Snowflake Hacker Pleads Guilty, Faces 32 Years
Snowflake hacker Connor Riley Moucka pleaded guilty on August 5, 2026, in the U.S. District Court for the Western District of Washington, admitting to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy count tied to the 2024 breaches of Snowflake customer accounts.
Here is what the plea confirms, how the breach actually happened, and what has changed since.
Sentencing: Up to 32 Years in Prison
The 26 year old, from Ontario, is scheduled to be sentenced on October 27. He faces a mandatory two years in prison on the identity theft count, to run consecutively with up to 30 years on the other three charges, as much as 32 years total.
Scale of the Snowflake Data Breach
Prosecutors say Moucka and co-defendant John Erin Binns used stolen login credentials, many of them surfaced years earlier through infostealer malware, to break into Snowflake customer accounts and then extorted victims and sold stolen records on cybercrime forums.
The Justice Department says the campaign compromised more than 165 organizations and exposed billions of records tied to more than 100 million people, with direct victim losses exceeding $9.5 million.
Named victims include AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, and Santander; the Ticketmaster breach alone involved roughly 560 million user records. Moucka personally collected at least $495,000, prosecutors say, including through a re-extortion attempt that used a government official’s stolen personal data.
DOJ and FBI React to Snowflake Hacker’s Guilty Plea
The Justice Department announced the plea the same day. Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division said the plea shows that cybercriminals can’t rely on anonymity to escape prosecution, wherever they are based.
FBI Seattle Special Agent in Charge W. Mike Herrington described Moucka’s extortion tactics as deliberate, saying they caused lasting harm to both the businesses targeted and their customers. Police in Australia, Spain, Ukraine, and Turkiye assisted the investigation, according to the Justice Department.
What the Plea Confirms
The plea resolves the case against Moucka only. Binns was separately arrested in Turkey, where a court approved a U.S. extradition request that he is contesting; according to court records, his case continues separately, and he remains outside U.S. custody.
A few figures still need context. In 2024, Snowflake and Mandiant said they had notified roughly 165 potentially exposed organizations; prosecutors are now citing a similar number of confirmed victims, but public filings don’t establish that the two counts describe an identical set of companies. Restitution and Moucka’s exact sentence remain undecided until the October 27 hearing.
Timeline of the Snowflake Breach Case
SOCRadar has tracked the incident since it broke in 2024 in our overview of the Snowflake breach; the key dates in the case are below.
- February–October 2024: Using stolen credentials, Moucka and Binns allegedly accessed Snowflake customer accounts that lacked multi-factor authentication.
- July 2024: AT&T disclosed that call and text records for nearly all of its wireless customers had been taken from its Snowflake environment.
- October 30, 2024: Moucka was arrested in Kitchener, Ontario; Binns was arrested separately in Turkey.
- Late 2024: Prosecutors in the Western District of Washington charged both men; the original complaint named about 10 victim organizations, far fewer than the 165-plus later cited.
- March 2025: Moucka agreed to extradition from Canada.
- July 2025: Moucka was arraigned in Seattle and pleaded not guilty. That same month, Cameron John Wagenius, whom prosecutors have linked to related intrusions, pleaded guilty in a separate case.
- August 5, 2026: Moucka pleaded guilty to all four counts.
- October 27, 2026: Sentencing is scheduled.
How the Snowflake Hackers Gained Access
The intrusions relied on previously stolen customer credentials rather than any flaw in Snowflake’s own systems, a conclusion Snowflake has maintained since 2024.
Researchers found that at least 79.7% of the accounts used in the campaign had prior credential exposure, some tracing back to infostealer infections from as early as 2020, with a few passwords left unrotated for as long as four years.
The accounts also generally lacked multi-factor authentication, so a stolen password alone was often enough to log in, and investigators said the Snowflake instances involved had no network allow-lists limiting access to trusted locations – a control Snowflake’s platform supports at the account, user, or integration level.
The campaign didn’t rely on especially novel hacking tools; it largely succeeded by using valid, legitimate-looking logins, the kind of activity that endpoint security software isn’t generally built to catch.
Conclusion: A Preventable Breach, a Slow Fix
Moucka’s guilty plea closes the legal chapter on one of the more consequential cloud breaches in recent memory, but in our view, the underlying pattern is far from resolved. None of this required custom malware or a zero-day: it ran on years-old stolen passwords and the simple absence of a second authentication factor, which is exactly why a campaign built on basic credential theft scaled to more than 165 organizations and over 100 million people before anyone caught it.
Snowflake‘s own response underscores how long that fix took to arrive. The company only began enforcing mandatory MFA for password-based human users, and stronger authentication for service accounts, in a rollout that started in August 2026 – two years after the breaches it is meant to prevent, and one that still carves out exceptions for reader and trial accounts as well as Snowflake Postgres. Credential-based intrusions remain the most common, and most preventable, category of cloud breach; closing that gap at the platform level, this case shows, is still measured in years, not months.

