Actor Profile
Connor Riley Moucka (also known as Alexander Moucka and "Waifu"), a 26-year-old Canadian national, operated as a cybercriminal targeting cloud storage environments for financial gain. Between February and October 2024, Moucka collaborated with co-conspirator John Erin Binns to conduct unauthorized access operations against Snowflake cloud storage customers. The actor's motivation was purely financial, conducting both direct extortion of breached organizations and selling stolen data on underground forums. Moucka obtained at least $2.5 million in Bitcoin from extortion payments and approximately $495,000 from data sales. The operation affected at least 165 organizations and over 100 million individuals, resulting in more than $9.5 million in victim losses. Moucka was arrested on October 30, 2024, and pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy charges, facing a maximum sentence of 32 years in prison.
TTPs (Tactics, Techniques, Procedures)
The primary attack vector involved credential-based access (T1078: Valid Accounts) to Snowflake cloud storage instances that lacked multi-factor authentication protection. Initial access credentials were obtained via infostealer malware infections on victim organization endpoints (T1555: Credentials from Password Stores, T1539: Steal Web Session Cookie). Once authenticated, the actors conducted discovery activities (T1087: Account Discovery, T1018: Remote System Discovery) using custom software to identify valuable information including organization names, user roles, and IP addresses within cloud storage environments. The operation involved large-scale data exfiltration (T1567: Exfiltration Over Web Service) of terabytes of sensitive information including call records, financial data, payroll information, DEA registration numbers, and PII. Post-compromise, the actors engaged in extortion (T1657: Financial Theft) demanding cryptocurrency payments and advertised stolen data for sale on underground forums. In at least one instance, the actor conducted re-extortion using stolen data of government officers and their family members to increase pressure on victims.
Targets & Patterns
The campaign targeted organizations across multiple industries utilizing Snowflake cloud storage services, with at least 165 confirmed victims. High-profile targets included telecommunications (AT&T), entertainment/ticketing (Ticketmaster), financial services (Santander), technology (Pure Storage), retail (Advance Auto Parts, Neiman Marcus), education (Los Angeles Unified), and insurance/financial services (QuoteWizard/LendingTree). The targeting pattern suggests opportunistic victim selection based on two criteria: organizations using Snowflake cloud storage and accounts lacking MFA protection. The breadth of affected sectors indicates the actors prioritized access feasibility over sector-specific targeting. Victim selection was likely driven by the value and monetization potential of stored data, particularly organizations holding large volumes of consumer PII, financial records, and telecommunications metadata. The geographic focus was primarily North American organizations, though the use of a cloud service provider created a force-multiplier effect allowing mass compromise through a single attack methodology.
Historical Context
This campaign represents one of the most significant cloud storage breach incidents to date, affecting over 100 million individuals and resulting in $9.5 million in direct victim losses. The Snowflake compromise wave occurred between February and October 2024, with Moucka's arrest on October 30, 2024, marking the operational conclusion. Co-conspirator John Erin Binns was arrested in Turkey with extradition proceedings contested. The campaign prompted Snowflake to implement mandatory security controls, including enforced MFA protection and minimum 14-character password requirements for all accounts. The breach disclosure timeline extended through 2024 as affected organizations including AT&T, Ticketmaster, Santander, and others publicly acknowledged compromises. Related threat activity includes the ShinyHunters extortion gang, which has claimed responsibility for subsequent breaches affecting Ernst & Young, Lidl, Aflac, NAIC, and Kodak, suggesting potential operational connections or copycat activity in the cloud storage extortion space following the Snowflake campaign's visibility.
