Connor Riley Moucka, a 26-year-old Canadian national from Kitchener, Ontario, has entered a guilty plea to multiple federal charges, admitting his central role in a sophisticated cybercrime operation that targeted over 165 organizations utilizing the cloud data provider Snowflake. Moucka, once characterized as one of the most impactful cybercrime threat actors of 2024, also confessed to the illicit acquisition of call and text history records belonging to more than 100 million AT&T customers, alongside other sensitive personal data.

The U.S. Department of Justice detailed Moucka’s extensive criminal activities, which spanned from February to October 2024. During this period, Moucka and his network of co-conspirators systematically exploited stolen login credentials to gain unauthorized access to cloud-hosted data. Their primary targets were accounts within Snowflake that lacked robust multi-factor authentication, making them vulnerable to their predatory tactics. The investigation revealed that the group extorted or attempted to extort a diverse array of prominent companies, including industry giants like Ticketmaster, LendingTree, Advance Auto Parts, and Neiman Marcus. In response to these widespread data breaches, Snowflake implemented enhanced security measures, including stricter password complexity requirements and mandatory multi-factor authentication.

Moucka was a prolific cybercriminal, frequently adopting new aliases and often operating under multiple identities concurrently. Among his most recognized monikers were "Judische" and "Waifu." His involvement as "Judische" in the Snowflake data breaches was first brought to light by KrebsOnSecurity in a September 2024 investigative report. This report also highlighted a disturbing correlation between Western, English-speaking cybercriminals and extremist groups that engage in the harassment and extortion of minors, pressuring them into self-harm or harming others. The September report identified "Judische" as a software engineer from Ontario with a history of involvement in numerous data breaches and voice phishing attacks against U.S. companies since at least 2020. Subsequently, approximately one month after the initial report, Canadian authorities apprehended Moucka on a provisional warrant issued by the United States.

Canadian Man Pleads Guilty in Snowflake Extortions

The government asserts that Moucka and his associates pilfered billions of sensitive customer records and exfiltrated terabytes of data. This stolen information included non-content call and text history records, banking and financial details, payroll information, Drug Enforcement Administration (DEA) registration numbers, driver’s license and passport numbers, social security numbers, and a broad spectrum of other personally identifiable information. The conspirators then leveraged this data for extortion, threatening to publish it online.

Beyond targeting corporate entities, Moucka also engaged in threats and harassment directed at government officials and security researchers who were actively working to identify and apprehend him. The Justice Department revealed that the conspirators received over $2.5 million in ransom payments. In a particularly egregious instance, Moucka re-extorted a victim by threatening further disclosure of their already stolen data. This re-extortion attempt specifically involved the compromised data of a government officer and members of their immediate family.

A key co-conspirator identified in the case is Cameron Wagenius, also known as "Kiberphant0m." Wagenius, a U.S. Army soldier, pleaded guilty in July 2025 to charges related to the extortion of AT&T and Verizon for their customer account data. Intriguingly, less than a month prior to Wagenius’s arrest, KrebsOnSecurity published an in-depth investigation into "Kiberphant0m’s" various online personas across platforms like Telegram and Discord. This investigation uncovered evidence suggesting the owner of these accounts was serving in the U.S. Army and stationed in South Korea.

"Kiberphant0m" also engaged in re-extortion activities. Notably, in the immediate aftermath of Moucka’s arrest, Wagenius posted on hacker forums what he claimed to be AT&T call logs belonging to then President-elect Donald Trump and then Vice President Kamala Harris. He also allegedly shared schematics purportedly stolen from the U.S. National Security Agency (NSA). Wagenius is scheduled for sentencing on September 3, 2026. The government indicates he faces a maximum penalty of 20 years imprisonment for conspiracy to commit wire fraud, a maximum of five years for extortion related to computer fraud, and a mandatory consecutive two-year sentence for aggravated identity theft.

Canadian Man Pleads Guilty in Snowflake Extortions

The third alleged co-conspirator is John Erin Binns, a 26-year-old American national who evaded U.S. authorities after being indicted for his admitted involvement in a 2021 data breach at T-Mobile. This breach exposed the personal information of at least 76 million customers. Sources close to the investigation indicate that Binns, also known by the handles "IRDev" and "IntelSecrets," was recently incarcerated in a Turkish prison but has since been released and has reappeared online. These sources further suggest that Binns has acquired Turkish citizenship, and under Turkish law, citizens cannot be extradited to foreign countries.

Moucka has pleaded guilty to four criminal counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. His sentencing is scheduled for October 27th. He faces a mandatory minimum penalty of two years imprisonment for the aggravated identity theft charge, and a potential maximum of 30 years for the remaining counts. The ultimate sentence Moucka receives will be determined by the federal judge, taking into account the breadth of his extensive cybercriminal record. For a more detailed account of Moucka’s arrest and an interview conducted prior to his apprehension, readers are referred to the original report published by KrebsOnSecurity.