Ransom Cartel Mastermind Once Known as ‘J.P. Morgan’ Sentenced to 16 Years; Canadian Man Pleads Guilty to Snowflake Data Theft
- Sentence handed: Maksim Silnikau, 40, received 16 years in prison for leading the Ransom Cartel ransomware operation.
- Guilty Plea: Connor Riley Moucka, 26, of Ontario, pleaded guilty to hacking Snowflake, a U.S. SaaS provider, and extorting its customers.
- Global victims: Ransom Cartel attacked at least 18 companies between 2021 and 2023, and Moucka compromised over 165 organizations via Snowflake.
A Belarusian national has been sentenced to 16 years in prison for creating and administering the Ransom Cartel ransomware scheme. Maksim Silnikau, 40, was sentenced in the Eastern District of Virginia after pleading guilty to conspiracy to commit offenses against the U.S., conspiracy to commit wire fraud, and aggravated identity theft.
Connor Riley Moucka, 26, of Kitchener, Ontario, Canada, has pleaded guilty to a widespread computer hacking conspiracy that compromised more than 165 organizations. Moucka entered the plea on August 5, 2026, admitting to four counts including computer fraud, wire fraud, aggravated identity theft, and a related conspiracy.
Ransom Cartel's Origins and Operations
According to court documents, Silnikau began developing Ransom Cartel in May 2021 and recruited participants from Russian-speaking cybercrime forums, where he operated under aliases including "J.P. Morgan," "xxx," and "lansky" since at least 2005.
He was also a member of the notorious Direct Connection website from 2011 until its shutdown in 2016, following the arrest of its administrator.
Silnikau distributed stolen credentials and encryption tools to co-conspirators and maintained a hidden dark web panel to monitor attacks, negotiate demands, and manage fund distribution among affiliates.
Snowflake-Related Intrusions
Between February and October 2024, Moucka and his co-conspirators used stolen login credentials to compromise cloud-hosted sensitive data belonging to at least 165 Snowflake customers.
In addition to extorting victims, Moucka and his co-conspirators sold the stolen data on the BreachForums, Exploit.in, and XSS.is cybercrime forums and Telegram. Moucka personally obtained at least $495,000 in this way, the U.S. Department of Justice (DOJ) has announced.
Scope of the Attacks
From 2021 to 2023, Silnikau's conspirators executed ransomware attacks on at least 18 companies worldwide, including firms in California, New York, and Nebraska. The individual was extradited from Poland in 2024 to face prosecution.
Prosecutors said the operation attempted to extort at least $5.2 million from its victims, with the U.S. identifying more than $6.7 million in confirmed losses across the 18 known victims. The scheme was disrupted by Silnikau's arrest in Estepona, Spain, in July 2023.
The Snowflake breach, initially disclosed by the company in June 2024, was attributed to the UNC5537 threat actor, a financially motivated threat group that targeted approximately 165 organizations and obtained over $2.5 million in ransom payments.
These included major companies like Advance Auto Parts, AT&T, LendingTree subsidiary QuoteWizard, Neiman Marcus, Santander Bank, Ticketmaster, Ticketek, and Pure Storage.




