Threat reportData BreachTL-2026-2908
Snowflake customer-account extortion campaign (UNC5537): Canadian suspect Connor Riley Moucka pleads guilty
Snowflake customer-account extortion campaign (UNC5537) (TL-2026-2908), also tracked as Snowflake data theft and extortion campaign, is a high-severity data breach, first published 2026-10-04. It is attributed to UNC5537 with high confidence, affects Snowflake Snowflake customer accounts (no MFA, no network policy), maps to 11 MITRE ATT&CK techniques (T1074.002, T1078.004, T1119), and is covered by 9 detection rules and 20 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 11MITRE ATT&CK
- Actors
- 1UNC5537
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-2908
- Threat ID
- TL-2026-2908
- Also known as
- Snowflake data theft and extortion campaign, UNC5537 Snowflake campaign
- Severity
- HIGH
- Status
- MONITORING
- Category
- DATA_BREACH
- First published
- Last reviewed
- Attribution
- UNC5537
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- telecoms, entertainment, retail, finance, automotive
- Target regions
- North America
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Snowflake customer-account extortion campaign (UNC5537)
Malware and tooling: LUMMA, MetaStealer, RACOON STEALER, REDLINE, RisePro, Vidar, DBeaver Ultimate, FROSTBITE
How Snowflake customer-account extortion campaign (UNC5537) works
Connor Riley Moucka (26, Kitchener, Ontario; aliases "Judische", "Waifu") pleaded guilty in August 2026 to computer fraud, wire fraud, aggravated identity theft and conspiracy over the 2024 Snowflake customer-account extortions. Using infostealer-sourced credentials against Snowflake accounts lacking MFA, the group breached at least 165 organizations and received over $2.5 million in ransom; sentencing is set for October 27, 2026.
This record tracks the legal resolution of a 2024 data-theft and extortion campaign that Mandiant tracks as UNC5537. Between February and October 2024, the actors logged in to Snowflake customer accounts with valid credentials that had previously been stolen by infostealer malware (Mandiant names VIDAR, RISEPRO, REDLINE, RACOON STEALER, LUMMA and METASTEALER). Victim accounts generally lacked multi-factor authentication, had credentials that were never rotated (some valid since 2020), and had no network allow-list. Mandiant and Snowflake attributed the activity to credential theft on customer-side or contractor systems, not to a breach of Snowflake's own platform; roughly 165 organizations were notified in May-June 2024.
On access, the actors used the Snowflake web UI (SnowSight), SnowSQL, DBeaver Ultimate over JDBC, and an attacker-built reconnaissance utility named "rapeflake" (tracked by Mandiant as FROSTBITE; .NET and Java variants plus Python connector use). Observed SQL included SHOW TABLES, LIST/LS on stages, CREATE TEMPORARY STAGE, COPY INTO a stage as gzip CSV, and GET to download the staged files. Connections were routed through commercial VPNs (Mullvad, Private Internet Access) and a Moldovan VPS provider (ALEXHOST SRL, AS200019), and stolen data was stored on MEGA and advertised for sale on cybercrime forums.
Per the August 2026 plea coverage (Krebs on Security, The Register, Security Affairs, Infosecurity Magazine), the conspirators used automated software to search the compromised cloud environments for banking records, payroll data, passport/driver's licence numbers, Social Security numbers and DEA registration numbers, then threatened to publish the data unless victims paid. Initial demands were at least $6 million; payments totalled roughly 36 Bitcoin (over $2.5 million), of which Moucka personally gained at least $495,000, and the group re-extorted at least one victim months after it paid in May 2024. Reported direct victim losses exceed $9.5 million. Named victims include Ticketmaster (Live Nation), Santander, AT&T (call and text records of 100+ million customers), Lending Tree, Advance Auto Parts and Neiman Marcus. Moucka reportedly also threatened government officials and security researchers using stolen personnel data.
Moucka was arrested in Canada in October 2024 in an investigation involving Canadian, Australian, Spanish, Ukrainian and Turkish authorities. Co-conspirators named in reporting are Cameron Wagenius ("Kiberphant0m", a U.S. Army soldier who pleaded guilty in July 2025; sentencing reported as set for September 3, 2026) and John Erin Binns ("IRDev"/"IntelSecrets", indicted, reported at large in Turkey). Moucka faces a mandatory minimum of two years on the identity-theft count and up to 30 years on the remaining counts. Note: sources differ on the plea date (August 5 vs August 6, 2026) and on the extradition date, so neither is asserted here beyond what each cites. This is a legal development on a 2024 campaign; correlate with any prior Snowflake/UNC5537 coverage.
