The U.S. Department of Justice has detailed a chilling timeline of Moucka’s digital transgressions, stating that between February and October of 2024, he and a network of accomplices systematically exploited stolen login credentials. This allowed them to gain unauthorized access to sensitive cloud-hosted data from a substantial number of clients of a prominent U.S.-based software-as-a-service provider. The hackers strategically targeted Snowflake customer accounts that lacked robust multi-factor authentication (MFA) protections, making them vulnerable to exploitation. The ensuing data breaches and extortion attempts ensnared a range of high-profile companies, including industry giants like Ticketmaster, Lending Tree, Advance Auto Parts, and the luxury retailer Neiman Marcus. In the wake of these significant security incidents, Snowflake was compelled to implement stricter password complexity requirements and enforce mandatory multi-factor authentication across its platform to bolster its defenses.

Moucka was a prolific operator within the cybercrime underground, known for his chameleon-like ability to adopt new online personas with remarkable frequency. He often managed multiple aliases concurrently, making him a difficult target for law enforcement. Among his most recognized and notorious online monikers were "Judische" and "Waifu." The involvement of "Judische" in the widespread Snowflake data breaches was initially brought to light by KrebsOnSecurity in a September 2024 investigative report. This report meticulously detailed the disconcerting overlap between Western, English-speaking cybercriminals and extremist groups that engage in the abhorrent practice of harassing and extorting minors, compelling them to inflict harm upon themselves or others.

The September 2024 exposé identified "Judische" as a software engineer residing in Ontario, Canada. The report detailed his alleged involvement in a string of data breaches and sophisticated voice phishing attacks targeting U.S. companies, a pattern of criminal behavior that stretched back to at least 2020. Subsequently, just over a month after this initial reporting, Canadian authorities, acting on a provisional arrest warrant issued by the United States, apprehended Moucka. This arrest marked a significant turning point in the investigation, signaling a coordinated effort between international law enforcement agencies to dismantle Moucka’s criminal enterprise.

The government’s case further elaborates on the devastating consequences of Moucka’s actions. It asserts that Moucka and his co-conspirators leveraged their unauthorized access to exfiltrate billions of sensitive customer records. The sheer volume of stolen data was staggering, comprising terabytes of information. This trove included not only non-content call and text history records but also deeply personal and financially sensitive information such as banking details, other financial records, payroll information, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, social security numbers, and a wide array of other personally identifiable information (PII). The perpetrators then engaged in extortion, threatening to publicly release this compromised data unless substantial ransom payments were made.

Canadian Man Pleads Guilty in Snowflake Extortions

Beyond targeting corporate entities, Moucka also exhibited a pattern of threatening and harassing government officials and cybersecurity researchers who were actively involved in efforts to track him down. The Department of Justice revealed that the conspirators successfully extracted over $2.5 million in ransom payments from their victims. In a particularly egregious instance, Moucka was found to have re-extorted a victim, leveraging threats of further disclosure of previously stolen data to extract additional payments. This tactic highlights a chilling escalation in his criminal modus operandi, demonstrating a willingness to exploit victims repeatedly.

The Justice Department’s statement unequivocally outlines the severity of this re-extortion attempt: "Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt." This specific detail underscores the personal and deeply invasive nature of the data that was compromised and weaponized by Moucka and his associates.

Among Moucka’s admitted co-conspirators is Cameron "Kiberphant0m" Wagenius, a U.S. Army soldier who, in July 2025, pleaded guilty to charges related to the extortion of AT&T and Verizon for their customer account data. Intriguingly, less than a month before Wagenius’s arrest, KrebsOnSecurity published an in-depth investigation into "Kiberphant0m’s" various online identities across platforms like Telegram and Discord. This investigation revealed that Wagenius had, at various times, indicated to others that he was a member of the U.S. Army stationed in South Korea, adding another layer of complexity to his alleged criminal involvement.

"Kiberphant0m" also engaged in re-extortion tactics. In a highly publicized incident immediately following Moucka’s arrest, "Kiberphant0m" posted on hacker forums what he claimed to be the AT&T call logs for then President-elect Donald Trump and then Vice President Kamala Harris. Furthermore, he allegedly shared schematics purportedly stolen from the U.S. National Security Agency (NSA), a revelation that sent shockwaves through intelligence and cybersecurity communities.

Wagenius is currently scheduled for sentencing on September 3, 2026. The government has indicated that he faces a maximum penalty of 20 years in prison for conspiracy to commit wire fraud, a maximum of five years for extortion in relation to computer fraud, and a mandatory consecutive two-year sentence for aggravated identity theft. These penalties reflect the gravity of his involvement in the sophisticated cybercrime ring.

Canadian Man Pleads Guilty in Snowflake Extortions

The third alleged co-conspirator in this extensive operation is John Erin Binns, a 26-year-old American national. Binns is described as an elusive figure who fled the United States after being indicted for his admitted role in a significant 2021 data breach at T-Mobile, which exposed the personal information of at least 76 million customers.

Sources closely connected to the investigation have revealed that Binns, also known online by the pseudonyms "IRDev" and "IntelSecrets," was, until recently, incarcerated in a Turkish prison. However, he has since been released and has reportedly resurfaced online, making his current whereabouts and activities a subject of ongoing concern. Crucially, these sources also indicated that Binns has recently obtained Turkish citizenship. Under Turkish law, citizens cannot be extradited to foreign countries, a legal technicality that may significantly complicate any future attempts by U.S. authorities to bring him to justice.

Moucka has formally pleaded guilty to four criminal counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. His sentencing is scheduled for October 27, where he faces a mandatory minimum penalty of two years in prison for the aggravated identity theft charge. Additionally, he could receive a maximum sentence of up to 30 years in prison for the remaining counts. The ultimate duration of Moucka’s incarceration will be determined by the federal judge, who will weigh the extensive nature of his cybercriminal activities against sentencing guidelines. For a more comprehensive understanding of Moucka’s alleged activities and a deeper dive into the background of John Erin Binns, readers are encouraged to refer to the original report on Moucka’s arrest published by KrebsOnSecurity.