Suspect behind Snowflake data-theft attacks arrested in Canada

Share:

Canadian authorities have arrested a man suspected of having stolen the data of hundreds of millions after targeting over 165 organizations, all of them customers of cloud storage company Snowflake.

According to Canada’s Department of Justice, Alexander “Connor” Moucka (aka “Waifu” and “Judische”) was taken into custody on Wednesday at the request of the United States and is scheduled to appear in court again today, as first reported by Bloomberg and confirmed by 404 Media.

“Following a request by the United States, Alexander Moucka (a.k.a. Connor Moucka) was arrested on a provisional arrest warrant on Wednesday October 30, 2024,” Ian McLeod, a spokesperson for Canada’s Department of Justice, told BleepingComputer on Tuesday.

“He appeared in court later that afternoon and his case was adjourned to Tuesday November 5, 2024. As extradition requests are considered confidential state-to-state communications, we cannot comment further on this case.”

A joint investigation by SnowFlake, Mandiant, and CrowdStrike found that an attacker (tracked at the time as UNC5537) used customer credentials stolen using infostealer malware to target at least 165 organizations that failed to configure multi-factor authentication (MFA) protection on their SnowFlake accounts.

Snowflake attack flow
Snowflake attack flow (Mandiant)

That is just a tiny part of the 9,400 Snowflake customers, with the complete list including some of the largest companies worldwide, such as Mastercard, Micron, NBC Universal, Capital One, Adobe, AT&T, Kraft Heinz, Doordash, HP, Okta, PepsiCo, Siemens, US Foods, Western Union, Yamaha, and many others.

Data breaches linked to these attacks, which started in April 2024, have affected hundreds of millions of individuals using the services of AT&T, Ticketmaster, Santander, Pure Storage, Advance Auto Parts, Los Angeles Unified, QuoteWizard/LendingTree, and Neiman Marcus.

In late May, Ticketmaster confirmed that data was stolen from its Snowflake account after a threat actor known as ShinyHunters began the data of 560 million Ticketmaster customers.

In July, AT&T also warned of a massive data breach after threat actors stole the call logs of approximately 109 million customers (nearly all of its mobile customers) from an online database on the company’s Snowflake account between April 14 and April 25, 2024.

Snowflake has since announced that it will enforce multi-factor authentication (MFA) for accounts created starting in October 2024 and require that all passwords be at least 14 characters long.

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
2:50 am, Feb 2, 2025
weather icon 0°C
L: -1° | H: 1°
mist
Humidity: 95 %
Pressure: 1023 mb
Wind: 1 mph ENE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 20%
Rain Chance: 0%
Visibility: 5 km
Sunrise: 7:37 am
Sunset: 4:51 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
-1° | 1°°C 0 mm 0% 7 mph 95 % 1025 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
3° | 10°°C 0 mm 0% 7 mph 92 % 1025 mb 0 mm/h
Tue Feb 04 9:00 pm
weather icon
6° | 10°°C 1 mm 100% 12 mph 92 % 1026 mb 0 mm/h
Wed Feb 05 9:00 pm
weather icon
4° | 7°°C 0 mm 0% 9 mph 86 % 1045 mb 0 mm/h
Thu Feb 06 9:00 pm
weather icon
2° | 7°°C 0 mm 0% 9 mph 87 % 1045 mb 0 mm/h
Today 3:00 am
weather icon
0° | 3°°C 0 mm 0% 4 mph 95 % 1023 mb 0 mm/h
Today 6:00 am
weather icon
1° | 2°°C 0 mm 0% 5 mph 91 % 1023 mb 0 mm/h
Today 9:00 am
weather icon
2° | 3°°C 0 mm 0% 5 mph 83 % 1022 mb 0 mm/h
Today 12:00 pm
weather icon
7° | 7°°C 0 mm 0% 7 mph 62 % 1023 mb 0 mm/h
Today 3:00 pm
weather icon
8° | 8°°C 0 mm 0% 7 mph 56 % 1022 mb 0 mm/h
Today 6:00 pm
weather icon
5° | 5°°C 0 mm 0% 4 mph 72 % 1024 mb 0 mm/h
Today 9:00 pm
weather icon
4° | 4°°C 0 mm 0% 4 mph 78 % 1025 mb 0 mm/h
Tomorrow 12:00 am
weather icon
3° | 3°°C 0 mm 0% 4 mph 79 % 1025 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€97,155.31
-1.91%
Ethereum(ETH)
€3,019.05
-5.69%
XRP(XRP)
€2.80
-5.25%
Tether(USDT)
€0.96
0.01%
Solana(SOL)
€208.07
-7.16%
USDC(USDC)
€0.96
0.00%
Dogecoin(DOGE)
€0.299304
-6.30%
Shiba Inu(SHIB)
€0.000017
-7.93%
Pepe(PEPE)
€0.000012
-13.67%
Scroll to Top