Connor Riley Moucka, a 26-year-old Canadian identified as one of the most significant cybercrime threat actors of 2024, has entered a guilty plea to charges of computer fraud and conspiracy to hack and extort over 165 organizations that utilized the cloud provider Snowflake. His admission of guilt also encompasses the theft of call and text history records belonging to more than 100 million AT&T customers.

The U.S. Justice Department detailed that between February and October 2024, Moucka and his co-conspirators systematically exploited stolen login credentials to compromise cloud-hosted data belonging to at least 165 clients of a U.S.-based software-as-a-service company. The attackers specifically targeted credentials for Snowflake customer accounts that lacked multi-factor authentication, leading to the extortion or attempted extortion of numerous prominent companies, including TicketMaster, Lending Tree, Advance Auto Parts, and Neiman Marcus. In the aftermath of these data breaches, Snowflake implemented enhanced password complexity requirements and enforced multi-factor authentication to bolster its security posture.

Canadian Man Pleads Guilty in Snowflake Extortions – Krebs on Security

Moucka was known for his frequent adoption of new online aliases, often managing multiple identities concurrently. Among his most recognized monikers were "Judische" and "Waifu." His involvement in the Snowflake data thefts was initially brought to light by KrebsOnSecurity in a September 2024 report, which explored the interconnectedness between Western, English-speaking cybercriminals and extremist groups that engage in the harassment and coercion of minors into self-harm or harming others. This earlier report identified "Judische" as a software engineer from Ontario with a history of participation in numerous data breaches and voice phishing attacks against U.S. companies dating back to at least 2020. Just over a month following this exposé, Canadian authorities apprehended Moucka based on a provisional warrant issued by the United States.

The government asserts that Moucka and his associates illicitly accessed and exfiltrated billions of sensitive customer records, downloading terabytes of data. This stolen information included non-content call and text history records, banking and financial details, payroll information, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, social security numbers, and other personally identifiable information. The perpetrators then extorted their victims by threatening to publicly release this sensitive data.

Beyond the data theft and extortion, Moucka also engaged in threats and harassment directed at government officials and security researchers who were actively involved in his apprehension. The Justice Department reported that the conspirators successfully extorted over $2.5 million in ransom payments. In at least one instance, Moucka re-extorted a victim by threatening further dissemination of their already stolen data. The Justice Department’s statement highlighted a particularly egregious act: "Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt."

Canadian Man Pleads Guilty in Snowflake Extortions – Krebs on Security

One of Moucka’s admitted co-conspirators is Cameron "Kiberphant0m" Wagenius, a U.S. Army soldier who pleaded guilty in July 2025. Wagenius admitted to extorting AT&T and Verizon for their customer account data. In a report published less than a month before Wagenius’s arrest, KrebsOnSecurity conducted an in-depth investigation into Wagenius’s various Telegram and Discord identities over the years, revealing that he had claimed to be in the Army and stationed in South Korea. Wagenius also engaged in re-extortion tactics. Following Moucka’s arrest, Wagenius posted on hacker forums what he alleged were AT&T call logs for then President-elect Donald Trump and then Vice President Kamala Harris, as well as schematics purportedly stolen from the U.S. National Security Agency (NSA). Wagenius is scheduled for sentencing on September 3, 2026, and faces significant prison time, including a maximum of 20 years for conspiracy to commit wire fraud, five years for extortion related to computer fraud, and a mandatory two-year sentence for aggravated identity theft, to be served consecutively.

The third alleged co-conspirator is John Erin Binns, a 26-year-old American national. Binns is an elusive figure who fled the United States after being indicted for his admitted role in a 2021 data breach at T-Mobile, which compromised the personal information of at least 76 million customers. Sources close to the investigation indicate that Binns, also known online as "IRDev" and "IntelSecrets," was recently incarcerated in a Turkish prison but has since been released. He has reportedly resurfaced online and has also obtained Turkish citizenship, which under Turkish law prevents his extradition to foreign countries.

Moucka pleaded guilty to four criminal counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. His sentencing is scheduled for October 27, where he faces a mandatory minimum penalty of two years imprisonment for the aggravated identity theft charge, alongside a maximum of 30 years for the remaining charges. The ultimate sentence will be determined by the federal judge based on the full extent of Moucka’s extensive cybercriminal activities. A more in-depth look at Moucka and Binns, including an interview with Moucka prior to his arrest, can be found in the original report on Moucka’s apprehension.