Connor Moucka
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Connor Moucka, also known by the alias Connor Moucka, is a threat actor located in Canada who pleaded guilty for his role in the 2024 Snowflake Inc. data breach. The guilty plea confirms his participation in an operation that resulted in unauthorized access to cloud storage environments. This admission establishes a direct link between the actor and the compromise of Snowflake’s infrastructure. No further affiliations or state connections have been publicly attributed to him based on the available information.
The breach involved attackers gaining access to Snowflake’s cloud storage and exfiltrating customers’ private information. The compromised data subsequently affected several high‑profile organizations, including Ticketmaster, Live Nation, and AT&T, indicating that the incident spanned the entertainment, live‑event promotion, and telecommunications sectors. The scope of the exposed information highlights the actor’s ability to target large‑scale cloud‑based services and extract sensitive personal data across multiple industries. No specific malware families or tooling styles were referenced in the public reporting of this incident.
The only publicly documented campaign associated with Connor Moucka is the 2024 Snowflake breach, which serves as a representative example of his activity. The operation’s primary observed tactic was the illicit entry into cloud storage systems to copy and remove private data. Attribution to any criminal consortium or nation‑state actor has not been established in the sources examined. Consequently, the profile is limited to the confirmed facts of his alias, location, guilty plea, and the details of the Snowflake‑related data theft.
Incidents
Attributed incidents are available to members.
1 incident