Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty on August 5, 2026 in federal court in Seattle to four counts: computer fraud, wire fraud, aggravated identity theft and a related conspiracy.

The conduct behind those counts is the largest cloud data-theft campaign on record. Moucka and co-defendant John Erin Binns compromised more than 165 organizations that used the Snowflake cloud data platform, stole records belonging to at least 100 million people, extorted the victims and sold what would not sell back to them on cybercrime forums.

The conspiracy collected more than $2.5 million in ransom payments. Moucka’s personal cut from ransoms and data sales was at least $495,000. Prosecutors put actual victim losses at $9.5 million.

Sentencing is set for October 27, 2026. The aggravated identity theft count carries a mandatory minimum of two years; the remaining counts expose him to up to 30 years.

Snowflake Was Never Breached

The detail that defined this campaign in 2024 still defines it in the plea: there was no vulnerability.

Moucka did not exploit Snowflake. He logged in. The credentials came from infostealer malware logs β€” some harvested years earlier, some dating back to November 2020 β€” sitting in criminal marketplaces waiting for someone to check whether they still worked. Mandiant’s investigation found that 79.7% of the compromised accounts had prior credential exposure.

They still worked because nobody had rotated them, and there was no second factor to stop them. Snowflake at the time did not require multi-factor authentication on customer tenants, and the customers who did not enable it themselves were, functionally, protected by a password that had been public for years.

The named victims are a roll call of the 2024 breach cycle: AT&T, Ticketmaster, Santander Bank, LendingTree, Advance Auto Parts, Neiman Marcus. The AT&T theft alone covered call and text records for nearly every one of its cellular customers between May and October 2022.

Each of those companies suffered a breach. None of them suffered an intrusion in the sense the word usually implies. The attacker arrived through the front door holding a valid key, and the platform had no mechanism configured to ask him for anything else.

The Second Guilty Plea in the Same Campaign

Moucka is not the first. Cameron John Wagenius, the former U.S. Army soldier who worked the same campaign, pleaded guilty in July 2025 to his role in the AT&T and Snowflake thefts.

John Erin Binns remains outside U.S. custody.

That split β€” two in the system, one beyond reach β€” is the pattern we traced across the whole of this year’s enforcement record in the 2026 cybercrime arrest wave. Prosecutors reach the operators who touch a cooperative jurisdiction. Moucka was arrested in Canada in October 2024 on a U.S. provisional warrant. Binns’s location has kept him out of a Seattle courtroom for two years.

The people who bought the stolen records are not charged at all.

What the Plea Costs the Ecosystem

A two-year mandatory minimum plus a sentencing exposure of 30 years is a real number, and it will be cited. It is worth being precise about what it deters.

Moucka is a direct operator. He personally netted under half a million dollars from a campaign that exposed 100 million people and cost victims nearly ten times what he made. The economics were never good for him. They were catastrophic for everyone else.

What made the campaign possible was not skill. It was a supply of years-old stolen credentials that remained valid, in a platform tier where MFA was optional and nobody was checking. That supply has not diminished. Infostealer logs remain the cheapest input in the criminal economy, and the pattern that made Snowflake tenants trivially reachable in 2024 is the same one that keeps producing SaaS breaches now β€” as the ShinyHunters Salesforce vishing campaign demonstrated across 2026 with a different platform and the same underlying failure.

Sentencing Moucka to a decade removes an operator. It does not remove a single credential from a single log.

The Control Nobody Enforced

The uncomfortable finding in this case is a governance one, not a technical one.

Every one of the 165 victim organizations could have prevented its own breach by enabling multi-factor authentication on its Snowflake tenant. Snowflake supported it. None of these organizations were breached because a control failed. They were breached because a control existed, was documented, and was left switched off β€” and because the platform vendor treated enforcement as a customer choice rather than a default.

Snowflake has since moved to mandatory MFA for new accounts. That change came after 100 million people had their records stolen, which is the usual sequence.

The lesson generalizes badly for anyone still running a shared-responsibility model on trust. If a security control is optional, its adoption rate is a business metric, not a security posture β€” and an attacker with a list of valid credentials will find every tenant on the wrong side of that metric in a matter of days. Moucka needed no exploit, no zero-day and no insider. He needed a list and the patience to work through it.

He worked through it, and it took two years to get him into a courtroom.

Sources