Visualização normal

Antes de ontemStream principal
  • ✇Security Affairs
  • Snowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of Records Pierluigi Paganini
    Snowflake hacker Connor Moucka pleads guilty after breaching 165 organizations, stealing billions of records, and extorting victims. Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty this week to a computer hacking conspiracy that compromised over 165 organizations, stole billions of customer records, and extorted multiple victims for millions of dollars. “Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty today to a widespread computer hacking conspiracy that re
     

Snowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of Records

6 de Agosto de 2026, 02:39

Snowflake hacker Connor Moucka pleads guilty after breaching 165 organizations, stealing billions of records, and extorting victims.

Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty this week to a computer hacking conspiracy that compromised over 165 organizations, stole billions of customer records, and extorted multiple victims for millions of dollars.

“Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty today to a widespread computer hacking conspiracy that resulted in the compromise of over 165 victim organizations, the theft of billions of sensitive customer records and the extortion of numerous victims.” states DoJ.

The unnamed “U.S.-based software-as-a-service company” at the center of the scheme is Snowflake, the cloud data platform, though the DOJ press release doesn’t name it directly. Moucka was arrested just six months after the breaches began, which is either impressive law enforcement work or a sign that he wasn’t as careful as he thought.

“between February and October 2024, Moucka and his co-conspirators used stolen login credentials to compromise cloud-hosted data belonging to at least 165 customers of a U.S.-based software-as-a-service company. Moucka and others used their unauthorized access to these customers’ computer systems to steal billions of sensitive customer records and download terabytes of information, including individuals’ non-content call and text history records, banking and other financial information, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, social security numbers and other personally identifiable information.” continues the DoJ’s press release.”They then extorted victims by threatening to publish data online.”

Moucka and his accomplices earned more than $2.5 million by extorting victims after stealing their data. In one case, they threatened to release information again, using stolen data belonging to a government official and family members to increase pressure.

They also sold stolen information on cybercrime forums and Telegram, allowing Moucka to personally gain at least $495,000. The attacks caused more than $9.5 million in direct losses for affected companies and exposed data linked to over 100 million individuals. Moucka pleaded guilty to computer fraud, wire fraud, identity theft, and conspiracy charges, and faces up to 30 years in prison.

The entry method wasn’t a sophisticated zero-day. The conspirators used stolen credentials, meaning accounts that weren’t protected by multi-factor authentication. That one missing control opened the door to what became one of the largest cloud data theft operations on record.

Re-extortion, going back to a victim who already paid and threatening them again, is a pattern that law enforcement has documented increasingly in ransomware and data theft cases. It works because victims are already compromised, the data is already gone, and the attacker has leverage as long as the data remains unpublished.

“Today’s guilty plea sends a clear message to cybercriminals: you cannot hide from justice, no matter how hard you may try to cover your tracks,” said Special Agent in Charge W. Mike Herrington of the FBI Seattle field office. “Connor Moucka’s threats and re-extortion tactics were calculated and predatory, and his actions did real harm to his victims, be they companies targeted for theft and extortion or the millions of everyday people who are their customers. Ultimately, though, Mr. Moucka’s schemes were no match for the tenacity of FBI Seattle and this international investigative team. I am incredibly proud of their work. Let this outcome serve as a reminder: actions have consequences, and the FBI will continue to relentlessly pursue those who target American businesses and individuals in cyberspace, wherever they may be.”

Moucka pleaded guilty to four counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. He faces a mandatory minimum of two years on the identity theft count and up to 30 years on the others. Sentencing is scheduled for October 27.

The man was extradited from Canada to the US in July 2025 with cooperation from the Royal Canadian Mounted Police, the Australian Federal Police, Spain’s Guardia Civil, the Security Service of Ukraine, and the Turkish National Police, a list that tells you something about how international these criminal networks have become.

“Connor Moucka hacked over 150 companies and organizations, obtained extremely sensitive information, and extorted the victims for millions of dollars,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division. “Moucka was arrested just six months after these breaches began, demonstrating this Department’s firm commitment to investigating and prosecuting sophisticated cybercriminals who cause extensive harm to American businesses and consumers. Today’s guilty plea serves as a reminder to all cybercriminals, regardless of where they live, that they cannot hide behind a wall of anonymity. You will be found and brought to justice.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

  • ✇Malwarebytes
  • What’s your data worth on the dark web? (Lock and Code S07E15)
    This week on the Lock and Code podcast… Twenty years ago, a British mathematician named Clive Humby popularized a phrase that came to describe data’s relationship with the entire global economy: “Data is the new oil.” Pithy as the phrase sounds, it is undeniably true. Data steers decisions at businesses of every size. Data created entirely new industries built around its capture. And, for a select number of companies, data has produced billions—if not trillions—of dollars in value.
     

What’s your data worth on the dark web? (Lock and Code S07E15)

27 de Julho de 2026, 11:35

This week on the Lock and Code podcast…

Twenty years ago, a British mathematician named Clive Humby popularized a phrase that came to describe data’s relationship with the entire global economy: “Data is the new oil.”

