A 26-year-old Canadian national, identified as Connor Riley Moucka of Kitchener, Ontario, has entered a guilty plea in a significant cybercrime case involving the cloud storage provider Snowflake. Moucka, who has been described as one of the most impactful cybercrime threat actors of 2024, has admitted to charges of computer fraud and conspiracy. These charges stem from his alleged involvement in hacking and extorting over 165 organizations that utilized Snowflake’s services. In a parallel and equally concerning admission, Moucka also pleaded guilty to stealing call and text history records belonging to more than 100 million AT&T customers.
The U.S. Department of Justice detailed how, between February and October of 2024, Moucka and his co-conspirators systematically exploited stolen login credentials. This illicit access allowed them to pilfer data from cloud-hosted environments belonging to at least 165 clients of the U.S.-based software-as-a-service company, Snowflake. The hackers strategically targeted credentials for Snowflake customer accounts that lacked multi-factor authentication, a critical security layer that would have significantly hindered their unauthorized access. Their subsequent actions involved extorting, or attempting to extort, a roster of prominent companies, including well-known entities such as Ticketmaster, LendingTree, Advance Auto Parts, and Neiman Marcus. In response to these widespread data breaches, Snowflake was compelled to enhance its security protocols, notably by increasing password complexity requirements and mandating multi-factor authentication for its users.
Moucka was a prolific actor in the cybercrime landscape, known for his fluid use of online aliases. He frequently adopted new monikers and sometimes operated multiple identities concurrently to evade detection and foster anonymity. Among his most recognized online personas were "Judische" and "Waifu." Moucka’s direct involvement in the Snowflake data breaches was initially brought to light by KrebsOnSecurity in a September 2024 report. This earlier investigation delved into the disconcerting overlap between Western, English-speaking cybercriminals and extremist groups that engage in the harassment and extortion of minors, compelling them to inflict harm upon themselves or others.

The September 2024 report by KrebsOnSecurity identified "Judische" as a software engineer hailing from Ontario, Canada. His alleged criminal activities, which included participation in numerous data breaches and voice phishing attacks against U.S. companies, dated back to at least 2020. A little over a month after this exposé, Canadian authorities, acting on a provisional warrant issued by the United States, apprehended Moucka.
The U.S. government asserts that Moucka and his accomplices, through their unauthorized access, managed to steal billions of sensitive customer records. They downloaded terabytes of highly confidential information, encompassing not only call and text history records but also banking and financial details, payroll information, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, social security numbers, and a broad spectrum of other personally identifiable information (PII). The modus operandi of the perpetrators involved extorting their victims by threatening to publicly release this stolen data online.
Beyond targeting organizations, Moucka also engaged in threatening and harassing behavior directed at government officials and security researchers who were actively working to track his activities and bring him to justice. The Justice Department indicated that the conspirators successfully extorted over $2.5 million in ransom payments. In a particularly egregious instance, Moucka is accused of re-extorting a victim, leveraging threats of further disclosure of their previously stolen data to extract additional payments. The Justice Department’s statement highlighted a disturbing detail: "Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt."
Among Moucka’s admitted co-conspirators is Cameron "Kiberphant0m" Wagenius, a member of the U.S. Army. Wagenius himself pleaded guilty in July 2025 to charges related to extorting AT&T and Verizon for their customer account data. Less than a month prior to Wagenius’s arrest, KrebsOnSecurity published an in-depth examination of Wagenius’s various Telegram and Discord identities over the years. This investigation revealed that Wagenius had informed others that he was a soldier in the U.S. Army stationed in South Korea.

Wagenius also engaged in re-extortion tactics. Immediately following Moucka’s arrest, Wagenius reportedly posted on hacker forums what he claimed to be AT&T call logs for then President-elect Donald Trump and then Vice President Kamala Harris. He also allegedly shared schematics purportedly stolen from the U.S. National Security Agency (NSA). Wagenius is scheduled for sentencing on September 3, 2026. The government is seeking a maximum penalty of 20 years in prison for conspiracy to commit wire fraud, a maximum of five years for extortion related to computer fraud, and a mandatory consecutive two-year sentence for aggravated identity theft.
The third alleged co-conspirator identified in this wide-ranging cybercrime operation is John Erin Binns, a 26-year-old American national. Binns is described as an elusive figure who fled the United States after being indicted for his admitted role in a 2021 data breach at T-Mobile, which exposed the personal information of at least 76 million customers. Sources close to the investigation indicated that Binns, also known by the aliases "IRDev" and "IntelSecrets," was recently incarcerated in a Turkish prison. However, he has since been released and has reappeared online. These same sources suggest that Binns has also recently acquired Turkish citizenship, which, under Turkish law, prevents his extradition to a foreign country.
Moucka’s guilty plea encompasses four criminal counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. His sentencing is scheduled for October 27, where he faces a mandatory minimum penalty of two years imprisonment for the aggravated identity theft charge. Additionally, he could be sentenced to a maximum of 30 years in prison for the remaining counts. Ultimately, the determination of Moucka’s actual prison sentence will rest with the federal judge overseeing his case, taking into account the totality of his extensive cybercriminal activities. A more detailed account of Moucka’s arrest and a deeper exploration of John Erin Binns’s background can be found in the original report on Moucka’s arrest published by KrebsOnSecurity.

