A 26-year-old Canadian man, once identified as one of the most significant cybercrime threat actors of 2024, has admitted guilt to computer fraud and conspiracy charges for his role in hacking and extorting over 165 organizations that relied on the cloud computing provider Snowflake. Connor Riley Moucka, hailing from Kitchener, Ontario, also confessed to pilfering call and text history records belonging to more than 100 million AT&T customers. This plea marks a pivotal moment in the ongoing crackdown on sophisticated cybercriminal operations that have targeted major corporations and critical infrastructure.

Moucka, operating under a variety of aliases including "Judische" and "Waifu," was a central figure in a widespread extortion scheme that exploited vulnerabilities in cloud security. Between February and October 2024, Moucka and his alleged co-conspirators systematically targeted stolen login credentials for Snowflake customer accounts. Their modus operandi involved identifying and exploiting accounts that lacked multi-factor authentication, a crucial security layer designed to prevent unauthorized access. Once inside, the hackers made off with vast quantities of sensitive data, subsequently extorting or attempting to extort numerous high-profile companies. Among the prominent victims named in the indictment are Ticketmaster, LendingTree, Advance Auto Parts, and Neiman Marcus, all of which suffered significant data breaches. In response to these widespread attacks, Snowflake has since implemented stricter password complexity requirements and mandated multi-factor authentication for its clients, underscoring the severity of the security lapse.

The scale of Moucka’s criminal enterprise is staggering. The U.S. Justice Department revealed that Moucka and his accomplices accessed and downloaded terabytes of sensitive customer information. This stolen data included not only non-content call and text history records but also critical financial information such as banking details, payroll records, and other personally identifiable information (PII) like Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, and social security numbers. The hackers then leveraged this stolen data as leverage, threatening to publish it online unless hefty ransom payments were made. This tactic of "data exfiltration and extortion" has become a prevalent and damaging strategy in the modern cybercrime landscape.

Canadian Man Pleads Guilty in Snowflake Extortions

Moucka’s criminal activities were not limited to data theft and extortion. The Justice Department also detailed his aggressive tactics in threatening and harassing government officials and security researchers who were actively involved in investigating and tracking him down. This demonstrates a pattern of escalating criminal behavior and a willingness to obstruct justice. The conspirators are believed to have extorted over $2.5 million in ransom payments. In a particularly egregious instance, Moucka reportedly re-extorted a victim by threatening further disclosure of their already stolen data, even using the stolen information of a government officer and their immediate family members to amplify the pressure. This level of personal targeting highlights the ruthless nature of these cybercriminals.

The investigation into Moucka’s activities has also shed light on a network of interconnected cybercriminals. One of Moucka’s admitted co-conspirators is Cameron "Kiberphant0m" Wagenius, a U.S. Army soldier who has also pleaded guilty to charges related to hacking and extortion, specifically targeting AT&T and Verizon for their customer account data. The investigative work, including detailed reporting by KrebsOnSecurity, played a crucial role in uncovering the identities and activities of these individuals. Wagenius, prior to his arrest, had bragged on hacker forums about his military service and posted what he claimed to be the AT&T call logs for then President-elect Donald Trump and then Vice President Kamala Harris, as well as schematics allegedly stolen from the U.S. National Security Agency (NSA). This connection between a serving soldier and sophisticated cybercrime is a deeply concerning development.

Wagenius faces significant penalties, including a maximum of 20 years in prison for conspiracy to commit wire fraud, five years for extortion related to computer fraud, and a mandatory two-year consecutive sentence for aggravated identity theft. His sentencing is scheduled for September 3, 2026.

A third alleged co-conspirator is John Erin Binns, a 26-year-old American national who has proven to be an elusive figure. Binns was indicted for his admitted involvement in a massive 2021 data breach at T-Mobile, which exposed the personal information of at least 76 million customers. Sources indicate that Binns, also known online as "IRDev" and "IntelSecrets," was recently incarcerated in a Turkish prison but has since been released. He has reportedly resurfaced online and, significantly, has obtained Turkish citizenship. Under Turkish law, citizens cannot be extradited to foreign countries, which may complicate efforts to bring him to justice in the United States.

Canadian Man Pleads Guilty in Snowflake Extortions

Moucka’s guilty plea encompasses four criminal counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. He is scheduled for sentencing on October 27, where he faces a mandatory minimum penalty of two years in prison for the aggravated identity theft charge, along with a potential maximum of 30 years for the other counts. The ultimate sentence will be determined by the presiding federal judge, taking into account the full scope of his extensive cybercriminal activities.

The case of Connor Riley Moucka and his co-conspirators underscores the persistent and evolving threat posed by organized cybercrime. The exploitation of cloud infrastructure, the sophisticated use of stolen credentials, and the brazen extortion tactics employed highlight the need for continuous vigilance and robust security measures by both corporations and government agencies. The international nature of these operations, involving individuals from different countries, also presents significant challenges for law enforcement agencies. The successful prosecution of Moucka represents a significant victory for cybersecurity and a testament to the dedication of investigators and prosecutors in their fight against digital adversaries. The detailed reporting and investigative journalism that preceded and accompanied these legal proceedings also played a vital role in exposing these criminal networks and bringing them to light. The ongoing pursuit of justice for the victims of these extensive data breaches and extortion schemes continues.