Defensive Recommendations
- Enforce multi-factor authentication (MFA) on all cloud storage and SaaS platform accounts, particularly those containing sensitive data; prioritize phishing-resistant MFA methods such as FIDO2/WebAuthn tokens to mitigate credential theft via infostealer malware
- Deploy endpoint detection capabilities to identify infostealer malware families (e.g., Redline, Raccoon, Vidar) that harvest browser-stored credentials and session tokens; monitor for suspicious credential access patterns (MITRE T1555, T1539)
- Implement cloud access security broker (CASB) solutions or native cloud platform monitoring to detect anomalous authentication patterns including impossible travel, unusual IP addresses, and access from anonymization services for cloud storage platforms
- Establish data loss prevention (DLP) controls and monitor for large-scale data exfiltration from cloud storage environments; set alerts for bulk downloads or API-based data extraction exceeding baseline thresholds (MITRE T1567)
- Conduct regular audits of cloud storage account security configurations, enforce minimum password complexity requirements (14+ characters), and implement conditional access policies restricting access from high-risk locations or unmanaged devices
---
# Geopolitical Context
Geopolitical Context
This case represents a significant transnational cybercriminal operation targeting cloud infrastructure, with a Canadian national and a U.S.-based co-conspirator exploiting weak authentication controls at Snowflake to breach 165 organizations across multiple sectors. The operation, which ran from February to October 2024, resulted in the theft of data affecting over 100 million individuals and caused more than $9.5 million in direct losses to victim organizations. The attackers leveraged infostealer malware to harvest credentials for accounts lacking multi-factor authentication, then systematically identified and exfiltrated high-value data for extortion and resale on underground forums. The case underscores the persistent threat posed by financially motivated cybercriminals operating across jurisdictions, the vulnerability of cloud services to credential-based attacks, and the challenges of international law enforcement coordination—illustrated by the contested extradition of co-conspirator John Erin Binns from Turkey. The guilty plea and potential 32-year sentence may signal strengthened U.S. prosecutorial resolve against large-scale data theft operations.
State Actor Alignment
This incident appears to be purely criminal in nature, with no indicators of state sponsorship or alignment. Connor Riley Moucka (also known as "Waifu") and John Erin Binns operated as financially motivated cybercriminals seeking monetary gain through extortion and data sales. The attackers obtained at least $2.5 million in bitcoin from extortion victims and an additional $495,000 from selling stolen data on underground forums. The case involved law enforcement cooperation between the United States and Canada, resulting in Moucka's arrest in Canada on October 30, 2024, and subsequent prosecution in U.S. federal court. Binns, who resided in Turkey at the time of the attacks, was arrested there following a U.S. extradition request, though the extradition has been contested. The U.S. Department of Justice's prosecution reflects standard criminal enforcement mechanisms rather than sanctions frameworks typically applied to state-sponsored cyber operations.
Business Impacty pro region
The Snowflake breach campaign demonstrates the global reach and impact of cloud-focused cybercrime, affecting organizations across North America and Europe. Major victims included U.S. telecommunications provider AT&T, entertainment platform Ticketmaster, Spanish banking institution Santander, and numerous other enterprises spanning financial services, retail, education, and technology sectors. The breach of over 100 million individuals' personal data—including call records, financial information, Social Security numbers, and government identification documents—creates significant privacy and security risks across multiple jurisdictions, potentially triggering regulatory actions under frameworks such as GDPR in Europe and various state-level breach notification laws in the United States. The case highlights vulnerabilities in the cloud service provider ecosystem that transcend national boundaries, as a single platform's security weaknesses enabled cascading breaches across diverse sectors and geographies. Snowflake's post-incident decision to mandate MFA and strengthen password requirements reflects broader industry pressure to enhance baseline security controls for cloud infrastructure. The contested extradition from Turkey may indicate ongoing friction in cyber law enforcement cooperation between NATO allies, particularly regarding U.S. requests for individuals involved in cyber operations.
Forecast
If Moucka receives a substantial sentence approaching the 32-year maximum, it may serve as a deterrent signal to other financially motivated actors targeting cloud infrastructure, though the effectiveness of such deterrence remains uncertain given the continued profitability of credential-based attacks. If Binns' extradition from Turkey is ultimately unsuccessful, it could embolden cybercriminals to operate from jurisdictions with complex or strained extradition relationships with Western law enforcement, potentially shifting operational bases for similar campaigns. If cloud service providers broadly adopt mandatory MFA and stronger authentication controls in response to this incident, the barrier to entry for credential-stuffing attacks may increase, likely pushing threat actors toward more sophisticated initial access methods such as MFA bypass techniques or supply chain compromises. If regulatory authorities in Europe and North America impose significant penalties on affected organizations for inadequate security controls, it may accelerate enterprise adoption of zero-trust architectures and enhanced identity governance frameworks. The case is likely to inform ongoing policy discussions regarding cloud security standards, shared responsibility models, and the adequacy of existing breach notification regimes in addressing systemic vulnerabilities in critical digital infrastructure.
