you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 0 min ago 255 onions tracked
home / news / security
28 August 2026 security 4 min read

Forum Sales as Court Exhibits: Inside the Snowflake Hacker's Guilty Plea

On August 6, Connor Riley Moucka, a 26-year-old from Kitchener, Ontario, pleaded guilty in federal court in Seattle to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy count. He faces up to 32 years in prison when he is sentenced on October 27. The plea closes the book on one of the largest data-theft campaigns of the decade: the compromise of Snowflake customer accounts belonging to 165 organizations, including AT&T, Ticketmaster, Santander, Advance Auto Parts, Neiman Marcus, Anheuser-Busch, Allstate, Mitsubishi, Progressive, and State Farm.

What the campaign actually was

The group, tracked by Mandiant as UNC5537, did not hack Snowflake itself. Between February and October 2024 they used login credentials harvested years earlier by infostealer malware - some still valid from infections dating back to 2020 - against customer accounts that had multi-factor authentication switched off. No exploit, no zero-day, just recycled passwords. Once inside cloud storage environments, they walked off with billions of records: banking details, Social Security numbers, passport numbers, driver's license numbers, call logs, DEA registration numbers. The scale is hard to overstate. The Ticketmaster breach alone involved roughly 560 million user records. AT&T's covered call and text metadata for more than 100 million customers. In total, prosecutors say at least 100 million people were affected, and victim companies absorbed more than $9.5 million in direct losses - before counting anything their customers lost.

When forum posts become exhibits

For anyone who has spent time around data-sale forums, the most interesting part of this case is not the intrusion technique. It is what happened to the marketplace side of the operation afterward. Moucka and his co-conspirators collected roughly $2.5 million in ransom payments from victims threatened with publication. On top of that, court documents show Moucka personally earned about $495,000 advertising stolen data on cybercrime forums including BreachForums and XSS.is, according to The Record. Those sales threads - the listings, samples, price negotiations, and buyer handoffs that look routine inside a forum ecosystem - are now prosecution exhibits. Prosecutors used them to establish not just the theft but the monetization trail: who advertised what, when, at what price, paid out to which wallets and accounts. A post bragging about fresh dumps reads very differently when it has been printed, stamped, and attached to an indictment. The pattern recurs across recent cases. Forum operators, vendors, and even prolific buyers keep discovering that their pseudonymous reputations - the trust scores and vouches that make forum commerce function - double as a written record of criminal activity. Courts do not need to seize a server to use it. Screenshots, archived threads, and buyer testimony reconstruct the whole trade. We have tracked this dynamic in enforcement coverage before, from the long prison terms courts have handed darknet market admins to individual vendor prosecutions built largely on forum activity.

The re-extortion detail

One detail from the Justice Department announcement stands out. Moucka extorted at least one victim twice, using stolen data belonging to a government officer and members of a then-former officer's immediate family in the second attempt. FBI officials described his tactics as "calculated and predatory." That kind of escalation - moving from corporate extortion to targeting identifiable individuals - is precisely the sort of aggravating factor that pushes sentencing guidelines upward, and it will be in front of the judge on October 27.

The co-conspirators and the wider net

Moucka is only part of the story. Co-defendant John Erin Binns, alleged to have operated from Turkey, was arrested there in 2024 and continues contesting a US extradition request. Cameron John Wagenius, a former US soldier linked to related intrusions, already pleaded guilty in a separate case in July 2025. Investigators received assistance from police in Australia, Spain, Ukraine, and Turkiye - a reminder that these crews span jurisdictions, and so do the investigations that dismantle them. It is worth noting what the plea does not resolve. Restitution amounts remain undecided until sentencing, and public filings do not prove the government's 165 confirmed victims match the 165 organizations Snowflake and Mandiant flagged as potentially exposed back in 2024. But the headline numbers - billions of records, 100 million people, $2.5 million in ransoms - now come from sworn admissions rather than threat-intelligence estimates.

What this means for forum-side sellers

Strip away the specifics and the lesson is blunt. Selling stolen data on a forum leaves the same kind of paper trail as running a market: timestamps, payment flows, buyer lists, and an ego-driven habit of posting proof. Moucka operated under aliases like "Waifu," "Judische," "Catist," and "Ellyel8," and was arrested within months of the campaign starting anyway. As FBI Cyber Division assistant director Brett Leatherman put it, hiding behind a screen is no shield from justice. Anyone assuming forum sales are lower-risk than market operations should read the charging documents - because prosecutors certainly will.

more notes

all news ›