A 26-year-old Canadian now faces up to 32 years in prison after admitting his role in the 2024 Snowflake data thefts, a campaign prosecutors say reached 165 organizations and exposed records belonging to more than 100 million people.
Moucka, who used the handles Waifu and Judische, entered the plea at the federal courthouse in Seattle, admitting computer fraud, wire fraud, aggravated identity theft and conspiracy. He is due to be sentenced on October 27.
The entry method was unglamorous. The group worked from credentials collected years before by infostealer malware and never changed since, with many Snowflake accounts also missing multi-factor authentication. No zero-day, no platform flaw: stale passwords and disabled MFA opened the door to data from companies including AT&T, Ticketmaster, Santander and Advance Auto Parts.
The group downloaded terabytes of call records, banking details, payroll files and Social Security numbers, then demanded ransoms. Moucka kept at least $495,000 from ransoms and data sales for himself, while the affected companies absorbed more than $9.5M in direct losses. In one case he returned to extort a victim a second time, threatening to release data on a government official’s family.
The Justice Department still has not named Snowflake, describing the target only as a US software-as-a-service provider. The plea is a reminder that the largest data thefts often start with basic hygiene failures rather than exotic technique.
