A 26-year-old Canadian man arrested in October 2024 pleaded guilty last week to a string of data breaches targeting compromised Snowflake instances between February and October 2024.
Connor Riley Moucka, alongside several co-conspirators, used stolen login credentials to access data belonging to at least 165 victim organisations before then using that data to extort those victims.
According to court documents, that data included billions of customer records totalling terabytes of information. The pair received more than US$2.5 million in ransom payments.
The hacker’s victims included Santander, QuoteWizard, and Ticketmaster.
“Hiding behind a screen is no shield from justice,” assistant director Brett Leatherman of the FBI’s Cyber Division said in an 5 August statement from the Department of Justice.
“Connor Moucka learned that when he was arrested just months after he began targeting US companies, stealing sensitive information, and extorting victims for millions of dollars. His guilty plea highlights the FBI’s commitment to protecting American businesses and consumers from cyber crime and reflects our strong partnership with the Royal Canadian Mounted Police and other international law enforcement agencies. The FBI will continue to identify, locate, and hold cyber criminals accountable, wherever they operate.”
Special agent in charge W. Mike Herrington of the FBI Seattle field office said Moucka’s guilty plea sent a message to his fellow hackers: “You cannot hide from justice, no matter how hard you may try to cover your tracks.”
“Connor Moucka’s threats and re-extortion tactics were calculated and predatory, and his actions did real harm to his victims, be they companies targeted for theft and extortion or the millions of everyday people who are their customers.
“Ultimately, though, Mr Moucka’s schemes were no match for the tenacity of FBI Seattle and this international investigative team. I am incredibly proud of their work. Let this outcome serve as a reminder: actions have consequences, and the FBI will continue to relentlessly pursue those who target American businesses and individuals in cyber space, wherever they may be.”
While the FBI led the investigation, several other law enforcement agencies provided “substantial assistance”, including the Royal Canadian Mounted Police, the Australian Federal Police, Spain’s Guardia Civil, the Security Service of Ukraine, and the Turkish National Police.
The investigation and subsequent arrest were carried out under the auspices of Operation Riptide.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.