Canadian Hacker Connor Riley Moucka Pleads Guilty in Massive Snowflake Cloud Extortion and AT&T Data Breach Scheme

A 26-year-old Canadian software engineer once identified by international cybersecurity investigators as one of the most destructive and consequential threat actors of 2024 has officially pleaded guilty to federal charges. Connor Riley Moucka, a resident of Kitchener, Ontario, entered guilty pleas to charges of computer fraud, wire fraud, aggravated identity theft, and conspiracy. His admission of guilt brings a major legal resolution to a cybercriminal campaign that compromised the cloud-hosted data of more than 165 high-profile organizations utilizing the cloud storage provider Snowflake, while also exposing the call and text message history records of over 100 million AT&T customers.
The U.S. Department of Justice outlined the scope of the criminal enterprise, noting that between February and October 2024, Moucka and an international network of co-conspirators systematically exploited stolen login credentials. The group targeted corporate accounts that lacked multi-factor authentication (MFA) enforcement, downloading terabytes of proprietary and sensitive consumer data. Victims of the extortion scheme included prominent household brands such as TicketMaster, LendingTree, Advance Auto Parts, and Neiman Marcus. The financial toll of the extortion demands surpassed $2.5 million in ransom payments, though the long-term economic, operational, and reputational damages to the impacted corporations remain immeasurable.
Chronology of a Global Cyber Extortion Campaign
The unfolding of the Snowflake breaches and subsequent extortions followed a rapid, high-stakes trajectory throughout 2024. The operational timeline highlights the aggressive methods employed by Moucka and his associates, as well as the swift coordination between independent cybersecurity researchers and international law enforcement agencies.
Early 2024: The campaign began in earnest around February 2024. Moucka, operating under numerous online aliases—most notably "Judische" and "Waifu"—began leveraging leaked or stolen credentials to access cloud storage containers hosted by Snowflake. The attackers bypassed perimeter defenses simply by taking advantage of corporate accounts that failed to mandate multi-factor authentication.
September 2024: Independent investigative journalism by KrebsOnSecurity exposed the real-world identity behind the "Judische" moniker. The report connected the handle to an Ontario-based software engineer with a multi-year history of conducting voice phishing attacks and data breaches against U.S. corporations since at least 2020. Furthermore, the report highlighted alarming overlaps between these Western cybercriminals and online extremist groups involved in the harassment and extortion of minors.
October 2024: Canadian authorities acted swiftly on a provisional arrest warrant issued by the United States. Royal Canadian Mounted Police (RCMP) arrested Moucka on October 30, 2024, following a surveillance operation that captured his movements in Ontario just days prior.
November 2024 to July 2025: Investigations deepened into Moucka’s co-conspirators. In July 2025, U.S. Army soldier Cameron Wagenius, known online as "Kiberphant0m," pleaded guilty to his role in extorting telecommunications giants AT&T and Verizon. Wagenius had utilized Telegram and Discord to coordinate attacks and even weaponized stolen logs to attempt high-profile re-extortions.

