SEATTLE, WA – August 9, 2026 (STL.News) Conner Moucka – A Canadian man has admitted his role in one of the largest cloud-based cybercrime conspiracies prosecuted by the U.S. Department of Justice, pleading guilty to hacking more than 165 organizations, stealing billions of sensitive customer records, and extorting victims for millions of dollars. The case highlights the growing threat posed by sophisticated cybercriminal groups and serves as a reminder that businesses relying on cloud services remain attractive targets for organized cybercrime.
Connor Riley Moucka, 26, of Kitchener, Ontario, entered guilty pleas in the U.S. District Court for the Western District of Washington to charges including computer fraud, wire fraud, aggravated identity theft, and conspiracy. According to federal prosecutors, Moucka and his co-conspirators carried out a months-long campaign in 2024 that compromised cloud-hosted data belonging to at least 165 customers of a U.S.-based software-as-a-service provider. Although the Justice Department did not identify the company by name in its announcement, multiple cybersecurity reports have identified the affected provider as Snowflake.
Conner Moucka – A Massive Cybercrime Campaign
Federal investigators say the conspiracy operated between February and October 2024. Using stolen login credentials obtained from previously compromised systems, the hackers accessed customer cloud environments, downloaded enormous amounts of sensitive information, and then demanded ransom payments in exchange for not publishing or selling the stolen data.
The stolen information included:
- Banking and financial records.
- Payroll information.
- Social Security numbers.
- Driver’s license and passport numbers.
- Drug Enforcement Administration registration numbers.
- Personally identifiable information.
- Non-content call and text history records affecting more than 100 million AT&T customers.
Investigators said the conspiracy resulted in the theft of billions of customer records and terabytes of confidential information, making it one of the most significant cloud-data theft campaigns uncovered in recent years.
Conner Moucka – Millions Generated Through Extortion
According to court documents, the hackers used the stolen information as leverage, threatening organizations with public disclosure unless ransom payments were made.
Federal prosecutors said the conspiracy collected more than $2.5 million in ransom payments from victims. Authorities also allege that Moucka personally earned nearly $500,000 through extortion payments and the sale of stolen information on cybercrime marketplaces. In at least one instance, prosecutors say he attempted to extort the same victim a second time by threatening to release additional sensitive information involving a government official and members of a former government official’s family.
Conner Moucka – High-Profile Victims
While court filings focus primarily on the criminal conduct rather than individual victims, numerous publicly reported investigations have linked the campaign to several major organizations whose customer data was stolen after attackers gained access to cloud storage accounts.
Among the companies publicly identified in connection with the broader campaign are:
- AT&T
- Ticketmaster
- Santander
- Advance Auto Parts
- Neiman Marcus
- State Farm
- Progressive
- Mitsubishi
- Allstate
- Anheuser-Busch
The breaches affected millions of consumers worldwide and generated months of investigations by both private cybersecurity firms and federal law enforcement agencies.
Conner Moucka – International Investigation
The investigation involved cooperation between the FBI, the Justice Department’s Computer Crime and Intellectual Property Section, the U.S. Attorney’s Office for the Western District of Washington, Canadian authorities, and the Royal Canadian Mounted Police.
Assistant Attorney General A. Tysen Duva said Moucka’s arrest only months after the attacks began demonstrates the Justice Department’s commitment to pursuing sophisticated cybercriminals regardless of where they operate.
FBI officials emphasized that geographic borders no longer shield cybercriminals from prosecution and that international cooperation continues to improve investigators’ ability to identify, locate, extradite, and prosecute offenders responsible for attacks against U.S. businesses and consumers.
Conner Moucka – Potential Prison Sentence
Moucka is scheduled to be sentenced on Oct. 27.
His guilty plea includes:
- Computer fraud.
- Wire fraud.
- Aggravated identity theft.
- Conspiracy.
The aggravated identity theft conviction carries a mandatory minimum prison sentence of two years. The remaining charges carry potential penalties totaling up to 30 additional years in federal prison. The final sentence will be determined by a federal judge after considering the U.S. Sentencing Guidelines and other statutory factors.
Conner Moucka – Lessons for Businesses
The case illustrates a recurring weakness exploited in many modern cyberattacks: compromised credentials rather than sophisticated software vulnerabilities.
Cybersecurity experts have noted that many organizations affected during the broader Snowflake-related attacks relied on usernames and passwords that had previously been stolen through malware infections, while some accounts lacked multi-factor authentication. Once attackers obtained valid credentials, they could access cloud environments without exploiting software flaws.
Organizations can reduce similar risks by:
- Requiring multi-factor authentication for all privileged and cloud accounts.
- Monitoring login activity for unusual geographic locations or abnormal behavior.
- Rotating passwords and access credentials regularly.
- Limiting user privileges to only those necessary for business operations.
- Encrypting sensitive data stored in cloud environments.
- Conducting regular security audits and employee cybersecurity awareness training.
- Maintaining tested offline backups of critical business data.
What Consumers Should Do
Although businesses are typically the direct victims of ransomware and cloud intrusions, consumers often suffer the greatest long-term consequences when personal information is stolen.
Anyone notified that their information may have been exposed in a data breach should consider:
- Changing passwords immediately, particularly if they have been reused across multiple websites.
- Enabling multi-factor authentication wherever available.
- Monitoring bank accounts and credit card activity.
- Reviewing credit reports for unauthorized accounts.
- Remaining cautious of phishing emails or fraudulent phone calls referencing personal information.
- Considering a fraud alert or credit freeze if Social Security numbers or financial information were compromised.
Identity theft frequently occurs months or even years after an initial breach, making continued vigilance important.
Cybercrime Continues to Evolve
The Moucka case reflects the evolution of organized cybercrime from isolated hacking incidents into sophisticated international criminal enterprises that combine credential theft, cloud intrusions, data theft, online extortion, and cryptocurrency payments.
Rather than targeting individual consumers directly, modern cybercriminal groups increasingly attack cloud infrastructure and enterprise service providers, allowing a single successful intrusion to expose information belonging to dozens—or even hundreds—of organizations simultaneously. The widespread impact of the 2024 campaign demonstrates how interconnected digital systems have become and why cybersecurity has become a boardroom issue for organizations of every size.
Federal officials say the guilty plea sends a clear message that international cooperation among law enforcement agencies continues to improve and that cybercriminals who target U.S. businesses should not expect anonymity to protect them indefinitely. While the prosecution marks a significant victory for investigators, experts caution that organizations must continue strengthening their cybersecurity defenses as cloud-based attacks grow in both scale and sophistication.
You can follow this news story on USPress.News as well.