[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f00eNktvvz4nc9-vX9DnVcbor9RPMMooTtYKaKPz72n4":3},{"article":4,"iocs":56},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"9f014d56-91bd-4e42-a23e-cfc76a5bf078","Snowflake Hacker Pleads Guilty in US Court","snowflake-hacker-pleads-guilty-in-us-court-4f0c33","Connor Riley Moucka was extradited to the United States in July 2025 after he was arrested in Canada. The post Snowflake Hacker Pleads Guilty in US Court appeared first on SecurityWeek.","Connor Riley Moucka has pleaded guilty in a US court for his role in a cybercrime campaign that compromised 165 organizations' Snowflake accounts. The group, identified as UNC5537, used stolen credentials to access sensitive data, stealing billions of records and extorting victims for $2.5 million in ransom payments. Moucka personally profited $500,000 from selling stolen data on hacking forums, and the targeted companies suffered over $9.5 million in losses.","Snowflake hacker pleads guilty to computer fraud, wire fraud, and conspiracy.","Connor Riley Moucka has pleaded guilty over his role in a cybercrime campaign that involved hacking into the Snowflake accounts of 165 organizations. The 26-year-old has pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy, and faces more than 30 years in prison. Sentencing is scheduled for October 27. The man was arrested in late 2024 in Canada and was extradited to the United States in July 2025. According to authorities, Moucka (reported in initial news coverage under the name Alexander ‘Connor’ Moucka) was part of a cybercrime group that used stolen login credentials to access data stored by organizations in their Snowflake data storage accounts. The campaign, attributed to a threat actor tracked as UNC5537, impacted organizations such as AT&T, Advance Auto Parts, Ticketmaster, Santander Bank, Neiman Marcus, Anheuser-Busch, Allstate, Mitsubishi, Progressive, and State Farm. The hackers stole billions of sensitive data records, including personal and financial information, and extorted victims. The DOJ says they received $2.5 million in ransom payments.Advertisement. Scroll to continue reading. In addition, the cybercriminals sold the stolen data on hacking forums, with Moucka obtaining half a million dollars. The DOJ said targeted companies suffered losses totaling more than $9.5 million, which does not include the losses of their customers — at least 100 million people. A former US soldier who pleaded guilty roughly one year ago to hacking into AT&T and Verizon systems is also believed to have participated in the Snowflake campaign. Related: Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison Related: Two Scattered Spider Hackers Sentenced to Jail in UK Related: US Charges Russian Individuals and Firms for Running Cybercrime Services Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs New Attack Methods Enable Malware to Hijack Passkey-Protected AccountsCybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data Water Sector Cyberattacks Reportedly Hit at Least 12 StatesTP-Link Omada ZTP Vulnerabilities Chain Into Full Network TakeoverMicrosoft Bug Bounty Program: $20 Million Paid to 500 ResearchersN‑able Patches Vulnerability Exploited to Hack N-central ServersUS Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other StatesPrompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations Latest News Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X PostsPodcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna ConwayCritical Paperclip Flaw Allowed Admin Access, Code ExecutionMeta AI Hacked External Systems During Cybersecurity TestingBelarusian Ransom Cartel Mastermind Gets 16 Years in PrisonCisco Patches Critical SD-WAN, IOS XE, FMC VulnerabilitiesHackers Start Exploiting Recent JetBrains TeamCity VulnerabilityHow a $50,000 Exploit Chain Turned Bixby Against Samsung Phones Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveServiceNow has appointed Simon Mouyal as Chief Marketing Officer.James Wilkinson has been named Chief Information Security Officer for the City of Dallas.PNC Financial Services Group has appointed Christian Winward as CISO.More People On The MoveExpert Insights Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fsnowflake-hacker-pleads-guilty-in-us-court\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2025\u002F07\u002Fplead-guilty-hacker-court.jpeg","2026-08-06T14:56:31+00:00","2026-08-06T16:00:52.008509+00:00",8,[18,21,24,27,29,31],{"name":19,"type":20},"UNC5537","threat_actor",{"name":22,"type":23},"Snowflake","product",{"name":25,"type":26},"AT&T","vendor",{"name":28,"type":26},"Ticketmaster",{"name":30,"type":26},"Santander Bank",{"name":32,"type":26},"Neiman Marcus","2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":33,"icon":35,"name":36,"slug":37},null,"Breaches","breaches",[39,41,46,51],{"category":40},{"id":33,"icon":35,"name":36,"slug":37},{"category":42},{"id":43,"icon":35,"name":44,"slug":45},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":47},{"id":48,"icon":35,"name":49,"slug":50},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",{"category":52},{"id":53,"icon":35,"name":54,"slug":55},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]