August to October 2025: As the legal proceedings advanced, Moucka formally entered his guilty pleas in federal court. His sentencing hearing is currently scheduled for October 27, where he faces a maximum potential prison sentence of 30 years alongside a mandatory minimum consecutive two-year term for aggravated identity theft.
Anatomy of the Breach: Methods and Vulnerabilities
The compromise of Snowflake and its associated corporate clients serves as a textbook case study in the dangers of inadequate identity and access management. Rather than executing sophisticated zero-day exploits or breaking through complex cryptographic defenses, the threat actors relied primarily on credential stuffing and the exploitation of preexisting security gaps.
According to federal investigators, Moucka and his accomplices gathered valid usernames and passwords from prior, unrelated data leaks. They then tested these credentials against Snowflake customer environments. Accounts that did not require multi-factor authentication provided an open door. Once inside the cloud architecture, the hackers exfiltrated billions of sensitive records.
The scope of the stolen data was staggering. It encompassed non-content call and text history records, banking and financial details, internal payroll registries, Drug Enforcement Administration (DEA) registration numbers, driver’s licenses, passports, Social Security numbers, and a wide array of other Personally Identifiable Information (PII).
Rather than simply stealing the data for resale on underground cybercrime forums, the group utilized a direct extortion model. They contacted corporate executives, threatening to publish or leak the proprietary databases online unless lucrative ransom demands were met. In several particularly aggressive instances, Moucka and his co-conspirators engaged in "re-extortion"—targeting victims a second time with threats of further data exposure even after initial agreements had been reached or ransoms paid. In one egregious example highlighted by the DOJ, Moucka utilized the stolen personal data of a government official and members of their family to exert pressure during a re-extortion attempt.
The Co-Conspirators: A Web of International Cybercrime
Moucka did not operate in a vacuum. Federal indictments and investigative reports have shed light on the co-conspirators who worked alongside him to build and maintain the extortion infrastructure.
Cameron "Kiberphant0m" Wagenius, a U.S. Army soldier stationed in South Korea during parts of his criminal enterprise, played a pivotal role in targeting telecommunications infrastructure. Wagenius pleaded guilty in July 2025 to wire fraud, extortion, and identity theft charges. His operational audacity extended to posting alleged AT&T call logs belonging to high-profile political figures, including then President-elect Donald Trump and then Vice President Kamala Harris, alongside classified schematics purportedly stolen from the U.S. National Security Agency (NSA) on hacker forums. Wagenius is slated to be sentenced on September 3, 2026, facing up to 25 years in combined prison time.

A third major figure linked to the broader network of threat actors is John Erin Binns, a 26-year-old American citizen. Binns previously fled the United States following an indictment for his role in the massive 2021 T-Mobile data breach, which compromised the personal records of at least 76 million customers. Operating under handles such as "IRDev" and "IntelSecrets," Binns reportedly spent time incarcerated in a Turkish prison before being released. Intelligence sources indicate that Binns has since acquired Turkish citizenship. Under Turkish legal protections, citizens cannot be extradited to foreign jurisdictions, complicating efforts by U.S. law enforcement to bring him to face American courts.
Corporate and Governmental Response
The fallout from the Snowflake-adjacent breaches forced a fundamental reckoning across the software-as-a-service (SaaS) and cloud computing industries. Snowflake itself took immediate, aggressive remediation steps following the discovery of the intrusions. The company overhauled its security posture by implementing stricter password complexity requirements and making multi-factor authentication a mandatory, non-negotiable default for all customer accounts.
Cybersecurity experts and regulatory bodies praised the swift legal actions taken by the U.S. Department of Justice, the FBI, the Royal Canadian Mounted Police, and cooperating international agencies. However, security analysts emphasize that the incident underscores systemic vulnerabilities in how organizations manage third-party cloud access and employee credential hygiene.
Broader Implications for Cloud Security and National Security
The guilty plea of Connor Riley Moucka marks a critical milestone in curbing modern cyber extortion, yet it also highlights evolving threats within the global cybersecurity landscape. The involvement of individuals connected to military service, such as Cameron Wagenius, demonstrates that threat actors can sometimes leverage institutional access or tactical knowledge to evade detection and amplify the psychological pressure of their extortion campaigns.
Furthermore, the blurring lines between financially motivated cybercrime syndicates and extremist online subcultures—as initially documented in relation to Moucka’s "Judische" persona—pose new challenges for law enforcement agencies tracking domestic and international threats. These groups frequently operate in decentralized chat rooms on platforms like Telegram and Discord, rapidly forming ad-hoc partnerships to execute complex, multi-stage attacks against critical infrastructure and major corporate entities.
As Moucka awaits his October 27 sentencing, the legal proceedings serve as both a deterrent and a stark reminder of the vulnerabilities inherent in modern digital ecosystems. For enterprises worldwide, the case reinforces the critical necessity of zero-trust architectures, mandatory multi-factor authentication, and rigorous monitoring of cloud storage environments to prevent unauthorized access before extortionists can turn corporate data into financial leverage.






