Canadian Man Pleads Guilty in Snowflake Extortions

Refract AI Intelligence Digest

BLUF

A major Snowflake extortion ring operator has been convicted, highlighting ongoing risks in cloud data security.

NEWS

Connor Riley Moucka admitted guilt to conspiring to hack and extort more than 165 organizations utilizing Snowflake's cloud storage. Additionally, he confessed to stealing call and text history records belonging to over 100 million AT&T customers.

Why I Care

This case underscores the severe consequences of misconfigured cloud credentials and the scale of data exposure possible through third-party providers, affecting enterprises and millions of consumers alike.

Next Steps

Organizations using Snowflake should immediately audit MFA enforcement and credential management policies, while security teams must review historical access logs for unauthorized activity by end-of-quarter.

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.
Back to Blog Listing

Source: Krebs on Security ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.