Canadian Hacker Pleads Guilty Over Snowflake Attack Hitting 165 Firms, Faces 32 Years
Connor Riley Mouka, a 26-year-old Canadian from Kitchener, Ontario, pleaded guilty in a Washington state federal court to computer fraud, wire fraud, aggravated identity theft and related conspiracy charges over the Snowflake data breach. The attack, carried out between February and October 2024 with stolen credentials, compromised data from at least 165 companies including AT&T and Ticketmaster. Mouka faces up to 32 years in prison at his October 27 sentencing. Prosecutors estimated direct losses of about $9.5 million.
Connor Riley Mouka, a Canadian national, formally pleaded guilty in US federal court in Washington state for his role in the hacking attack on the Snowflake platform. Mouka, 26, resides in Kitchener, Ontario, Canada. On Wednesday, he pleaded guilty to computer fraud, wire fraud, aggravated identity theft and related conspiracy charges. Sentencing is set for October 27, with Mouka facing up to 32 years in prison. Prosecutors alleged that Mouka and his accomplices used stolen login credentials to illegally access the Snowflake platform between February and October 2024, leading to data breaches at no fewer than 165 companies.
The group stole billions of documents from major companies and institutions including AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander Bank, LendingTree and a US school district. The AT&T breach involved call and text message records of more than 100 million customers, while the Ticketmaster breach affected approximately 560 million users. The leaked data included bank records, financial information, US Drug Enforcement Administration registration numbers, driver's licence numbers, passport numbers and social security numbers.
After stealing the data, the group extorted victim companies by threatening to make the data public, netting approximately $2.5 million in illegal proceeds. Mouka also conducted a second round of extortion against one victim, during which he used stolen data belonging to a government official and that official's immediate family members. In addition, he advertised and sold victim company data on dark web forums including BreachForums and XSS. is, earning a further $495,000. Prosecutors estimated that victim companies suffered direct economic losses of approximately $9.5 million as a result of the series of data breaches.
Following the incident, Snowflake commissioned Mandiant to conduct an investigation, which confirmed that the platform itself had no security vulnerabilities. The hackers used credentials that had been stolen in 2020 but remained valid to log in and gain account access. The investigation showed the group was primarily active in North America and collaborated with a Turkish member. The Turkish hacker involved, John Erin Binns, was indicted for his participation in the T-Mobile hack and was arrested by Turkish police in 2024. Mouka was arrested in Canada in November 2024 and extradited to the United States in July 2025. Before his arrest, he destroyed relevant evidence.
Why this event matters
The event has a measured impact on 1 industry. The strongest current signal is negative for Cloud Services & Data Centres, with intensity 65/100 and 80% confidence over a short term horizon.
Impact figures are analytical estimates that combine direction, intensity, confidence and event importance. They are not investment advice.