Canadian Suspect Arrested Over Snowflake Customer Breach and Extortion Attacks

Teilen:

Canadian law enforcement authorities have arrested an individual who is suspected to have conducted a series of hacks stemming from the breach of cloud data warehousing platform Snowflake earlier this year.

The individual in question, Alexander “Connor” Moucka (aka Judische and Waifu), was apprehended on October 30, 2024, on the basis of a provisional arrest warrant, following a request by the U.S.

The development was first reported by Bloomberg and corroborated by 404 Media. The exact nature of the charges against Moucka is currently not known.

In June 2024, Snowflake disclosed that a “limited number” of its customers were targeted as part of a targeted campaign. Later, Google-owned Mandiant attributed it to a financially motivated threat group called UNC5537.

“UNC5537 comprises members based in North America, and collaborates with an additional member in Turkey,” the company assessed with moderate confidence at the time, adding approximately 165 organizations were impacted.

Some of the targeted companies included major corporations such as Advance Auto Parts, AT&T, LendingTree, Neiman Marcus, Santander, and Ticketmaster (Live Nation).

In some of the incidents, the threat actor(s) attempted to extort the companies by threatening to sell the stolen data on criminal forums if they didn’t pay up. AT&T reportedly paid the hackers $370,000 to delete the stolen data, according to WIRED.

The attacks worked by leveraging stolen customer credentials obtained via prior stealer malware infections to obtain initial access. The investigation also found that the initial compromise of infostealer malware occurred on contractor systems that were used for downloading games and pirated software.

Reports published by Krebs On Security and 404 Media in September 2024 revealed that Judische is likely based in Canada and has connections to a broader cybercrime ecosystem called the Com, which is known to engage in physical and digital attacks, sometimes resorting to violence, to gain access to accounts and steal funds from rivals.

Judische is also believed to have collaborated with another hacker called John Binns, who was arrested in Turkey in May 2024.

Update

The U.S. Department of Justice has unsealed an indictment accusing Connor Riley Moucka and John Erin Binns of using credentials obtained via information stealers to breach at least 10 Snowflake customers and exfiltrate sensitive data in exchange for ransom payments.

This included “approximately 50 billion customer call and text records” from a “major telecommunications” company in the U.S., court documents said, likely referencing AT&T. The defendants have also been alleged to conceal the money trail by routing the funds through “a complex series of cryptocurrency transactions.”

In all, the two hackers are estimated to have extorted three victims for at least 36 bitcoins, valued at roughly $2.5 million at the time of the payment. They also attempted to sell the stolen data, harvested using a tool dubbed Rapeflake, on cybercriminal forums for millions of dollars.

“Through this scheme, the co-conspirators gained unlawful access to billions of sensitive customer records, including individuals’ non-content call and text history records, banking and other financial information, payroll records, Drug Enforcement Agency (‘DEA’) registration numbers, driver’s license numbers, passport numbers, Social Security numbers, and other personally identifiable information,” it said.

Ravie Lakshmanan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:00 pm, Juli 1, 2025
Wetter-Symbol 31°C
L: 30° | H: 33°
overcast clouds
Luftfeuchtigkeit: 49 %
Druck: 1013 mb
Wind: 6 mph
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 96%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:47 am
Sonnenuntergang: 9:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
30° | 33°°C 0 mm 0% 10 mph 61 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
18° | 22°°C 1 mm 100% 10 mph 88 % 1023 mb 0 mm/h
Do. Juli 03 10:00 pm
Wetter-Symbol
13° | 26°°C 0 mm 0% 9 mph 56 % 1029 mb 0 mm/h
Fr. Juli 04 10:00 pm
Wetter-Symbol
15° | 26°°C 0 mm 0% 9 mph 50 % 1028 mb 0 mm/h
Sa. Juli 05 10:00 pm
Wetter-Symbol
16° | 23°°C 1 mm 100% 14 mph 93 % 1021 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
30° | 31°°C 0 mm 0% 7 mph 50 % 1013 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
31° | 32°°C 0 mm 0% 10 mph 43 % 1013 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
31° | 31°°C 0 mm 0% 10 mph 38 % 1012 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 8 mph 61 % 1014 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 6 mph 70 % 1015 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 5 mph 79 % 1016 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 6 mph 76 % 1016 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 4 mph 62 % 1016 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€90,312.51
-1.12%
Ethereum(ETH)
€2,082.92
-0.04%
Fesseln(USDT)
€0.85
0.00%
XRP(XRP)
€1.87
1.17%
Solana(SOL)
€126.41
-0.87%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.137021
-2.00%
Shiba Inu(SHIB)
€0.000009
-1.48%
Pepe(PEPE)
€0.000008
-3.02%
Nach oben scrollen