Moucka steals billions

Article by Nacata Security, 06/08/2026

Did you know someone drained one hundred and sixty-five companies from the cloud without raising any suspicion?

Connor Riley Moucka did it between February and October 2024.

He used no zero-days or sophisticated techniques. He got in with stolen passwords on accounts without two-factor authentication, and that was enough to expose data belonging to one hundred million people.

For months, no one detected him. Meanwhile, he was downloading terabytes of information: call records, payroll data, passport numbers, banking details, and even records from the US drug enforcement agency.

Illustrates the mechanics of the attack: stolen credentials used without resistance to access data from hundreds of companies, with no need for sophisticated techniques.
Access without resistance

The method was simple, but the damage was enormous.

Moucka and his accomplices used purchased or stolen credentials to break into Snowflake, a cloud platform that stored data for hundreds of large companies. Since those accounts did not have two-factor authentication enabled, the door was wide open. Once inside, they copied terabytes of sensitive information: medical records, financial data, social security numbers, driver’s licenses, and passports belonging to millions of citizens.

Then came the extortion — and then the extortion came again.

Once they had the data, they threatened companies with publishing it unless they paid. But the pattern did not stop there: in several cases they extorted victims who had already paid, using personal information about government officials and their families to apply further pressure. That tactic — re-extortion — is becoming a common signature in data theft operations.

The group accumulated more than $9.5 million in confirmed direct damages.

Moucka personally pocketed at least $495,000 by selling data on cybercrime forums and Telegram. The group exceeded $2.5 million in extortion payments. Five countries coordinated his arrest: the Royal Canadian Mounted Police, the Spanish Civil Guard, the Australian Federal Police, and agencies from Ukraine and Turkey.

Represents the re-extortion pattern and the systemic failure: the absence of a single security control that leaves an entire chain of organizations vulnerable.
An unclosed chain

This case is not an exception — it is the pattern.

Re-extortion affects companies across all sectors that have already paid once, and attackers repeat it because it works.

As long as the stolen data remains unpublished, the attacker retains every advantage over the victim.

The attacks exposed data belonging to more than 100 million people and caused direct losses exceeding $9.5 million.

The conviction comes, but the damage is already done.

Moucka pleaded guilty to computer fraud, aggravated identity theft, and conspiracy. He faces up to thirty years in prison. Sentencing is scheduled for October 27. What has no scheduled date is the recovery of the exposed data.

The underlying problem goes further.

Snowflake is one of the most widely used cloud platforms by large corporations for centralizing their data. When a shared provider becomes an attack vector, the blast radius multiplies: it is not one compromised company — it is one hundred and sixty-five at once. This model — targeting the common link — is becoming increasingly frequent in large-scale incidents.

And the failure that made it possible was avoidable from the start.

None of the compromised accounts had two-factor authentication enabled. There was no zero-day, no sophisticated exploit — only leaked credentials and a basic configuration setting that no one had ever turned on. That single missing control opened the door to what the Department of Justice describes as one of the largest cloud data thefts on record.

Represents the international collaboration of five countries that coordinated the investigation and extradition of the accused, closing the operation in under a year.
Five countries united

International collaboration was key to stopping him in record time.

Five countries coordinated the investigation that led to Moucka’s extradition from Canada to the United States in July 2025. The FBI, the Spanish Civil Guard, and agencies from Australia, Ukraine, and Turkey closed the net in under a year.

But the data is already out and it is not coming back.

Even though Moucka is in custody, the information of more than one hundred million people continues to circulate on cybercrime forums and Telegram. A criminal conviction does not erase a call history or recover an exposed passport number. The real victims — the citizens whose data was sold — have no sentencing date to look forward to.

Cloud security starts with the basics.

Enabling two-factor authentication would have prevented this attack. It is not a complex measure — it is a decision any company can make today.

Protect your accounts

  • Enable two-factor authentication on all your important accounts.
  • Review which cloud services store your data and require MFA.
  • If you have already paid a ransom, assume they may extort you again.

How many of your cloud accounts still have two-factor authentication disabled?

Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.

Related articles

Nacata Security, reach out to us anytime

How would you rate this news?

We are Nacata Security, get to know us

web: nacata.io

email: info@nacata.io

Phone: 919930793

LinkedIn: Nacata Security

Incidents

Cyberattacks that have already happened and are confirmed: hacked companies, leaked data, services down after an attack, ransoms paid.

Real cases, with names and clear consequences, explained simply so anyone understands what happened and who it affected.



RATING


9



Who are we?


At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.


We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.


We’d be glad to get in touch with you for whatever you need.