court documents and Mandiant). The credential-acquisition method is not specified in the source material. Attribution of the Turkey-based co-conspirator to John Erin Binns is drawn from court documents but the broader group composition is unconfirmed. No MITRE ATT&CK profile exists for "Connor Riley Moucka" — treat actor-level ATT&CK mapping as unavailable.
4. Mitigation & containment
This case implicates process and identity controls, not a patchable vulnerability.
P1 — within 24 hours
- Audit all Snowflake (and equivalent cloud-data-platform) accounts for MFA enforcement. Disable or require re-enrolment for any account lacking MFA. The attack chain relied on stolen credentials; MFA would have blocked the majority of access attempts.
- Review Snowflake account login history for the period February–October 2024 for anomalous access: unusual source IPs, new device fingerprints, access at atypical hours, or access from geographies inconsistent with the account owner.
P2 — within 72 hours
- Enforce credential rotation for all service accounts, integrations, and human accounts with Snowflake access. Prioritise accounts whose credentials may have been exposed in known infostealer dumps (check Have I Been Pwned, Hudson Rock, or equivalent credential-leak intelligence).
- Verify that Snowflake network policies are configured to restrict account access to known corporate IP ranges where feasible.
- Review Snowflake
LOGIN_HISTORYandSESSION_HISTORYviews for indicators of credential reuse or session hijacking.
P3 — within 7 days
- Implement Snowflake's SCIM-based SSO integration if not already in place, eliminating local credentials entirely.
- Establish a quarterly credential-leak monitoring process for all cloud-data-platform accounts.
- Review and update extortion incident-response playbooks to include re-extortion scenarios — Moucka extorted at least one victim twice, indicating that payment does not guarantee data deletion or cessation of contact.
- If the organisation was a potential victim during the February–October 2024 window and has not yet confirmed compromise, conduct a retrospective review of Snowflake access logs for that period.
5. Indicators of compromise
No atomic indicators of compromise (IPs, domains, hashes, email addresses) are available in the source material.
Behavioural indicators
| Behaviour | Where to observe | Confidence |
|---|---|---|
| Login to Snowflake account using credentials stolen from a prior breach (no MFA challenge) | Snowflake LOGIN_HISTORY view; SIEM authentication logs |
High — confirmed by Mandiant investigation |
| Bulk data export or query results exceeding normal volume from a Snowflake account | Snowflake ACCESS_HISTORY view; QUERY_HISTORY view; data egress monitoring |
High — consistent with exfiltration of billions of files |
| Sale of stolen data on BreachForums or XSS[.]is forums | Threat-intelligence monitoring of cybercriminal forums | High — confirmed in court documents |
| Extortion contact threatening publication of stolen data, followed by a second extortion demand after initial payment | Incident response communications; extortion email monitoring | Medium — confirmed for at least one victim; may not be universal |
6. Detection
Insufficient indicators to author detection rules. The source material describes behavioural patterns (credential-based access, bulk exfiltration, forum-based data sale) but does not provide specific artefacts such as file hashes, command-line strings, mutex names, registry keys, or distinctive network signatures that would support YARA or Sigma rule authoring. Clients should rely on the behavioural indicators in §5 and implement detection logic in their SIEM using Snowflake's LOGIN_HISTORY, ACCESS_HISTORY, and QUERY_HISTORY views.
7. Sources
- Recorded Future News (The Record), "Canadian man pleads guilty to Snowflake hacks that led to 165 breaches," https://therecord.media/guilty-plea-snowflake-hack-connor-riley-moucka, 5 August 2026.
8. Adverse Trace position
This is a confirmed, resolved law-enforcement matter — not an emerging threat or active vulnerability. The campaign's impact was severe (165+ victims, billions of files exfiltrated, $9.5 million in losses) but the attack vector was credential theft, not a platform vulnerability or zero-day. Snowflake's platform was not compromised. The primary lessons for EMEA financial services are operational: enforce MFA on all cloud-data-platform accounts, monitor for credential-leak exposure, and prepare for re-extortion scenarios. Attribution to Moucka is confirmed by guilty plea; group-level attribution remains unconfirmed and no MITRE ATT&CK profile exists for this actor. We will continue monitoring for any release of additional IOCs from court filings or Mandiant's investigation, and will update clients if new technical indicators emerge. No further advisory is anticipated unless new technical detail is published.
Published via PulseTrace — Adverse Trace threat intelligence.