UNC5537's Connor Riley Moucka Pleads Guilty to Snowflake Extortion Campaign
Connor Riley Moucka, the threat actor we track as UNC5537, pleaded guilty today to a widespread computer hacking conspiracy involving the compromise of over 165 victim organizations and the theft of billions of sensitive customer records.
In 2024, our team identified that Moucka used stolen credentials to systematically target misconfigured SaaS customer instances across over a hundred organizations worldwide. The operation resulted in extensive data exfiltration and extortion attempts targeting enterprise environments.
By the public and private sector working together, defenders can impose serious costs on threat actors.
- Department of Justice announcement: https://www.justice.gov/opa/pr/canadian-man-pleads-guilty-hacking-us-cloud-storage-provider-and-extorting-its-customers
- Previous UNC5537 research: https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion