ctipilot.ch

UNC5537

actor · actor:unc5537

Mandiant-designated cluster behind the 2024 mass credential-based extortion campaign against customer tenants of a shared cloud data platform. Connor Riley Moucka, a Canadian national operating principally as Judische and Waifu, pleaded guilty on 2026-08-05 to four federal counts over a campaign the U.S. Department of Justice records as compromising over 165 victim organisations, stealing billions of customer records and yielding over $2.5 million in ransom payments; sentencing is set for 2026-10-27. The access path was stolen credentials against tenants that did not enforce multi-factor authentication, with no vulnerability in the provider alleged (DOJ, 2026-08-05; KrebsOnSecurity, 2026-08-06).

Aliases: Judische, Waifu

Coverage timeline
1
first 2026-08-10 → last 2026-08-10
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Related entities below
ATT&CK techniques
2
pinned v19.2 · see below

ATT&CK techniques

2 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-10/unc5537-moucka-guilty-plea-saas-tenant-extortion-template · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-10/unc5537-moucka-guilty-plea-saas-tenant-extortion-template · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-10/unc5537-moucka-guilty-plea-saas-tenant-extortion-template · ATT&CK page ↗

Stealth TA0005

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-10/unc5537-moucka-guilty-plea-saas-tenant-extortion-template · ATT&CK page ↗

Impact TA0040

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-08-10/unc5537-moucka-guilty-plea-saas-tenant-extortion-template · ATT&CK page ↗

Story timeline

  1. 2026-08-10Connor Moucka pleads guilty over the 2024 SaaS-tenant mass-extortion campaign — 165+ victim organisations reached with stolen credentials and no vulnerability in the platform
    active-threatsLaw-enforcement closure on the campaign that set the template for cloud-tenant compromise, with the access path entirely credential-based

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

collaborates with

Where this entity is cited

  • active-threats1

Source distribution

  • justice.gov1 (50%)
  • krebsonsecurity.com1 (50%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about UNC5537 (1)

2026-08-10 · view entry permalink →

NOTABLENATOA1

Connor Moucka pleads guilty over the 2024 SaaS-tenant mass-extortion campaign — 165+ victim organisations reached with stolen credentials and no vulnerability in the platform

The 2024 campaign that taught everyone what a mass SaaS-tenant compromise looks like has reached a guilty plea. The U.S. Department of Justice announced on 2026-08-05 that Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty over a February-to-October 2024 conspiracy involving "the compromise of over 165 victim organizations, the theft of billions of sensitive customer records and the extortion of numerous victims" (U.S. Department of Justice, 2026-08-05). DOJ records that the conspirators received "over $2.5 million in ransom payments", that victim companies suffered over $9.5 million in actual losses excluding harm to their own customers, and that those customers total at least 100 million individuals. He "pleaded guilty to four counts of the indictment, including computer fraud, wire fraud, aggravated identity theft, and a related conspiracy", is scheduled for sentencing on 27 October, and faces a two-year mandatory minimum on the identity-theft count.

The sourcing here needs stating precisely, because the two available accounts do not carry the same facts. DOJ describes the victim platform only as a U.S.-based software-as-a-service company and never names it; the release contains no mention of multi-factor authentication and names no co-conspirator. It is KrebsOnSecurity that supplies the platform's identity and the access precondition: "The hackers targeted stolen credentials for Snowflake customer accounts that did not enforce multi-factor authentication, and extorted or attempted to extort a host of well-known companies… Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication" (KrebsOnSecurity, 2026-08-06). Krebs also supplies Moucka's operating aliases, and identifies an admitted co-conspirator — a U.S. Army soldier who pleaded guilty in July 2025 to extorting two telecommunications carriers for customer account data and who is separately scheduled for sentencing on 2026-09-03.

The reason this belongs in front of a public-sector SOC two years after the fact is the shape of the access path, which both sources agree on: stolen credentials used against customer-controlled tenants of a shared data platform. No vulnerability in the provider is alleged by either account. The platform did what platforms do — it enforced the authentication policy each tenant configured — and the tenants that had not enforced a second factor were the ones that lost data. Every public administration that has moved reporting, analytics or case data onto a shared cloud data platform holds that same risk shape, and holds it on the tenant side where the provider's own security posture is not the deciding variable.

the compromise of over 165 victim organizations, the theft of billions of sensitive customer records and the extortion of numerous victims

The conspirators profited from the scheme, receiving over $2.5 million in ransom payments.

Moucka pleaded guilty to four counts of the indictment, including computer fraud, wire fraud, aggravated identity theft, and a related conspiracy. He is scheduled to be sentenced on Oct. 27 and faces a mandatory minimum penalty of two years in prison on the aggravated identity theft count and a maximum penalty of 30 years in prison on the remaining counts.

U.S. Department of Justice 2026-08-05

The hackers targeted stolen credentials for Snowflake customer accounts that did not enforce multi-factor authentication, and extorted or attempted to extort a host of well-known companies, including TicketMaster, Lending Tree, Advance Auto Parts and Neiman Marcus. Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.

KrebsOnSecurity 2026-08-06
incident10 Aug 04:53Zmulti-sourceOpen finding ↗