All incidents

Snowflake data breach and extortion case

breachopenAug 5, 2026 — Aug 6, 2026
Canadian hacker admits Snowflake breach, extorts millions

CONNOR Moucka, a 26‑year‑old from Kitchener, Ontario, pleaded guilty to hacking a US‑based cloud storage provider, as outlined by the Department of Justice here. The attack compromised over 165 organisations, exfiltrated billions of records and led to multimillion‑dollar extortion demands. More than 100 million individuals had their personal data exposed, prompting widespread concern about credential safety in cloud environments.

Investigators said Moucka and his accomplices obtained stolen login credentials for the Snowflake platform and accessed accounts that lacked multi‑factor authentication. No CVE identifiers were assigned to the intrusion because the breach relied on legitimate credentials rather than a software vulnerability. The attackers moved laterally within the victim’s Snowflake environments, downloading customer databases, backup files and internal logs.

Using the stolen data, the group threatened to publish the information unless victims paid a ransom, ultimately collecting over $2.5 million in payments. The Department of Justice estimated that direct losses to the affected companies exceeded $9.5 million, factoring in incident response, regulatory fines and reputational harm. Moucka’s online monikers “Waifu” and “Judishe” appeared in underground forums where he advertised the harvested datasets.

The intrusions took place between February and October 2024, six months before Moucka’s arrest in August 2026. Although no specific threat actor group was linked to the campaign, the case illustrates a growing trend of re‑extortion, where attackers revisit victims after an initial payment to demand further money. Security analysts note that the Snowflake environment, while secure by design, becomes vulnerable when organisations neglect basic identity controls.

Defenders should enforce multi‑factor authentication on all cloud service accounts and regularly audit privileged credentials for signs of compromise. Implementing least‑privilege access and monitoring for anomalous data export can help detect credential abuse early. Organisations are also advised to rotate keys and revoke any tokens that may have been exposed in previous breaches.

Finally, companies should review third‑party integrations that rely on Snowflake and ensure that any shared datasets are encrypted both at rest and in transit. Continuous threat‑intelligence feeds can alert security teams to newly posted dumps on illicit markets, allowing rapid response before extortion attempts succeed. Staying vigilant on identity hygiene remains the most effective defence against similar credential‑theft campaigns.

The plea agreement also requires Moucka to forfeit the illicit gains and pay restitution to victims, a process overseen by the federal court in the Northern District of Georgia. Prosecutors highlighted the case as a warning to cybercriminals who assume that stealing cloud credentials carries low risk. Courts have begun to impose longer sentences for large‑scale data theft, signalling a shift toward stricter penalties for credential‑based intrusions.

Intelligence briefing updated Aug 6, 2026

Root sourcewww.justice.gov
Timeline Coverage

Swipe to explore timeline