Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Snowflake Hacker Pleads Guilty in US Court

Connor Riley Moucka was extradited to the United States in July 2025 after he was arrested in Canada. 

Hacker pleads guilty

Connor Riley Moucka has pleaded guilty over his role in a cybercrime campaign that involved hacking into the Snowflake accounts of 165 organizations.

The 26-year-old has pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy, and faces more than 30 years in prison. Sentencing is scheduled for October 27. 

The man was arrested in late 2024 in Canada and was extradited to the United States in July 2025.

According to authorities, Moucka (reported in initial news coverage under the name Alexander ‘Connor’ Moucka) was part of a cybercrime group that used stolen login credentials to access data stored by organizations in their Snowflake data storage accounts. 

The campaign, attributed to a threat actor tracked as UNC5537, impacted organizations such as AT&T, Advance Auto Parts, Ticketmaster, Santander Bank, Neiman Marcus, Anheuser-Busch, Allstate, Mitsubishi, Progressive, and State Farm. 

The hackers stole billions of sensitive data records, including personal and financial information, and extorted victims. The DOJ says they received $2.5 million in ransom payments.

Advertisement. Scroll to continue reading.

In addition, the cybercriminals sold the stolen data on hacking forums, with Moucka obtaining half a million dollars.

The DOJ said targeted companies suffered losses totaling more than $9.5 million, which does not include the losses of their customers — at least 100 million people.

A former US soldier who pleaded guilty roughly one year ago to hacking into AT&T and Verizon systems is also believed to have participated in the Snowflake campaign. 

Related: Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison

Related: Two Scattered Spider Hackers Sentenced to Jail in UK

Related: US Charges Russian Individuals and Firms for Running Cybercrime Services

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

1Kosmos has named Frank Cohen Chief Revenue Officer.

ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.

James Wilkinson has been named Chief Information Security Officer for the City of Dallas.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.