A hacker has pleaded guilty in the case tied to data theft from more than 165 Snowflake customers.
TechCrunch reported that Connor Moucka, a 26-year-old Canadian citizen, pleaded guilty after being accused of hacking more than 165 companies, stealing billions of records, and extorting several companies and individuals. The US Department of Justice announced the plea on 6 August 2026, turning a widely watched breach campaign into a clearer legal milestone.
The case matters because prosecutors tied the campaign to Snowflake, a cloud data platform used by many organisations to store and analyse data. According to the report, hacking Snowflake allowed Moucka and his co-conspirators to break into dozens of customers, including AT&T, LendingTree, and Ticketmaster.
What changed in the case
What changed now is the legal status: the case has moved from accusation to a guilty plea. According to TechCrunch's report on the Justice Department announcement, Moucka pleaded guilty to conduct tied to hacks affecting more than 165 companies.
The article says the campaign brought in more than $2.5 million in ransom payments over time for Moucka and his accomplices. It also says Moucka received about $500,000 from selling victims' data on hacking forums, including BreachForums. TechCrunch, citing the Department of Justice, reported that victims suffered $9.5 million in losses.
The report adds that Moucka was arrested in Canada at the end of 2024, months after the Snowflake breaches, and is scheduled to be sentenced on 27 October. TechCrunch says he faces decades in prison.
What the Snowflake link means in plain English
Snowflake is described in the reporting as a cloud provider. In practical terms, that means companies use it to hold and work with data in remote systems rather than only on their own on-site servers. When attackers gain access connected to that platform, the impact can spread across many customer organisations if customer environments are then reached through that access.
TechCrunch said Moucka was accused of hacking Snowflake, which then allowed him and his co-conspirators to break into dozens of Snowflake customers. The article does not provide a deeper technical walkthrough of how that access was obtained or used, so the safest conclusion from the source is limited: investigators tied the customer breaches to an intrusion involving the cloud provider.
That distinction matters. The source supports saying this was not framed as a breach at only one end company. It was a case in which one cloud-related compromise was linked to many downstream victims.
Who was affected and what data was taken
The report names several victims, including AT&T, LendingTree, and Ticketmaster. According to TechCrunch, data from more than 100 million AT&T customers was stolen, including call and texting records.
The same report says other breaches involved banking information, driver's licence numbers, and Social Security numbers. That mix shows the campaign was not limited to one type of data. It included communications records and highly sensitive personal information that can have consequences for both companies and their customers.
The article also notes that Moucka was known online as Waifu and Judische. TechCrunch adds that Austin Larsen, a senior researcher at Google's cybersecurity firm Mandiant who had been investigating the Snowflake hacks, previously said Moucka was “one of the most consequential” hackers of 2024.
Why this plea matters beyond one case
The source does not establish every technical detail of how the breaches worked, and it does not say which specific controls would have stopped them. What it does establish is narrower and important: prosecutors say one campaign tied to Snowflake reached more than 165 companies, exposed highly sensitive data, and produced millions of dollars in losses.
The strongest conclusion supported by this report is that cloud-related access failures can have consequences far beyond a single victim when many organisations depend on the same platform. The next thing worth watching is not a broad prediction about the whole industry, but the harder details that may emerge from sentencing and any later disclosures about how the campaign worked in practice.