A 26-year-old Canadian man once identified by cybersecurity researchers as one of the most destructive and consequential cybercrime threat actors of 2024 has officially pleaded guilty to computer fraud and conspiracy. Connor Riley Moucka, hailing from Kitchener, Ontario, admitted to orchestrating a sweeping campaign to hack and extort more than 165 corporate organizations that utilized the cloud data platform Snowflake. Alongside his admitted involvement in the Snowflake intrusions, Moucka also confessed to stealing the sensitive call and text history records belonging to more than 100 million customers of telecommunications giant AT&T.
The developments mark a major milestone in a sprawling international cybercrime investigation led by U.S. and Canadian law enforcement agencies. According to filings from the U.S. Justice Department, Moucka and a network of co-conspirators operated between February and October 2024. During this multi-month spree, the hackers systematically leveraged stolen login credentials to infiltrate cloud-hosted environments and plunder corporate databases belonging to at least 165 high-profile customers of the major U.S.-based software-as-a-service provider.
The threat actors capitalized on a glaring security oversight across numerous corporate accounts: the failure to enforce robust multi-factor authentication. By exploiting these vulnerable Snowflake customer profiles, Moucka and his associates gained unauthorized access to proprietary corporate files, intellectual property, and extensive consumer databases. The criminal enterprise then turned this access into leverage, running a high-stakes extortion campaign against a vast roster of well-known corporate entities. Among the prominent victims targeted by the hackers were major brands including TicketMaster, LendingTree, Advance Auto Parts, and Neiman Marcus. In the wake of the devastating breaches, Snowflake moved swiftly to overhaul its platform security, implementing stricter password complexity mandates and making multi-factor authentication mandatory for user accounts.
Throughout his tenure in the cybercrime underworld, Moucka frequently rotated through a variety of online handles, sometimes managing multiple distinct personas simultaneously to mask his digital footprint. However, two of his most prominent monikers—"Judische" and "Waifu"—became deeply familiar to threat intelligence analysts tracking the intrusions. The connection between the persona known as Judische and the widespread Snowflake data thefts was first exposed by KrebsOnSecurity in a September 2024 investigative report. That report detailed the dark nexus connecting Western, English-speaking cybercriminals with extremist networks engaged in the harassment, swatting, and extortion of minors to coerce them into harming themselves or others.

The initial September report identified Judische as a software engineer based in Ontario who had maintained active involvement in numerous corporate data breaches and aggressive voice-phishing campaigns targeting U.S. enterprises since at least 2020. Barely a month after those findings were published, Canadian law enforcement officials moved in, arresting Moucka on a provisional warrant issued by the United States government.
Federal prosecutors detailed the staggering scale of the data pillaged during the conspiracy, noting that Moucka and his accomplices utilized their unauthorized access to steal billions of sensitive customer records and download terabytes of proprietary information. The stolen troves encompassed a vast array of confidential material, including non-content call and text history records, banking and financial data, corporate payroll archives, Drug Enforcement Administration registration numbers, driver’s license numbers, passport numbers, Social Security numbers, and a wide array of other personally identifiable information. Armed with these critical files, the perpetrators subjected corporate victims to relentless extortion schemes, threatening to dump sensitive internal documents and consumer data onto public hacker forums if ransom demands were not met.
As the pressure mounted from law enforcement and corporate security teams, Moucka allegedly escalated his tactics, actively threatening and harassing government officials and independent security researchers who were assisting in the effort to unmask him. According to the Justice Department, the criminal conspiracy successfully extorted over $2.5 million in ransom payments from panicked victims. In at least one egregious instance of bad faith, Moucka re-extorted a targeted victim, dangling the threat of further public disclosures of stolen data even after initial agreements had seemingly been reached.
"Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt," stated an official release from the U.S. Justice Department regarding the scope of his predatory conduct.

The investigation into the broader cybercrime syndicate also brought to light the involvement of several key co-conspirators. One of Moucka’s admitted partners in crime is Cameron "Kiberphant0m" Wagenius, a U.S. Army soldier who formally pleaded guilty in July 2025 to charges stemming from his role in extorting telecommunications companies AT&T and Verizon for their customer account databases. Just weeks prior to Wagenius’s arrest, security researchers published a deep dive into the various Telegram and Discord aliases utilized by Kiberphant0m over the years, uncovering digital footprints where the account holder openly discussed being stationed in South Korea while serving in the military.
Wagenius similarly engaged in vindictive re-extortion tactics against victim organizations. In the immediate aftermath of Moucka’s arrest, Kiberphant0m published files on underground hacker forums that he claimed were the AT&T call logs for then-President-elect Donald Trump and then-Vice President Kamala Harris, alongside engineering schematics allegedly stolen from the U.S. National Security Agency. Wagenius is scheduled to face sentencing on September 3, 2026. Federal prosecutors noted that he faces a maximum statutory penalty of 20 years in prison for conspiracy to commit wire fraud, a maximum penalty of five years for computer fraud-related extortion, and a mandatory consecutive two-year prison sentence for aggravated identity theft.
A third key figure linked to the sprawling conspiracy is John Erin Binns, a 26-year-old American national who fled the United States after being indicted for his admitted role in a massive 2021 cyberattack against T-Mobile that exposed the personal records of at least 76 million customers. Sources close to the ongoing international investigation revealed that Binns—who has operated under aliases such as "IRDev" and "IntelSecrets"—was recently incarcerated in a Turkish prison before being released back into the digital sphere. Investigators noted that Binns managed to secure Turkish citizenship during his time abroad, complicating future legal proceedings because Turkish law prohibits the extradition of its citizens to foreign jurisdictions.
Appearing before a federal court, Moucka entered formal guilty pleas to four distinct criminal counts, encompassing computer fraud, wire fraud, aggravated identity theft, and conspiracy. His sentencing hearing has been scheduled for October 27. Under the terms of the federal charges, Moucka faces a mandatory minimum sentence of two years in prison specifically for the aggravated identity theft count, coupled with a maximum potential penalty of up to 30 years in prison across the remaining counts. Ultimately, the final determination regarding the exact length of the prison term Moucka will serve for his extensive cybercriminal enterprise will rest with the presiding federal judge.
Leave a Reply