CSIDB logo
Threat actor

Connor Moucka

Attribution profile

Type
Undetermined
Location
Canada
Known incidents
1 incident
First seen
2024-01-01
Last seen
2024-01-01
Updated
2026-09-01 14:07
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Connor Moucka, also known by the alias Connor Moucka, is a threat actor located in Canada who pleaded guilty for his role in the 2024 Snowflake Inc. data breach. The guilty plea confirms his participation in an operation that resulted in unauthorized access to cloud storage environments. This admission establishes a direct link between the actor and the compromise of Snowflake’s infrastructure. No further affiliations or state connections have been publicly attributed to him based on the available information.

The breach involved attackers gaining access to Snowflake’s cloud storage and exfiltrating customers’ private information. The compromised data subsequently affected several high‑profile organizations, including Ticketmaster, Live Nation, and AT&T, indicating that the incident spanned the entertainment, live‑event promotion, and telecommunications sectors. The scope of the exposed information highlights the actor’s ability to target large‑scale cloud‑based services and extract sensitive personal data across multiple industries. No specific malware families or tooling styles were referenced in the public reporting of this incident.

The only publicly documented campaign associated with Connor Moucka is the 2024 Snowflake breach, which serves as a representative example of his activity. The operation’s primary observed tactic was the illicit entry into cloud storage systems to copy and remove private data. Attribution to any criminal consortium or nation‑state actor has not been established in the sources examined. Consequently, the profile is limited to the confirmed facts of his alias, location, guilty plea, and the details of the Snowflake‑related data theft.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB