Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Snowflake Hacker Pleads Guilty in US Court

Connor Riley Moucka was extradited to the United States in July 2025 after he was arrested in Canada. 

Hacker pleads guilty

Connor Riley Moucka has pleaded guilty over his role in a cybercrime campaign that involved hacking into the Snowflake accounts of 165 organizations.

The 26-year-old has pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy, and faces more than 30 years in prison. Sentencing is scheduled for October 27. 

The man was arrested in late 2024 in Canada and was extradited to the United States in July 2025.

According to authorities, Moucka (reported in initial news coverage under the name Alexander ‘Connor’ Moucka) was part of a cybercrime group that used stolen login credentials to access data stored by organizations in their Snowflake data storage accounts. 

The campaign, attributed to a threat actor tracked as UNC5537, impacted organizations such as AT&T, Advance Auto Parts, Ticketmaster, Santander Bank, Neiman Marcus, Anheuser-Busch, Allstate, Mitsubishi, Progressive, and State Farm. 

The hackers stole billions of sensitive data records, including personal and financial information, and extorted victims. The DOJ says they received $2.5 million in ransom payments.

Advertisement. Scroll to continue reading.

In addition, the cybercriminals sold the stolen data on hacking forums, with Moucka obtaining half a million dollars.

The DOJ said targeted companies suffered losses totaling more than $9.5 million, which does not include the losses of their customers — at least 100 million people.

A former US soldier who pleaded guilty roughly one year ago to hacking into AT&T and Verizon systems is also believed to have participated in the Snowflake campaign. 

Related: Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison

Related: Two Scattered Spider Hackers Sentenced to Jail in UK

Related: US Charges Russian Individuals and Firms for Running Cybercrime Services

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.

Pietr Lindahal has been named Vice President and Chief Information Security Officer at Boston Scientific.

AI agent identity and enforcement company FIOR has appointed Gemma Ungoed-Thomas as Adviser.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.