A 26-year-old Canadian man, once identified as a preeminent cybercrime threat actor of 2024, has entered a guilty plea to charges of computer fraud and conspiracy, admitting to his role in hacking and extorting over 165 organizations that utilized the cloud computing services of Snowflake. Connor Riley Moucka, hailing from Kitchener, Ontario, also confessed to the illicit acquisition of call and text history records belonging to more than 100 million AT&T customers. This admission marks a significant development in a series of sophisticated cyberattacks that have shaken the corporate world and exposed the vulnerabilities of cloud-based data storage.
The U.S. Department of Justice revealed that between February and October of 2024, Moucka, operating with a network of co-conspirators, systematically exploited stolen login credentials to pilfer sensitive cloud-hosted data from at least 165 clients of a prominent U.S.-based software-as-a-service provider. The attackers strategically targeted credentials for Snowflake customer accounts that lacked multi-factor authentication, a crucial security layer that would have significantly hindered their unauthorized access. Their nefarious activities extended to extorting or attempting to extort a number of high-profile companies, including industry giants like Ticketmaster, LendingTree, Advance Auto Parts, and Neiman Marcus. In response to these widespread data breaches, Snowflake has since implemented stricter password complexity requirements and mandated the adoption of multi-factor authentication across its platform, aiming to fortify its defenses against future attacks.
Moucka was known for his chameleon-like approach to cybercrime, frequently adopting new aliases and sometimes operating multiple identities concurrently. Among his most notorious monikers were "Judische" and "Waifu." His involvement in the Snowflake data breaches, operating under the guise of "Judische," was first brought to light by KrebsOnSecurity in a September 2024 report. This investigative piece detailed the disturbing overlap between Western, English-speaking cybercriminal elements and extremist groups that prey on vulnerable minors, coercing them into self-harm or harming others. The September report further identified "Judische" as a software engineer from Ontario with a history of involvement in numerous data breaches and voice phishing attacks targeting U.S. companies dating back to at least 2020. This initial exposé paved the way for his apprehension; a little over a month later, Canadian authorities, acting on a provisional arrest warrant issued by the United States, took Moucka into custody.

The prosecution asserts that Moucka and his accomplices leveraged their unauthorized access to abscond with billions of sensitive customer records, downloading terabytes of highly confidential information. This stolen data encompassed a disturbing array of personally identifiable information (PII), including non-content call and text history records, banking and financial details, payroll information, Drug Enforcement Administration (DEA) registration numbers, driver’s license and passport numbers, social security numbers, and other critical PII. The perpetrators then proceeded to extort their victims, threatening to publicly release the stolen data online.
Beyond targeting corporate entities, Moucka also engaged in the harassment and intimidation of government officials and security researchers who were actively working to track him down. The Justice Department further disclosed that the conspirators successfully extracted over $2.5 million in ransom payments. In a particularly egregious instance, Moucka reportedly re-extorted a victim by threatening further disclosure of their already compromised stolen data. The Justice Department’s statement highlighted the chilling detail that "Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt."
Among Moucka’s admitted co-conspirators is Cameron "Kiberphant0m" Wagenius, a U.S. Army soldier who pleaded guilty in July 2025 to charges related to extorting AT&T and Verizon for their customer account data. Prior to Wagenius’s arrest, KrebsOnSecurity published an in-depth investigation into his various online personas across platforms like Telegram and Discord. This exposé revealed how Wagenius, who identified himself as being in the Army and stationed in South Korea, was involved in these illicit activities.
Wagenius also engaged in re-extortion tactics. Notably, in the immediate aftermath of Moucka’s arrest, Wagenius posted on hacker forums what he claimed were the AT&T call logs for then President-elect Donald Trump and then Vice President Kamala Harris. He also allegedly shared schematics pilfered from the U.S. National Security Agency (NSA). Wagenius is scheduled for sentencing on September 3, 2026. The government indicates he faces a maximum penalty of 20 years imprisonment for conspiracy to commit wire fraud, a maximum of five years for extortion related to computer fraud, and a mandatory consecutive two-year sentence for aggravated identity theft.

The third alleged member of this criminal enterprise is John Erin Binns, a 26-year-old American national. Binns became an elusive figure after being indicted for his confessed involvement in a significant 2021 data breach at T-Mobile, which compromised the personal information of at least 76 million customers. Sources close to the investigation suggest that Binns, also known by the aliases "IRDev" and "IntelSecrets," was recently incarcerated in a Turkish prison. However, he has since been released and has reportedly resurfaced online. These same sources indicate that Binns has also recently acquired Turkish citizenship, which, under Turkish law, prevents his extradition to foreign countries.
Moucka’s guilty plea encompasses four criminal counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. His sentencing is scheduled for October 27, where he faces a mandatory minimum penalty of two years imprisonment for the aggravated identity theft charge, in addition to a potential maximum of 30 years for the remaining charges. The ultimate length of his sentence will be determined by the federal judge overseeing his case, considering the breadth of his extensive cybercriminal activities. For a more comprehensive understanding of Moucka’s case, including an interview conducted prior to his arrest and a deeper examination of John Erin Binns, readers are encouraged to refer to the original report on Moucka’s arrest published by KrebsOnSecurity.

