Canadian Man Pleads Guilty in Snowflake Extortions and AT&T Data Theft
Connor Riley Moucka admits to hacking cloud data platform and compromising customer call records

Key Takeaways
- Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty to computer fraud and conspiracy.
- The plea includes hacking and extorting more than 165 organizations using the Snowflake cloud data platform.
- Moucka also admitted to stealing call and text history records of over 100 million AT&T customers.
- The case was reported by Krebs on Security on August 6, 2026.
- The plea resolves charges related to both the Snowflake extortions and the AT&T data theft.
Quick answers
- What happened?
- Connor Riley Moucka, 26, of Kitchener, Ontario, has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations using the Snowflake cloud data platform. The plea also covers the theft of call and text history records from over 100 million AT&T customers. The case was reported by Krebs on Security on August 6, 2026.
- Which products are affected?
- Snowflake Cloud Data Platform
- What should defenders do?
- Organizations using Snowflake should review and harden account security, including multi-factor authentication and least-privilege access controls. AT&T and other telecommunications providers should assess breach implications and strengthen protection of customer call and text metadata. Regular security audits and monitoring of cloud accounts are recommended.
A 26-year-old Canadian man described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers. According to reporting, Moucka’s guilty plea resolves charges related to the compromise of Snowflake cloud accounts and the subsequent extortion of organizations relying on the platform. The plea also encompasses the large-scale theft of AT&T customer call and text metadata. The reported actions affected a broad range of entities and a significant volume of customer data. Authorities and cybersecurity analysts are monitoring the case for implications on cloud security practices and telecommunications data protection.
Security Details
The defendant pleaded guilty to computer fraud and conspiracy to hack and extort Snowflake cloud data platform customers and to stealing AT&T customer call and text history records. Specific technical details of the Snowflake compromise and the methodology used to access AT&T records were not disclosed in the reported plea. Organizations using Snowflake are advised to review security configurations, and AT&T is assessing the implications of the reported data theft.
Affected products
Snowflake Cloud Data Platform
Mitigation
Organizations using Snowflake should review and harden account security, including multi-factor authentication and least-privilege access controls. AT&T and other telecommunications providers should assess breach implications and strengthen protection of customer call and text metadata. Regular security audits and monitoring of cloud accounts are recommended.
Sources
Krebs on Security
Canadian Man Pleads Guilty in Snowflake Extortions
Aug 6, 2026 · 17:00
Original link
Related Security News

Former US Air Force Members Sentenced to Prison for Business Email Compromise Scams
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. The sentencing, reported by BleepingComputer in September 2026, concluded a federal case targeting individuals who abused their military backgrounds to conduct financially motivated email fraud. The attacks spanned multiple years prior to sentencing, though specific victim counts and total financial losses were not detailed in the reporting. The case underscores the legal consequences of using military credentials and training for cyber-enabled fraud.




