Snowflake Hacker Guilty Plea in U.S. Court

www.news4hackers.com-snowflake-hacker-guilty-plea-in-u-s-court-snowflake-hacker-guilty-plea-in-u-s-court

A 26-year-old individual has admitted to participating in a cybercrime operation targeting Snowflake accounts of 165 organizations.

Key Details of the Cybercrime Scheme

The defendant faces charges including computer fraud, wire fraud, aggravated identity theft, and conspiracy, with potential sentencing exceeding 30 years in prison. A court hearing is scheduled for October 27. The individual was apprehended in Canada during late 2024 and transferred to the United States in July 2025.

The Suspect and Arrest

Authorities identified the suspect as Connor Riley Moucka, previously reported under the name Alexander Connor Moucka. The cybercriminal activity involved unauthorized access to data stored in Snowflake cloud storage accounts through compromised login credentials.

Targeted Organizations and Impact

This campaign, linked to a threat actor designated as UNC5537, affected entities such as AT&T, Advance Auto Parts, Ticketmaster, Santander Bank, Neiman Marcus, Anheuser-Busch, Allstate, Mitsubishi, Progressive, and State Farm. Attackers exfiltrated billions of sensitive records, including personal and financial data, and demanded ransom payments.

Financial Consequences

The Department of Justice (DOJ) reported that victims paid $2.5 million in ransoms, while the hacker network generated $500,000 by selling stolen data on underground forums. The DOJ highlighted that the targeted organizations incurred losses exceeding $9.5 million, excluding damages to their customers, which affected at least 100 million individuals.

“The scale of the breach underscores the risks associated with misconfigured cloud storage environments and the importance of robust access controls.”

Connection to a Separate Case

A separate case involving a former U.S. soldier who previously pleaded guilty to hacking AT&T and Verizon systems is believed to be connected to the Snowflake campaign. The operation exploited vulnerabilities in cloud infrastructure to compromise data integrity and confidentiality.

Technical Aspects of the Breach

Attackers leveraged stolen credentials to bypass security measures, enabling unrestricted access to sensitive datasets. The case highlights the growing threat of organized cybercrime groups leveraging cloud platforms for large-scale data exfiltration and financial gain.

Law Enforcement Response

Law enforcement agencies continue to track and prosecute individuals involved in such schemes, emphasizing the need for enhanced security protocols in cloud-based systems.

FAQs

What is the significance of this cybercrime case?

This case highlights the risks of cloud-based data breaches and the involvement of organized cybercrime groups in targeting major organizations.

How many organizations were affected?

165 organizations were impacted, including major companies like AT&T, Ticketmaster, and Santander Bank.

What are the potential penalties for the defendant?

The defendant faces charges that could result in over 30 years in prison, along with fines and other legal consequences.



About Author

en_USEnglish