A 26-year-old Canadian national, once characterized as a leading figure in the cybercrime landscape of 2024, has entered a guilty plea to charges of computer fraud and conspiracy. Connor Riley Moucka, hailing from Kitchener, Ontario, admitted to orchestrating a sophisticated scheme that targeted over 165 organizations utilizing the cloud computing services of Snowflake. His illicit activities also extended to the theft of call and text history records belonging to more than 100 million AT&T customers, a colossal breach of privacy.
The U.S. Department of Justice revealed that between February and October 2024, Moucka and his accomplices systematically exploited stolen login credentials to gain unauthorized access to data hosted on Snowflake’s platform. Their primary targets were Snowflake customer accounts that lacked robust multi-factor authentication, leaving them vulnerable to exploitation. The attackers subsequently extorted, or attempted to extort, a significant number of prominent companies. Among the high-profile victims were Ticketmaster, LendingTree, Advance Auto Parts, and Neiman Marcus, whose sensitive data was compromised. In the wake of these breaches, Snowflake was compelled to enhance its security protocols by implementing stricter password complexity requirements and enforcing multi-factor authentication across its services.
Moucka was a prolific figure in the cybercriminal underworld, frequently adopting new online personas and often managing multiple identities concurrently. His most recognized aliases were "Judische" and "Waifu." KrebsOnSecurity first brought "Judische’s" involvement in the Snowflake data breaches to light in a September 2024 report. This report delved into the concerning intersection between Western, English-speaking cybercriminals and extremist groups that engage in harassment and extortion, particularly targeting minors with harmful directives. The September exposé identified "Judische" as a software engineer from Ontario with a history of involvement in numerous data breaches and voice phishing attacks against U.S. companies, dating back to at least 2020. Just over a month later, Moucka’s activities culminated in his arrest by Canadian authorities, acting on a provisional warrant issued by the United States.

The scale of the data theft was staggering. The government asserts that Moucka and his co-conspirators pilfered billions of sensitive customer records, downloading terabytes of highly confidential information. This included, but was not limited to, non-content call and text history records, banking and financial details, payroll information, Drug Enforcement Administration (DEA) registration numbers, driver’s license and passport numbers, social security numbers, and a wide array of other personally identifiable information (PII). The perpetrators then leveraged this stolen data, threatening to publish it online unless substantial ransoms were paid.
Moucka’s criminal enterprise extended beyond data theft and extortion. He also engaged in the harassment and intimidation of government officials and cybersecurity researchers who were actively working to track him down. The Department of Justice further stated that the conspirators amassed over $2.5 million in ransom payments. In a particularly brazen act, Moucka was found to have re-extorted a victim by threatening further disclosure of their already stolen data, demonstrating a disturbing pattern of escalating malicious conduct. This re-extortion attempt involved the stolen data of a government officer and members of their immediate family, as detailed in a statement from the Department of Justice.
A key figure in Moucka’s criminal network was Cameron "Kiberphant0m" Wagenius, a soldier in the U.S. Army. Wagenius pleaded guilty in July 2025 to charges related to extorting AT&T and Verizon for their customer account data. Less than a month before Wagenius’s arrest, KrebsOnSecurity published an in-depth investigation into Wagenius’s various online identities across platforms like Telegram and Discord. This investigation revealed that Wagenius had confided in others about his military service and his deployment in South Korea. Wagenius also engaged in re-extortion tactics. Notably, in the immediate aftermath of Moucka’s arrest, Wagenius posted on hacker forums what he claimed were AT&T call logs for then-President-elect Donald Trump and then-Vice President Kamala Harris, alongside alleged schematics stolen from the U.S. National Security Agency (NSA). Wagenius is scheduled for sentencing on September 3, 2026, and faces a maximum of 20 years for conspiracy to commit wire fraud, five years for extortion related to computer fraud, and a mandatory two-year sentence for aggravated identity theft, to be served consecutively.

The third alleged co-conspirator is John Erin Binns, a 26-year-old American national. Binns is an elusive figure who fled the United States after being indicted for his admitted role in a significant 2021 data breach at T-Mobile, which exposed the personal information of at least 76 million customers. Sources close to the investigation indicated that Binns, also known by the monikers "IRDev" and "IntelSecrets," was recently incarcerated in a Turkish prison but has since been released. He has reportedly resurfaced online and, under Turkish law, cannot be extradited to a foreign country after recently obtaining Turkish citizenship.
Moucka’s guilty plea encompasses four criminal counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. His sentencing is scheduled for October 27th. He faces a mandatory minimum of two years in prison for the aggravated identity theft charge, with a maximum penalty of 30 years for the remaining counts. The ultimate sentence will be determined by the federal judge, considering the entirety of Moucka’s extensive cybercriminal activities. Further details and context regarding Moucka’s arrest and John Erin Binns can be found in KrebsOnSecurity’s original report on Moucka’s apprehension.

