A 26-year-old Canadian national, once identified as a significant cybercrime threat actor of 2024, has admitted to a string of serious federal offenses, including computer fraud and conspiracy to hack and extort over 165 organizations that relied on the cloud data platform Snowflake. Connor Riley Moucka, hailing from Kitchener, Ontario, also confessed to the egregious theft of call and text history records belonging to more than 100 million AT&T customers. This plea represents a pivotal moment in the ongoing crackdown against sophisticated cybercriminal operations that have targeted major corporations and exposed sensitive personal information on an unprecedented scale.

The U.S. Department of Justice has laid out a disturbing timeline of Moucka’s illicit activities, detailing how, between February and October 2024, he and his network of co-conspirators systematically exploited stolen login credentials. These credentials were used to gain unauthorized access to cloud-hosted data belonging to at least 165 clients of a prominent U.S.-based software-as-a-service provider. The hackers’ strategy was particularly insidious: they specifically targeted stolen credentials for Snowflake customer accounts that lacked multi-factor authentication, a crucial security layer that would have significantly hindered their efforts. This vulnerability allowed them to pilfer data and subsequently extort or attempt to extort a roster of high-profile companies, including household names like Ticketmaster, Lending Tree, Advance Auto Parts, and Neiman Marcus. In the wake of these breaches, Snowflake has proactively responded by implementing stricter password complexity requirements and mandating multi-factor authentication for all its users, a move that underscores the severity of the threat.

Moucka was a master of disguise in the digital underworld, frequently adopting new online personas and often managing multiple aliases simultaneously. Among his most notorious monikers were "Judische" and "Waifu." His involvement as "Judische" in the Snowflake data breaches was first brought to light by KrebsOnSecurity in a September 2024 investigative report. This earlier report delved into the troubling nexus between Western, English-speaking cybercriminals and extremist groups that prey on vulnerable individuals, particularly minors, coercing them into self-harm or harming others. The September 2024 exposé identified "Judische" as a software engineer from Ontario with a history of involvement in numerous data breaches and voice phishing attacks against U.S. companies dating back to at least 2020. Just over a month after this initial report, Canadian authorities, acting on a provisional warrant from the United States, apprehended Moucka.

Canadian Man Pleads Guilty in Snowflake Extortions

The scale of the data compromised is staggering. The government asserts that Moucka and his associates leveraged their unauthorized access to steal billions of sensitive customer records, downloading terabytes of highly confidential information. This data included not only non-content call and text history records but also critical financial details such as banking information, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, social security numbers, and a vast array of other personally identifiable information (PII). The modus operandi involved threatening victims with the public release of this stolen data if ransom demands were not met.

Beyond the direct victims of data theft, Moucka also engaged in threatening and harassing behavior towards government officials and security researchers who were instrumental in tracking his criminal activities. The Department of Justice revealed that the conspirators successfully extorted over $2.5 million in ransom payments. In a particularly brazen act of re-extortion, Moucka once again targeted a victim, threatening further disclosure of their already stolen data. The DOJ statement highlighted the chilling detail that Moucka "used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt," demonstrating a disturbing lack of ethical boundaries and a willingness to exploit personal vulnerabilities for financial gain.

The investigation has also unraveled the roles of other key players in this elaborate cybercriminal enterprise. One of Moucka’s admitted co-conspirators is Cameron "Kiberphant0m" Wagenius, a U.S. Army soldier who pleaded guilty in July 2025. Wagenius confessed to extorting AT&T and Verizon for their customer account data. Intriguingly, less than a month before Wagenius’s arrest, KrebsOnSecurity published an in-depth exposé of "Kiberphant0m’s" various online identities across Telegram and Discord, revealing his claims of being in the Army and stationed in South Korea.

Wagenius, much like Moucka, also engaged in re-extortion tactics. Following Moucka’s arrest, "Kiberphant0m" posted on hacker forums what he purported to be the AT&T call logs for then President-elect Donald Trump and then Vice President Kamala Harris. He also allegedly shared schematics stolen from the U.S. National Security Agency (NSA), further escalating the gravity of his criminal actions and demonstrating a willingness to target high-profile individuals and sensitive government information. Wagenius is scheduled for sentencing on September 3, 2026, and faces a maximum penalty of 20 years in prison for conspiracy to commit wire fraud, five years for extortion related to computer fraud, and a mandatory consecutive two-year sentence for aggravated identity theft.

Canadian Man Pleads Guilty in Snowflake Extortions

The third alleged co-conspirator in this network is John Erin Binns, a 26-year-old American national. Binns is described as an elusive figure who absconded from the United States after being indicted for his admitted role in a significant 2021 data breach at T-Mobile, which compromised the personal information of at least 76 million customers. Sources close to the investigation indicate that Binns, also known by the online handles "IRDev" and "IntelSecrets," was recently incarcerated in a Turkish prison. However, he has since been released and has resurfaced online. Alarmingly, these sources suggest that Binns has also recently acquired Turkish citizenship, a status that, under Turkish law, prevents his extradition to foreign countries, potentially complicating efforts to bring him to justice. An image of a passport, shared by Binns in an email to KrebsOnSecurity in February 2023, underscores his international movements and attempts to evade law enforcement.

Moucka’s guilty plea encompasses four serious criminal counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. He is scheduled for sentencing on October 27 and faces a mandatory minimum penalty of two years in prison for the aggravated identity theft charge. Additionally, he could be sentenced to a maximum of 30 years in prison for the remaining counts. The ultimate sentence will be determined by the presiding federal judge, who will weigh the extensive nature of Moucka’s cybercriminal activities when deciding the final duration of his incarceration. This plea agreement marks a significant victory for law enforcement in dismantling a sophisticated cybercriminal ring and signals a strong commitment to holding perpetrators of large-scale data breaches and extortion accountable.