Connor Moucka pleads guilty over the 2024 SaaS-tenant mass-extortion campaign — 165+ victim organisations reached with stolen credentials and no vulnerability in the platform
The 2024 campaign that taught everyone what a mass SaaS-tenant compromise looks like has reached a guilty plea. The U.S. Department of Justice announced on 2026-08-05 that Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty over a February-to-October 2024 conspiracy involving "the compromise of over 165 victim organizations, the theft of billions of sensitive customer records and the extortion of numerous victims" (U.S. Department of Justice, 2026-08-05). DOJ records that the conspirators received "over $2.5 million in ransom payments", that victim companies suffered over $9.5 million in actual losses excluding harm to their own customers, and that those customers total at least 100 million individuals. He "pleaded guilty to four counts of the indictment, including computer fraud, wire fraud, aggravated identity theft, and a related conspiracy", is scheduled for sentencing on 27 October, and faces a two-year mandatory minimum on the identity-theft count.
The sourcing here needs stating precisely, because the two available accounts do not carry the same facts. DOJ describes the victim platform only as a U.S.-based software-as-a-service company and never names it; the release contains no mention of multi-factor authentication and names no co-conspirator. It is KrebsOnSecurity that supplies the platform's identity and the access precondition: "The hackers targeted stolen credentials for Snowflake customer accounts that did not enforce multi-factor authentication, and extorted or attempted to extort a host of well-known companies… Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication" (KrebsOnSecurity, 2026-08-06). Krebs also supplies Moucka's operating aliases, and identifies an admitted co-conspirator — a U.S. Army soldier who pleaded guilty in July 2025 to extorting two telecommunications carriers for customer account data and who is separately scheduled for sentencing on 2026-09-03.
The reason this belongs in front of a public-sector SOC two years after the fact is the shape of the access path, which both sources agree on: stolen credentials used against customer-controlled tenants of a shared data platform. No vulnerability in the provider is alleged by either account. The platform did what platforms do — it enforced the authentication policy each tenant configured — and the tenants that had not enforced a second factor were the ones that lost data. Every public administration that has moved reporting, analytics or case data onto a shared cloud data platform holds that same risk shape, and holds it on the tenant side where the provider's own security posture is not the deciding variable.
the compromise of over 165 victim organizations, the theft of billions of sensitive customer records and the extortion of numerous victims
The conspirators profited from the scheme, receiving over $2.5 million in ransom payments.
Moucka pleaded guilty to four counts of the indictment, including computer fraud, wire fraud, aggravated identity theft, and a related conspiracy. He is scheduled to be sentenced on Oct. 27 and faces a mandatory minimum penalty of two years in prison on the aggravated identity theft count and a maximum penalty of 30 years in prison on the remaining counts.
The hackers targeted stolen credentials for Snowflake customer accounts that did not enforce multi-factor authentication, and extorted or attempted to extort a host of well-known companies, including TicketMaster, Lending Tree, Advance Auto Parts and Neiman Marcus. Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.
ATT&CK mapping
2 techniques mapped from the cited reporting · MITRE ATT&CK v19.2
Initial Access TA0001
T1078.004Valid Accounts: Cloud Accounts
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Persistence TA0003
T1078.004Valid Accounts: Cloud Accounts
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Privilege Escalation TA0004
T1078.004Valid Accounts: Cloud Accounts
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Stealth TA0005
T1078.004Valid Accounts: Cloud Accounts
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Impact TA0040
T1657Financial Theft
Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.