Defendant Pleads Guilty to Role in Snowflake Account Intrusion Campaign

Connor Riley Moucka has pleaded guilty in a US federal court for his alleged role in a cybercrime operation that compromised Snowflake data-storage accounts belonging to 165 organizations.The 26-year-...

Connor Riley Moucka has pleaded guilty in a US federal court for his alleged role in a cybercrime operation that compromised Snowflake data-storage accounts belonging to 165 organizations.

The 26-year-old admitted to computer fraud, wire fraud, aggravated identity theft and a related conspiracy, according to the US Department of Justice. He faces a potential prison sentence of more than 30 years. A sentencing hearing is scheduled for October 27.

Moucka was arrested in Canada in late 2024 and extradited to the United States in July 2025. Early reports identified him as Alexander “Connor” Moucka.

Credentials used to access Snowflake accounts

Authorities say Moucka and other members of the group used stolen credentials to enter Snowflake environments and extract information stored by victims. The activity has been linked to the threat actor known as UNC5537.

Organizations identified as victims or targets include AT&T, Advance Auto Parts, Ticketmaster, Santander Bank, Neiman Marcus, Anheuser-Busch, Allstate, Mitsubishi, Progressive and State Farm. Investigators say the attackers obtained billions of records containing personal and financial information, then attempted to profit through extortion and the sale of data on criminal forums.

The Justice Department said the group collected approximately $2.5 million in ransom payments. Moucka allegedly received about $500,000 from selling stolen information. Reported losses to the affected companies exceed $9.5 million, excluding potential harm to customers. Authorities estimate that at least 100 million people may have been affected.

A former US service member who pleaded guilty approximately a year earlier in a separate case involving intrusions into AT&T and Verizon systems is also suspected of having participated in the Snowflake-related activity.

The case highlights the risks posed by exposed or reused credentials, particularly where cloud data platforms are concerned. Investigators have not indicated that the campaign depended on a vulnerability in Snowflake itself; instead, the reported intrusions centered on obtaining valid account credentials and using them to access customer environments.