Canadian Cyber Security Journal
SOCIAL:
Filed under: Featured, News

Ontario Man Pleads Guilty to Snowflake Data-Theft Campaign That Hit 165 Companies

What Happened

Connor Riley Moucka, a 26-year-old from Kitchener, Ontario, pleaded guilty on August 5 in U.S. District Court for the Western District of Washington. He entered guilty pleas on four counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy to commit those offences.

Moucka and at least one co-conspirator obtained bulk batches of stolen credentials sourced from infostealer malware. They used those credentials to access Snowflake customer accounts where multi-factor authentication was not enforced — a configuration gap Snowflake’s own post-incident review identified as the primary enabler of the campaign. At least 165 Snowflake customers were breached, including AT&T, Ticketmaster, LendingTree, and Advance Auto Parts. The attackers then extorted victims, demanding payment to withhold or delete the stolen data. The campaign generated more than $2.5 million in ransom payments.

Moucka was arrested in Canada in October 2024 following a joint law enforcement investigation involving Canada, Australia, Spain, Ukraine, and Turkey. He was extradited to the United States in July 2025. Sentencing is scheduled for October 27. The aggravated identity theft count carries a mandatory minimum of two years; the remaining counts carry a combined maximum of 30 years.

Why This Matters for Canadian Organizations

This case carries two distinct lessons for Canadian security teams.

The first is domestic. The attacker was Canadian. His arrest required international coordination, extradition, and a U.S. prosecution. The RCMP participated in the takedown. Canadian citizens face prosecution under both Canadian and U.S. cybercrime law when they target organizations abroad — and increasingly, those prosecutions succeed. This signals that domestic threat actors are a credible risk category, not an abstraction.

The second is operational. The Snowflake campaign worked because cloud data warehouse accounts lacked mandatory MFA. Infostealer credentials are bought and sold freely on criminal marketplaces. Any Canadian organization storing sensitive data in Snowflake, Databricks, BigQuery, or similar platforms faces identical exposure if credential governance is weak. Under PIPEDA and provincial privacy statutes, a breach affecting Canadian residents triggers mandatory notification to the Office of the Privacy Commissioner. A breach of this scale affecting Canadian employees, customers, or citizens creates significant regulatory and legal exposure.

OSFI’s B-13 guideline requires federally regulated financial institutions to manage technology and cyber risk, including risks arising from the use of third-party cloud platforms. The absence of MFA on a cloud data warehouse holding regulated data would represent a gap in that risk management framework.

What to Do

Review all cloud data warehouse accounts — Snowflake, Databricks, BigQuery, Redshift — and confirm MFA is enforced at the account level, not left optional. Rotate any service account credentials shared with third-party analytics, BI, or ETL tools. Implement Snowflake network policies restricting access by IP range where operationally feasible. Review your infostealer exposure by checking whether any corporate credentials appear in known breach data sets through your threat intelligence provider. If your organization was among the 165 affected Snowflake customers, confirm breach notification obligations under PIPEDA have been met. Report any relevant incidents to the Canadian Centre for Cyber Security at cyber.gc.ca.

Source: BleepingComputer

Enjoy this article? Don’t forget to share.