ZeroHour
CyberScooppublished ()ingested @gregotto

Man arrested in Canada believed to be behind Snowflake customer breach

criticalPolicy & legal exploited in the wildimportance 60
Full article729 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Connor Moucka was arrested last week at the behest of the United States, CyberScoop has learned.

Listen to this article

0:00

Learn more.

In this photo illustration, A ticketmaster website is shown on a computer screen on November 18, 2022 in Miami, Florida. A person allegedly responsible for the Ticketmaster breash was in arrested in Canada last week. (Joe Raedle/Getty Images)

Canadian authorities have arrested a person suspected of orchestrating a series of data exfiltration attacks targeting customers of the data storage firm Snowflake. 

Alexander “Connor” Moucka was taken into custody Oct. 30, based on a provisional arrest warrant, according to Canada’s Department of Justice. He is scheduled to appear in court Tuesday.

The Canadian Department of Justice confirmed to CyberScoop that the arrest was carried out at the request of the United States. 

While the specific charges against Moucka remain undisclosed, insiders familiar with the case have identified him as a key figure behind the attacks. Presentations from cybersecurity researchers given earlier this year labeled the individual, who was known by several online monikers including “Judische” and “Waifu,” as a 26-year-old from Ontario, Canada. Moucka was arrested in Kitchener, a city in Ontario approximately 65 miles west of Toronto. 

Attempts to reach Moucka have been unsuccessful. The FBI declined to comment. The White House did not respond to CyberScoop’s request for comment.

The breaches, which were discovered between April and July, affected major companies like AT&T, Ticketmaster and Santander. It was believed earlier this year that as many as 165 companies were impacted by the breach. Those responsible for the breaches tried to blackmail these companies by threatening to sell the stolen data on criminal forums.

Researchers found evidence that Judische collaborated with another hacker, John Binns, on the attack targeting AT&T, which the company said in July included records of “nearly all” of its customers’ data for a six-month period in 2022. Binns, previously indicted for an attack on T-Mobile in 2021, was arrested by Turkish authorities after the AT&T attack and remains in custody. 

During a presentation at LabsCon earlier this year, a Mandiant researcher presented evidence that whomever is responsible for the Snowflake breaches is a member of “The Com,” an online ecosystem that includes groups engaging in cybercriminal activity, violence, extortion, kidnappings, shootings and robberies, according to researchers who track the activity and law enforcement officials. 

Bloomberg was the first to report on Moucka’s arrest. 

More Scoops

The Department of Justice building is seen in Washington, DC, on August 9, 2022. (Photo by STEFANI REYNOLDS/AFP via Getty Images)

Snowflake hacker pleads guilty, faces up to 32 years in prison

Connor Moucka obtained almost $500,000 for playing a key role in one of the most widespread and damaging cyberattack sprees on record.

The U.S. Department of Justice is seen on June 20, 2023 in Washington, DC. (Photo by Kevin Dietsch/Getty Images)

Former Army soldier pleads guilty to widespread attack spree linked to AT&T, Snowflake and others

Traffic streaks past the Department of Justice (DOJ) headquarters building late in the evening on May 18, 2024 in Washington, DC. (Photo by J. David Ake/Getty Images)

Canadian citizen allegedly involved in Snowflake attacks consents to extradition to US

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/snowflake-breach-suspected-arrested-connor-moucka-waifu/