Snowflake
Incident posture
Timeline
Summary
Connor Moucka pleaded guilty for his role in the 2024 Snowflake Inc. data breach, where attackers accessed cloud storage to steal customers' private information; the breach also exposed data from Ticketmaster, Live Nation, and AT&T.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Between April 2 and May 18, 2024, a group of cybercriminals operating under the name ShinyHunters conducted an extended intrusion into cloud storage accounts belonging to Snowflake Inc., a major data warehousing provider, and several of its high-profile corporate clients. The hackers exploited stolen or compromised credentials to access customer data repositories, ultimately extracting more than 1.3 terabytes of sensitive information spanning multiple organizations. Among the most prominently identified victims were Ticketmaster, its parent company Live Nation, and telecommunications giant AT&T. The stolen datasets included personal identifying information, credit card numbers, order histories, payment details, and answers to security questions, representing a comprehensive profile of users that could be exploited for fraud, identity theft, or resale on criminal marketplaces. In the case of Ticketmaster alone, the breach exposed records belonging to more than 560 million user accounts, a scale that placed the incident among the largest consumer data compromises of the year. The attackers initially attempted to monetize the Ticketmaster portion of the stolen data by offering it for sale online in 2024 at a price of $500,000 USD, while reportedly seeking up to $6 million USD for the complete dataset harvested from the broader Snowflake campaign.
The detection of the breach at Ticketmaster occurred in late May 2024, several weeks after the intrusion period had already concluded. Ticketmaster subsequently issued a notification email to affected customers in July 2024, informing them that an "unauthorized third party" had compromised their information and outlining recommended security steps that customers should take in response. The company also disclosed that it had implemented "a number of technical and administrative steps to further enhance the security of its systems and customer data" on its platform, though specific technical details of those measures were not publicly enumerated. Beyond the data theft itself, the cybercriminals leveraged the breach as leverage for extortion, specifically targeting Ticketmaster with threats tied to the company's ticketing infrastructure for Taylor Swift's Eras Tour. The perpetrators claimed to possess barcode data for hundreds of thousands of tickets to the tour's scheduled stops in Indianapolis, Miami, and New Orleans, and demanded millions of dollars in ransom. Although some ticketing data was ultimately leaked, Ticketmaster's dynamic barcode system prevented the fraudulent use of the compromised tickets, meaning the stolen barcode information could not be redeemed by fans who had purchased them or by the criminals seeking to profit through resale.
The financial proceeds from the operation were substantial. Connor Moucka, a 26-year-old resident of Kitchener, Ontario, who was identified as one of the principal participants in the Snowflake breach, reportedly received approximately $495,000 USD in Bitcoin, equivalent to over $600 million CAD according to the exchange rates referenced in reporting. In total, Moucka and his co-conspirators extorted more than $3 million CAD in Bitcoin from three victims across the wider operation. Moucka was subsequently apprehended and extradited to the United States, where he appeared in the U.S. District Court for the Western District of Washington on August 5, 2025 (as implied by the case timeline and the August 10, 2026 article date referencing his plea). He pleaded guilty to one count each of computer fraud, wire fraud, aggravated identity theft, and a related conspiracy charge. The aggravated identity theft count carries a mandatory minimum sentence of two years, while the remaining three counts carry potential sentences of up to thirty years combined. His sentencing hearing was scheduled for October 27. Assistant Attorney General A. Tysen Duva of the U.S. Department of Justice's Criminal Division stated publicly that "Today's guilty plea serves as a reminder to all cybercriminals, regardless of where they live, that they cannot hide behind a wall of anonymity. You will be found and brought to justice." The case underscored the cross-border nature of the investigation and the willingness of U.S. authorities to pursue cybercriminals operating from foreign jurisdictions. As a consequence of Moucka's guilty plea and the broader law enforcement action, the Snowflake breach case moved into its judicial resolution phase, with co-conspirators facing parallel proceedings and victim organizations continuing to manage the downstream effects of having their customer data exposed at scale.
Sources
Sources available to members: 1 source.