Connor Riley Moucka has pleaded guilty over his role in a cybercrime campaign that involved hacking into the Snowflake accounts of 165 organizations.
The 26-year-old has pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy, and faces more than 30 years in prison. Sentencing is scheduled for October 27.
The man was arrested in late 2024 in Canada and was extradited to the United States in July 2025.
According to authorities, Moucka (reported in initial news coverage under the name Alexander ‘Connor’ Moucka) was part of a cybercrime group that used stolen login credentials to access data stored by organizations in their Snowflake data storage accounts.
The campaign, attributed to a threat actor tracked as UNC5537, impacted organizations such as AT&T, Advance Auto Parts, Ticketmaster, Santander Bank, Neiman Marcus, Anheuser-Busch, Allstate, Mitsubishi, Progressive, and State Farm.
The hackers stole billions of sensitive data records, including personal and financial information, and extorted victims. The DOJ says they received $2.5 million in ransom payments.
In addition, the cybercriminals sold the stolen data on hacking forums, with Moucka obtaining half a million dollars.
The DOJ said targeted companies suffered losses totaling more than $9.5 million, which does not include the losses of their customers — at least 100 million people.
A former US soldier who pleaded guilty roughly one year ago to hacking into AT&T and Verizon systems is also believed to have participated in the Snowflake campaign.
Related: Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison
Related: Two Scattered Spider Hackers Sentenced to Jail in UK
Related: US Charges Russian Individuals and Firms for Running Cybercrime Services