Connor Moucka pleaded guilty to orchestrating a sprawling hacking campaign that compromised more than 165 Snowflake customers, generating over $2.5 million in ransom payments for his criminal ring.
The attack exploited weak credential security across Snowflake's customer base. Moucka and his accomplices gained unauthorized access to customer accounts and extracted sensitive data, then demanded payment in exchange for not publicly releasing or selling the information. The campaign represents one of the largest coordinated breaches targeting a single cloud data platform.
Snowflake, which went public in 2020 and serves thousands of enterprises storing petabytes of data, faced intense scrutiny following the initial breach disclosures in 2024. The company's customers included household names across retail, financial services, and technology sectors. The incident exposed a critical vulnerability in how organizations managed API keys and authentication credentials within Snowflake environments, with many customers running default or easily guessable passwords.
Moucka's guilty plea marks a significant enforcement action in a case that shook confidence in Snowflake's security posture. Federal prosecutors pursued charges related to wire fraud, computer fraud, and extortion. The plea deal suggests cooperation with authorities investigating the broader criminal network involved in the scheme.
The breach highlighted a persistent problem in cloud infrastructure. Even well-capitalized platforms cannot force customers to implement basic security hygiene. Snowflake released updated guidance and security tools following the incident, but the damage extended beyond compromised data to customer trust.
The case underscores why cloud security audits focus heavily on access controls and credential management. Enterprise customers now face pressure to rotate API keys regularly and implement multi-factor authentication across cloud platforms. For Snowflake, the incident and subsequent prosecution provide some closure but serve as a reminder that platform-level security improvements alone cannot protect against human error at the customer level