Pithy as the phrase sounds, it is undeniably true.

Data steers decisions at businesses of every size. Data created entirely new industries built around its capture. And, for a select number of companies, data has produced billions—if not trillions—of dollars in value.

So how is it that, on the dark web, your stolen identity can be purchased for just 95 cents?

That’s what a Malwarebytes researcher found last month after spending 48 hours inside the dark web to investigate cybercrime. Across a variety of forums and directories, he found subscription plans for malware that steals information once implanted on a device. He found guides for deploying social engineering scams. He found people selling their services to build fake websites that trick people into handing over their usernames and passwords. And he found one of the dark web’s most traded commodities—personal data, packaged together about individual people, to help a cybercriminal commit identity fraud.

These packages are called “fullz.” For victims in the United States, a fullz contains a full name, Social Security Number, date of birth, address, and other personal details. That is enough, on its own, for a cybercriminal to potentially open a bogus line of credit, file a fake tax return, access financial accounts, or obtain medical services under someone else’s name.

As we wrote on Malwarebytes Labs:

“For less than the cost of a cup of coffee, a cybercriminal can buy enough information to devastate someone’s financial life.”

It’s the kind of risk that could scare anyone, especially considering the scale behind it. In just the first six months of 2026, Malwarebytes found more than 7,500 compromised data sets on the dark web containing more than 8.4 billion records.

And yet, even today, cybersecurity professionals still get asked why anyone should bother protecting their data.

The public, understandably, are exhausted. With data breaches happening every week—if not every day—cybersecurity can start to feel pointless. With young people unable to build financial security, they start believing that they have nothing worth stealing. And with Big Tech already collecting our every movement, behavior, click, and concern, people understandably feel powerless to fight any kind of data abuse, be it corporate or criminal.

So today’s episode approaches the question from a different direction. This isn’t about why you should protect yourself—plenty of company websites will tell you that, and most of them rely on fear. This is about why hackers want your data in the first place.

Today, on the Lock and Code podcast, host David Ruiz explains how cybercriminals turn a single repeated password into account takeover, how a screenshot of your house from Google Maps became a tool in extortion emails, and why the most benign information about you—an address, an age, one public photo—is often the most useful data a stranger can buy.

Tune in today to listen to the full episode.

Show notes and credits:

Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)


Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.

Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium for Lock and Code listeners.

Iranian Hacker Arrested Over Alleged $3.4 Billion Cyberattack on USA Infrastructure

Iranian hacker

An alleged Iranian hacker accused of hacking US infrastructure has been arrested in Montenegro following a joint operation by Montenegrin police and the U.S. Federal Bureau of Investigation (FBI). The suspect is expected to face charges related to computer fraud, hacking, conspiracy, and identity theft after authorities linked him to a years-long cyber campaign that reportedly caused more than $3.4 billion in damages. 

Iranian Hacker Faces Computer Fraud and Hacking Charges 

The 39-year-old suspect, who holds dual Iranian and Turkish citizenship, was arrested in the Adriatic coastal town of Kotor, Montenegro. According to local police, he is wanted by the Southern District Court of New York on charges of conspiracy to commit computer fraud, hacking, and identity theft.  The case will now be referred to a High Court judge in Montenegro's capital, Podgorica, where extradition proceedings are expected to begin. 

Alleged Cyberattack on USA Universities Caused Billions in Damage 

In an official statement, Montenegro's police directorate alleged that the Iranian hacker had been involved in large-scale hacking operations since 2013.  "From 2013 onward, … he carried out massive hacking attacks … targeting more than 150 universities in the United States, causing damage estimated at over $3.4 billion," the statement said.  Authorities claim the stolen data and access to compromised university accounts were used to benefit Iran's Islamic Revolutionary Guard Corps (IRGC) and other Iranian organizations, including universities. Investigators allege the campaign formed part of a broader cyberattack on USA institutions aimed at acquiring sensitive academic data and digital access. 

Extradition Process Underway 

Following the arrest, Montenegrin authorities confirmed that the suspect remains in custody while legal proceedings continue. If approved, he will be extradited to the United States to face charges tied to computer fraud, identity theft, and extensive hacking operations.  The FBI participated in the investigation that led to the arrest, although the agency was not immediately available for comment after the announcement. 

Iranian Cyber Operations Remain Under Scrutiny 

The latest arrest comes amid continued concerns over Iranian-linked cyber activity. Iran and the IRGC have long been associated with state-sponsored cyber operations targeting U.S. organizations and infrastructure.  In April, U.S. cybersecurity, intelligence, and law enforcement agencies warned that Iranian hacking campaigns targeting equipment across critical U.S. infrastructure had intensified. The warning highlighted an increase in attempted intrusions, reinforcing concerns over future cyberattacks on the USA.  The arrest marks a new development in an international investigation into one of the largest alleged cybercrime cases involving an Iranian hacker, with prosecutors pursuing charges that include conspiracy, computer fraud, hacking, and identity theft linked to billions of dollars in reported losses. 
❌
❌