MITRE ATT&CK techniques used in TL-2026-2908
Collection
T1074.002 Data Staged: Remote Data Staging; T1119 Automated Collection; T1213.006 Data from Information Repositories: Databases; T1530 Data from Cloud Storage
Initial Access
T1078.004 Valid Accounts: Cloud Accounts
Credential Access
T1555.003 Credentials from Password Stores: Credentials from Web Browsers
Exfiltration
T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
Resource Development
T1583.003 Acquire Infrastructure: Virtual Private Server; T1650 Acquire Access
Reconnaissance
T1589.001 Gather Victim Identity Information: Credentials
Impact
Affected products and versions in Snowflake customer-account extortion campaign (UNC5537)
- Snowflake — Snowflake customer accounts (no MFA, no network policy)
Vulnerable versions: Customer accounts with single-factor authentication and unrotated credentials
Fixed in: Accounts enforcing MFA and network policies
Remediation for Snowflake customer-account extortion campaign (UNC5537)
Immediate actions
- Run Snowflake's published IOC and login-history hunting queries over the full retention window (365 days) for logins from listed IPs and the client application IDs below
- Disable and rotate credentials for any Snowflake user showing access from unexpected IPs, VPN/VPS ranges or unapproved client applications
- Review ACCESS_HISTORY/QUERY_HISTORY for CREATE TEMPORARY STAGE, COPY INTO @stage and GET activity indicating bulk export
Workarounds
- Use Snowflake account-level policies to require MFA and restrict network access until per-user controls are rolled out
Longer-term hardening
- Enforce MFA for all human Snowflake users and prefer SSO/key-pair auth for service accounts
- Configure Snowflake network policies (IP allow-lists) at account and user level
- Rotate credentials on a schedule and monitor for infostealer exposure of employee and contractor credentials
- Alert on anomalous query volume, new client application IDs and data-egress spikes
Weaknesses (CWE) in Snowflake customer-account extortion campaign (UNC5537)
Timeline of Snowflake customer-account extortion campaign (UNC5537)
- Earliest infostealer infection date Mandiant associated with a credential later used by UNC5537 (month precision).
- Per the indictment-based reporting, the Snowflake customer-account intrusion and extortion campaign begins (February 2024; month precision).
- Mandiant's example log shows a DBeaver Ultimate (JDBC 3.13.30) login from 37.19.210.21; Snowflake saw increased threat activity from mid-April 2024.
- Mandiant contacts Snowflake after receiving intelligence on stolen database records; victim notification begins.
- Snowflake publishes detection and hardening guidance including IOCs and investigative queries.
- Mandiant publishes its UNC5537 report: ~165 organizations notified, FROSTBITE tool, infostealer-sourced credentials, no MFA.
- Connor Riley Moucka arrested in Canada in a multinational investigation (Canada, Australia, Spain, Ukraine, Turkey); month precision.
- Co-conspirator Cameron Wagenius (Kiberphant0m) pleads guilty (July 2025; month precision).
- Moucka pleads guilty to computer fraud, wire fraud, aggravated identity theft and conspiracy (sources cite Aug 5 or Aug 6, 2026).
- Sentencing for Wagenius was reported as scheduled for this date; outcome not confirmed in the sources reviewed.
- Moucka sentencing scheduled; mandatory minimum 2 years on identity theft count, up to 30 years on remaining counts.
Sources cited for Snowflake customer-account extortion campaign (UNC5537)
- Canadian Man Pleads Guilty in Snowflake Extortions (Krebs on Security)
- UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion (Mandiant / Google Cloud)
- Canadian Hacker Pleads Guilty Over Snowflake Extortion Campaign (Infosecurity Magazine)
- Snowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of Records (Security Affairs)
- Snowflake extortion plea coverage (The Register)
- Snowflake attacker pleads guilty to hack of 165 companies' data (InfoWorld)
- A guide to threat hunting and monitoring in Snowflake (Datadog Security Labs)
- Detect threats in Snowflake: UNC5537 (Hunters)
- Snowflake account hacks linked to Santander, Ticketmaster breaches (BleepingComputer)
- YetiHunter: Open-source threat hunting tool for Snowflake environments (Help Net Security)
Detection coverage for TL-2026-2908
As of 2026-10-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2908 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.