Skip to main content
SnowflakeSecurity incident

Snowflake extortionist admits 165-victim cloud crime spree

What happened

At least 165 of Snowflake's customers had their cloud environments compromised in a data theft campaign between February and October 2024, resulting in the exposure of billions of customer records.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

storage Connor Moucka pleads guilty over sprawling 2024 campaign that looted billions of records A Canadian who helped orchestrate the sprawling Snowflake-linked data theft campaign has pleaded guilty in the US, admitting that he and his co-conspirators returned to squeeze at least one victim a second time. Connor Riley Moucka, 26, of Kitchener, Ontario, admitted computer fraud, wire fraud, aggravated identity theft, and conspiracy charges over a hacking spree that compromised more than 165 organizations, exposed billions of customer records, and brought in about $2.5 million in ransom payments. According to the US Department of Justice , Moucka and his co-conspirators used stolen login credentials to break into the cloud environments of at least 165 customers of a US software provider between February and October 2024. The DOJ still doesn't name the company, but the allegations match the 2024 campaign against Snowflake customers that ensnared the likes of Ticketmaster, Santander, AT&T, and dozens of others. In a plea agreement seen by The Register, Moucka admitted developing software that automatically searched compromised cloud environments for valuable information. He and his co-conspirators used it to identify lucrative targets and steal terabytes of banking records, payroll data, passport and driver's license numbers, Social Security numbers, DEA registration numbers...

Keep reading with a free account

The rest of this article, and every signal for Snowflake, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Security incident

What this signalsA breach often leads to new security spend.

More security incident signals at other companies

The full record

From the Signal API record

Details

Issue named
Stolen login credentials used to access customer cloud environments

Extraction

Confidence
90%
Detected
Aug 6, 2026
signal_type
news
signal_subtype
security_incident

Use this data

Get every security incident signal for Snowflake and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Snowflake this week?”

  2. Send it to your own tools

    The Signal API returns security incident signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/6ce771f1-2359-6b20-4fdc-a1189798b023 returns this record as JSON. POST /v1/companies/enrich returns every signal for snowflake.com.

{
  "signal_id": "6ce771f1-2359-6b20-4fdc-a1189798b023",
  "signal_type": "news",
  "signal_subtype": "security_incident",
  "detected_at": "2026-08-06T14:00:00+00:00",
  "company": {
    "name": "Snowflake",
    "domain": "snowflake.com"
  },
  "data": {
    "url": "https://www.theregister.com/storage/2026/08/06/snowflake-extortionist-admits-165-victim-cloud-crime-spree-and-squeezing-one-target-twice/5284059",
    "title": "Snowflake extortionist admits 165-victim cloud crime spree – and squeezing one target twice",
    "excerpt": "storage Connor Moucka pleads guilty over sprawling 2024 campaign that looted billions of records A Canadian who helped orchestrate the sprawling Snowflake-linked data theft campaign has pleaded guilty in the US, admitting that he and his co-conspirators returned to squeeze at least one victim a second time. Connor Riley Moucka, 26, of Kitchener, Ontario, admitted computer fraud, wire fraud, aggravated identity theft, and conspiracy charges over a hacking spree that compromised more than 165 organizations, exposed billions of customer records, and brought in about $2.5 million in ransom payments. According to the US Department of Justice , Moucka and his co-conspirators used stolen login credentials to break into the cloud environments of at least 165 customers of a US software provider between February and October 2024. The DOJ still doesn't name the company, but the allegations match the 2024 campaign against Snowflake customers that ensnared the likes of Ticketmaster, Santander, AT&T , and dozens of others. In a plea agreement seen by The Register , Moucka admitted developing software that automatically searched compromised cloud environments for valuable information. He and his co-conspirators used it to identify lucrative targets and steal terabytes of banking records, payroll data, passport and driver's license numbers, Social Security numbers, DEA registration numbers...",
    "summary": "At least 165 of Snowflake's customers had their cloud environments compromised in a data theft campaign between February and October 2024, resulting in the exposure of billions of customer records.",
    "planning": false,
    "image_url": "https://image.theregister.com/258627.jpg?imageId=258627&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683",
    "confidence": 0.9,
    "published_at": "2026-08-06T14:00:00Z",
    "vulnerability": "Stolen login credentials used to access customer cloud environments",
    "article_sentence": "According to the US Department of Justice , Moucka and his co-conspirators used stolen login credentials to break into the cloud environments of at least 165 customers of a US software provider between February and October 2024."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.