# Snowflake customer-account extortion campaign (UNC5537): Canadian suspect Connor Riley Moucka pleads guilty

> Connor Riley Moucka (26, Kitchener, Ontario; aliases "Judische", "Waifu") pleaded guilty in August 2026 to computer fraud, wire fraud, aggravated identity theft and conspiracy over the 2024 Snowflake customer-account extortions. Using infostealer-sourced credentials against Snowflake accounts lacking MFA, the group breached at least 165 organizations and received over $2.5 million in ransom; sentencing is set for October 27, 2026.

- **Published:** 2026-10-04T00:00:00Z
- **Last reviewed:** 2026-10-04T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2908
- **ID:** TL-2026-2908
- **Severity:** HIGH
- **Category:** DATA_BREACH
- **Status:** MONITORING
- **Actor:** UNC5537
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

This record tracks the legal resolution of a 2024 data-theft and extortion campaign that Mandiant tracks as UNC5537. Between February and October 2024, the actors logged in to Snowflake customer accounts with valid credentials that had previously been stolen by infostealer malware (Mandiant names VIDAR, RISEPRO, REDLINE, RACOON STEALER, LUMMA and METASTEALER). Victim accounts generally lacked multi-factor authentication, had credentials that were never rotated (some valid since 2020), and had no network allow-list. Mandiant and Snowflake attributed the activity to credential theft on customer-side or contractor systems, not to a breach of Snowflake's own platform; roughly 165 organizations were notified in May-June 2024.

On access, the actors used the Snowflake web UI (SnowSight), SnowSQL, DBeaver Ultimate over JDBC, and an attacker-built reconnaissance utility named "rapeflake" (tracked by Mandiant as FROSTBITE; .NET and Java variants plus Python connector use). Observed SQL included SHOW TABLES, LIST/LS on stages, CREATE TEMPORARY STAGE, COPY INTO a stage as gzip CSV, and GET to download the staged files. Connections were routed through commercial VPNs (Mullvad, Private Internet Access) and a Moldovan VPS provider (ALEXHOST SRL, AS200019), and stolen data was stored on MEGA and advertised for sale on cybercrime forums.

Per the August 2026 plea coverage (Krebs on Security, The Register, Security Affairs, Infosecurity Magazine), the conspirators used automated software to search the compromised cloud environments for banking records, payroll data, passport/driver's licence numbers, Social Security numbers and DEA registration numbers, then threatened to publish the data unless victims paid. Initial demands were at least $6 million; payments totalled roughly 36 Bitcoin (over $2.5 million), of which Moucka personally gained at least $495,000, and the group re-extorted at least one victim months after it paid in May 2024. Reported direct victim losses exceed $9.5 million. Named victims include Ticketmaster (Live Nation), Santander, AT&T (call and text records of 100+ million customers), Lending Tree, Advance Auto Parts and Neiman Marcus. Moucka reportedly also threatened government officials and security researchers using stolen personnel data.

Moucka was arrested in Canada in October 2024 in an investigation involving Canadian, Australian, Spanish, Ukrainian and Turkish authorities. Co-conspirators named in reporting are Cameron Wagenius ("Kiberphant0m", a U.S. Army soldier who pleaded guilty in July 2025; sentencing reported as set for September 3, 2026) and John Erin Binns ("IRDev"/"IntelSecrets", indicted, reported at large in Turkey). Moucka faces a mandatory minimum of two years on the identity-theft count and up to 30 years on the remaining counts. Note: sources differ on the plea date (August 5 vs August 6, 2026) and on the extradition date, so neither is asserted here beyond what each cites. This is a legal development on a 2024 campaign; correlate with any prior Snowflake/UNC5537 coverage.

## MITRE ATT&CK

- T1589.001 Gather Victim Identity Information: Credentials
- T1650 Acquire Access
- T1583.003 Acquire Infrastructure: Virtual Private Server
- T1078.004 Valid Accounts: Cloud Accounts
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1213.006 Data from Information Repositories: Databases
- T1530 Data from Cloud Storage
- T1119 Automated Collection
- T1074.002 Data Staged: Remote Data Staging
- T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
- T1657 Financial Theft

## Sources

- [Canadian Man Pleads Guilty in Snowflake Extortions (Krebs on Security)](https://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/)
- [UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion (Mandiant / Google Cloud)](https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion)
- [Canadian Hacker Pleads Guilty Over Snowflake Extortion Campaign (Infosecurity Magazine)](https://infosecurity-magazine.com/news/canadian-hacker-guilty-snowflake)
- [Snowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of Records (Security Affairs)](https://securityaffairs.com/196714/security/snowflake-hacker-pleads-guilty-after-breaching-165-companies-and-stealing-billions-of-records.html)
- [Snowflake extortion plea coverage (The Register)](https://www.theregister.com/a/5284059)
- [Snowflake attacker pleads guilty to hack of 165 companies' data (InfoWorld)](https://www.infoworld.com/article/4206755/snowflake-attacker-pleads-guilty-to-hack-of-165-companies-data-2.html)
- [A guide to threat hunting and monitoring in Snowflake (Datadog Security Labs)](https://securitylabs.datadoghq.com/articles/a-guide-to-threat-hunting-and-monitoring-in-snowflake/)
- [Detect threats in Snowflake: UNC5537 (Hunters)](https://www.hunters.security/en/blog/detect-threats-in-snowflake-unc5537)
- [Snowflake account hacks linked to Santander, Ticketmaster breaches (BleepingComputer)](https://www.bleepingcomputer.com/news/security/snowflake-account-hacks-linked-to-santander-ticketmaster-breaches/)
- [YetiHunter: Open-source threat hunting tool for Snowflake environments (Help Net Security)](https://www.helpnetsecurity.com/2024/06/14/snowflake-threat-hunting/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2908
