A 26-Year-Old From Kitchener Pleads Guilty to One of 2026’s Largest Breaches
On August 6, 2026, Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty in federal court in Seattle to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy charge, according to The Hacker News. Moucka, who used the online aliases “Waifu” and “Judische,” admitted to a hacking and extortion campaign that compromised at least 165 organizations using Snowflake’s cloud data platform, exposing records tied to at least 100 million people, per CSO Online’s reporting.
The confirmed victim list, out of the 165+ organizations affected overall, includes major names: AT&T, Ticketmaster, and Neiman Marcus Group. The Hacker News reports the attackers “obtained billions of sensitive customer records and downloaded terabytes of information” from the compromised accounts. Sentencing is scheduled for October 27, 2026; Moucka faces a two-year mandatory minimum on the identity-theft count and up to 30 years in total, according to The Hacker News.
No Exploit, No Platform Flaw — Just Old Passwords
The most important detail in this case is not the scale of the breach but its mechanism. ComplianceHub’s analysis states plainly: “No exploit, no flaw in the platform.” The credentials that let the attackers in were old passwords harvested years earlier by infostealer malware and never rotated, and the affected accounts had multi-factor authentication switched off. ComplianceHub’s review found that at least 79.7% of the compromised accounts had prior credential exposure, with some of that exposed data dating back to November 2020 — meaning the underlying passwords had been circulating on criminal marketplaces for roughly five years before they were used in this specific campaign.
The data taken varied by victim but included call and text histories, payroll records, DEA registration numbers, and passport and Social Security numbers, according to ComplianceHub. Moucka personally obtained at least $495,000 from ransom payments and data sales, per The Hacker News. The broader conspiracy — which also involved co-defendants John Erin Binns (still outside U.S. custody) and Cameron John Wagenius, who pleaded guilty in July 2025 — collected more than $2.5 million in total ransom payments, according to TechCrunch.
This mechanism — infostealer malware harvesting credentials that then sit unused and unrotated for years before being weaponized — is not unique to Snowflake customers; it exploits a gap in organizational process rather than a gap in any single vendor’s code. A password stolen by malware on an employee’s personal or work device in 2020 remains just as functional an attack credential in 2026 if nobody ever changed it and no MFA layer sits between the password and the data. That is what makes this case instructive well beyond Snowflake specifically: the same failure mode could plausibly be sitting, undetected, in other organizations’ SaaS accounts today — the ComplianceHub finding that 79.7% of the compromised accounts had years-old credential exposure is a warning about how long stolen passwords stay viable, not a claim about any specific other company.
Advertisement
Why a Guilty Plea Two Years Later Still Matters
This is not a new breach — the underlying Snowflake customer-account compromises were first disclosed in 2024. What makes the August 2026 plea newsworthy is that it closes the loop on attribution and confirms, under oath in federal court, the exact mechanism that caused a breach affecting 100 million people: credential reuse and absent MFA, not a platform-level security failure at Snowflake itself. That distinction matters for any organization evaluating its own SaaS vendor risk, because it shifts the accountability question from “is my cloud vendor secure” to “did I enforce MFA and rotate credentials on every account with access to that vendor.”
The conspiracy’s structure also matters for anyone tracking how these extortion campaigns actually operate. Moucka was not acting alone: TechCrunch reports that co-defendant John Erin Binns remains outside U.S. custody, while Cameron John Wagenius — who used the alias “Kiberphant0m” — was arrested in January 2025 and pleaded guilty in July 2025, more than a year before Moucka’s own plea. That staggered timeline of arrests and pleas illustrates how long-running these prosecutions can take even when the technical evidence is clear-cut, and it means the full financial and legal picture of the conspiracy is still not entirely closed even as of Moucka’s plea — Binns’ case remains outstanding.
What This Means for Enterprise Security Teams
1. Audit every SaaS account for MFA enforcement, not just policy existence
The Snowflake accounts that were compromised had MFA switched off — not missing as a feature, but disabled in practice. Run an actual configuration audit across every SaaS platform your organization uses (not just Snowflake) to confirm MFA is enforced at the account level, not merely available and unused.
2. Treat infostealer-harvested credentials as a standing threat, not a one-time incident
ComplianceHub’s finding that some compromised credentials dated back to November 2020 shows how long stolen passwords remain viable attack tools. Subscribe to a credential-exposure monitoring service and rotate any password that has ever appeared in a known infostealer log or breach dataset — even years-old exposure remains exploitable if the password was never changed.
3. Reassess vendor risk assessments that focus only on the vendor’s own security posture
Snowflake’s platform was not exploited — customer-side credential hygiene was. Update your third-party risk framework to explicitly evaluate your own team’s access-control practices for each SaaS vendor, not just the vendor’s certifications and audit reports.
4. Build an incident response plan that assumes multi-year-old credentials are still active
Since some of the compromised passwords were exposed as early as 2020 and remained valid until the 2024 breach, assume your organization has dormant, unrotated credentials somewhere in its SaaS footprint right now. Prioritize a credential-rotation sweep over waiting for the next breach disclosure to force the issue.
The Compliance Lesson
The Moucka guilty plea is a clean natural experiment in accountability: a breach affecting 100 million people, 165+ organizations, and losses exceeding $9.5 million traced not to a zero-day or a platform vulnerability, but to a preventable, well-understood control gap — unrotated credentials and disabled MFA. For compliance and security leaders, this case is likely to become a reference point in vendor-risk and insurance conversations precisely because the causal chain is so unambiguous: no forensic dispute about attribution, no ambiguity about the entry vector, and now a guilty plea on the public record confirming both.
That unambiguity is itself unusual. Most large breaches leave room for disputed attribution, contested root-cause analysis, or a vendor and its customers pointing fingers at each other for months. Here, a defendant has admitted under oath to the mechanism, the scale, and the financial take — which gives insurers, auditors, and boards a rare, fully-documented case study to cite when arguing for mandatory MFA and credential-rotation policies rather than treating them as optional best practices.
Frequently Asked Questions
Who is Connor Moucka and what did he plead guilty to?
Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty on August 6, 2026 in federal court in Seattle to computer fraud, wire fraud, aggravated identity theft, and conspiracy, according to The Hacker News. He used the aliases “Waifu” and “Judische” and admitted to hacking and extorting at least 165 organizations that used the Snowflake cloud data platform.
Did Snowflake’s platform have a security vulnerability?
No. According to ComplianceHub’s analysis, “no exploit, no flaw in the platform” was involved — the attackers used old, unrotated passwords harvested by infostealer malware, on accounts that had multi-factor authentication disabled.
How many people and companies were affected by the breach?
At least 165 organizations were compromised, including AT&T, Ticketmaster, and Neiman Marcus Group, exposing records tied to at least 100 million people, according to CSO Online. Actual financial losses exceeded $9.5 million, per The Hacker News.
Sources & Further Reading
- Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People — The Hacker News
- Snowflake Attacker Pleads Guilty to Hack of 165 Companies’ Data — CSO Online
- Hacker Pleads Guilty to Stealing Data From More Than 165 Snowflake Customers — TechCrunch
- The Snowflake Guilty Plea: 165 Tenants, No Vulnerability, and the MFA Control Nobody Enforced — ComplianceHub













