Snowflake Data Breach Hacker Pleads Guilty, Faces 32-Year Prison Sentence

www.news4hackers.com-snowflake-data-breach-hacker-pleads-guilty-faces-32-year-prison-sentence-snowflake-data-breach-hacker-pleads-guilty-faces-32-year-prison-sentence

A Canadian individual has admitted guilt in a federal court for breaching cloud storage provider Snowflake and compromising data from over 165 organizations.

Case Overview

Connor Riley Moucka, 26, from Kitchener, Ontario, entered a plea for computer fraud, wire fraud, aggravated identity theft, and conspiracy. Sentencing is scheduled for October 27, with potential incarceration up to 32 years.

FBI Comments

FBI Cyber Division Assistant Director Brett Leatherman emphasized that digital anonymity does not shield perpetrators from legal consequences, noting Moucka’s arrest occurred shortly after initiating attacks on U.S. entities.

Scheme Details

The scheme involved unauthorized access to Snowflake accounts between April and September 2024, leveraging stolen credentials to extract sensitive information and demand ransom payments. The conspirators secured over $2.5 million through extortion, with Moucka personally receiving at least $495,000.

Impact and Financial Losses

One incident involved repeated extortion attempts targeting a government official’s personal data and family members. Stolen information was marketed on platforms including BreachForums, Exploit.in, XSS.is, and Telegram. The Justice Department highlighted that victim organizations incurred more than $9.5 million in direct financial losses, excluding impacts on 100 million individuals.

Affected Entities

Affected entities included AT&T, Ticketmaster, Santander, Advance Auto Parts, LendingTree, Neiman Marcus, Pure Storage, and Bausch Health.

Law Enforcement Response

FBI Seattle Field Office Special Agent in Charge W. Mike Herrington described the tactics as deliberate and harmful, affecting both corporate targets and their customers. Law enforcement agencies involved in the investigation included the FBI and U.S. Department of Justice.

Conclusion

The case underscores the escalating risks of cyberattacks on cloud infrastructure and the legal repercussions for cybercriminals.



About Author

en_USEnglish