A 26-year-old man accused of playing a role in a large cybercrime campaign has pleaded guilty in US court. The case centers on allegations that he helped gain access to Snowflake accounts belonging to 165 organizations, using stolen login credentials.
According to authorities, the same individual was previously reported in early coverage under the name Alexander “Connor” Moucka. He now faces multiple federal charges and sentencing scheduled for October 27.
What the guilty plea covers
The defendant, identified by authorities as Connor Riley Moucka, entered his plea for his role in the scheme. The charges listed in court include computer fraud, wire fraud, aggravated identity theft, and a related conspiracy count.
If the court imposes the maximum penalties associated with these charges, he could face more than 30 years in prison. The scheduled sentencing date signals that prosecutors intend to treat the matter as a serious, high-impact cybercrime.
How the Snowflake intrusion is described
Prosecutors say the group behind the campaign used stolen credentials to access data stored by victim organizations in their Snowflake data storage accounts. In other words, the alleged access path relied on compromised login information rather than a claim—at least in the publicly described summary—of exploiting a Snowflake-specific weakness.
The campaign has been attributed to a threat actor tracked as UNC5537. Authorities connect the activity to the theft of sensitive records and subsequent monetization efforts.
Scale of the impact and named victims
The affected organizations span multiple industries and included companies such as AT&T, Advance Auto Parts, Ticketmaster, Santander Bank, Neiman Marcus, Anheuser-Busch, Allstate, Mitsubishi, Progressive, and State Farm.
Authorities describe the campaign as having stolen billions of sensitive data records. Those records reportedly included personal and financial information, which prosecutors say was then used for extortion.
Data theft, extortion, and ransom totals
Alongside theft, the DOJ states that victims were extorted. In this case, prosecutors report that they received $2.5 million in ransom payments.
The court filings summarized in the reporting also include a financial damage figure tied to targeted companies. Prosecutors say the losses they suffered totaled more than $9.5 million, excluding customer impacts. Authorities estimate that at least 100 million people were affected when customer data exposure is considered.
Selling stolen data on hacking forums
Monetization did not stop at ransoms. Prosecutors also say the cybercriminals sold the stolen data on hacking forums.
In that aspect of the scheme, the defendant reportedly obtained about $500,000, according to the DOJ description cited in the case coverage. This reflects a broader cybercrime pattern in which stolen datasets can be weaponized, traded, or resold.
Arrest, extradition, and timeline
Investigators arrested the defendant in late 2024 in Canada. After that, he was extradited to the United States in July 2025, where the legal process has continued.
The guilty plea now moves the case closer to sentencing. With the date set for October 27, the next step will focus on the recommended punishment range and arguments from both sides regarding the scope of the defendant’s involvement.
Connections to other cybercrime prosecutions
The reporting also notes that prosecutors believe another person—described as a former US soldier—may have participated in the Snowflake campaign. That individual pleaded guilty about a year earlier in connection with hacking into AT&T and Verizon systems.
These references suggest that investigators view the alleged activity as part of a wider network of intrusions and criminal collaboration, rather than as an isolated incident.
Why this case matters for organizations
This matter is a reminder that major breaches can involve credential-based access and that large cloud or data-platform environments can be targeted through account compromise. Even when the underlying storage platform is widely used and well-known, unauthorized access can still happen if login details are stolen, reused, or inadequately protected.
Organizations with data stored in third-party environments may want to review controls such as strong authentication, limiting credential reuse, monitoring for suspicious logins, and ensuring that access permissions are tightly scoped. While this case summary does not lay out specific technical steps used by the attackers beyond stolen credentials, the pattern is clear: criminals can reach valuable datasets when account security fails.
For leaders and incident response teams, the case also highlights how consequences extend beyond immediate business disruption. Prosecutors describe both ransom demands and broader downstream risk through resale of stolen data, which can affect millions of people.
Conclusion: Snowflake hacker pleads guilty
The Snowflake hacker pleads guilty in a federal case tied to alleged access to Snowflake accounts of 165 organizations. Authorities say the campaign involved stolen login credentials, theft of extensive personal and financial records, extortion, and selling data on hacking forums.
With sentencing scheduled for October 27, the court will determine the final punishment after this guilty plea. In the meantime, the details in the DOJ’s account underscore the ongoing threat posed by cybercrime groups targeting high-value data storage and monetizing breaches through multiple channels.
Source: https://www.securityweek.com/snowflake-hacker-pleads-guilty-in-us-court/
