A 26-year-old Canadian man, once recognized as a preeminent threat in the cybercrime landscape of 2024, has formally entered a guilty plea to charges of computer fraud and conspiracy. Connor Riley Moucka, hailing from Kitchener, Ontario, admitted to his involvement in hacking and extorting over 165 organizations that utilized the cloud computing services of Snowflake. His admissions also extend to the illicit acquisition of call and text history records belonging to more than 100 million AT&T customers, a staggering breach of privacy. The U.S. Department of Justice detailed that between February and October of 2024, Moucka, operating with co-conspirators, exploited stolen login credentials to pilfer data from cloud-hosted environments of at least 165 clients of a prominent U.S.-based software-as-a-service provider.

The modus operandi of this cybercrime syndicate targeted stolen credentials associated with Snowflake customer accounts that lacked robust multi-factor authentication. This vulnerability allowed them to extort, or attempt to extort, a considerable number of high-profile companies, including but not limited to Ticketmaster, Lending Tree, Advance Auto Parts, and Neiman Marcus. In the wake of these widespread data breaches, Snowflake implemented enhanced security measures, including stricter password complexity requirements and the mandatory enforcement of multi-factor authentication, to fortify its infrastructure against future attacks.

Moucka was a master of digital disguise, frequently adopting new online aliases and often managing multiple identities concurrently. Among his most recognizable monikers were "Judische" and "Waifu." His admitted participation in the Snowflake data breaches was initially brought to light by KrebsOnSecurity in a September 2024 exposé. This report delved into the concerning nexus between Western, English-speaking cybercriminals and extremist groups that engage in harassment and extortion, particularly targeting minors and coercing them into self-harm or harming others. The September 2024 article identified "Judische" as a software engineer based in Ontario with a history of involvement in numerous data breaches and voice phishing attacks against U.S. companies dating back to at least 2020. Little over a month after this exposé, Canadian authorities, acting on a provisional warrant from the United States, apprehended Moucka.

Canadian Man Pleads Guilty in Snowflake Extortions – Krebs on Security

The prosecution asserts that Moucka and his associates, through their unauthorized access, managed to steal billions of sensitive customer records and download terabytes of data. This stolen information encompassed a broad spectrum of highly personal and confidential details, including non-content call and text history records, banking and financial information, payroll data, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, social security numbers, and other personally identifiable information (PII). The perpetrators then leveraged this compromised data by threatening to publish it online, demanding ransom payments from their victims.

Adding a particularly malicious layer to his criminal enterprise, Moucka also engaged in the threat and harassment of government officials and security researchers who were actively working to track him down. The Justice Department revealed that the conspirators successfully extorted over $2.5 million in ransom payments. In a particularly egregious act, Moucka re-extorted a victim by threatening further disclosure of their previously stolen data. The Justice Department’s official statement highlighted that Moucka "used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt."

Among Moucka’s admitted co-conspirators is Cameron Wagenius, a U.S. Army soldier who operated under the alias "Kiberphant0m." Wagenius pleaded guilty in July 2025 to charges related to extorting AT&T and Verizon for their customer account data. Less than a month prior to Wagenius’s arrest, KrebsOnSecurity published an in-depth investigation into "Kiberphant0m’s" various online identities across platforms like Telegram and Discord over several years. This investigation revealed communications where the account owner indicated they were serving in the Army and stationed in South Korea.

"Kiberphant0m" also engaged in re-extortion tactics. In the immediate aftermath of Moucka’s arrest, Wagenius posted on hacker forums what he claimed to be AT&T call logs belonging to then President-elect Donald Trump and then Vice President Kamala Harris. He also allegedly posted schematics purportedly stolen from the U.S. National Security Agency (NSA). Wagenius is scheduled for sentencing on September 3, 2026. The government indicates he faces a maximum penalty of 20 years imprisonment for conspiracy to commit wire fraud, a maximum of five years for extortion in relation to computer fraud, and a mandatory consecutive two-year sentence for aggravated identity theft.

Canadian Man Pleads Guilty in Snowflake Extortions – Krebs on Security

The third alleged co-conspirator identified in this extensive operation is John Erin Binns, a 26-year-old American national. Binns is an elusive figure who fled the United States following his indictment for his admitted role in a 2021 data breach at T-Mobile, which exposed the personal information of at least 76 million customers. Sources close to the investigation indicate that Binns, also known by his online handles "IRDev" and "IntelSecrets," was until recently incarcerated in a Turkish prison. However, he has since been released and has resurfaced online. These same sources suggest that Binns has also recently acquired Turkish citizenship, a status that, under Turkish law, prevents his extradition to a foreign country.

Moucka has pleaded guilty to four criminal counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. His sentencing is slated for October 27, where he faces a mandatory minimum penalty of two years imprisonment for the aggravated identity theft charge, along with a maximum penalty of 30 years for the remaining counts. The ultimate sentence will be determined by the federal judge, taking into account the full extent of Moucka’s extensive cybercriminal activities. An earlier interview with Moucka conducted prior to his arrest, along with a more detailed examination of John Erin Binns’s activities, can be found in KrebsOnSecurity’s original report concerning Moucka’s arrest.