Main Facts
A 26-year-old Canadian national has officially entered a guilty plea for his role in one of the most destructive and far-reaching cybercrime campaigns of recent years. Connor Riley Moucka, a resident of Kitchener, Ontario, admitted before a federal court to multiple counts of computer fraud, wire fraud, conspiracy, and aggravated identity theft.
Regarded by cybersecurity intelligence firms and law enforcement alike as a pivotal threat actor of 2024, Moucka masterminded a large-scale data theft and extortion ring. Operating primarily under digital aliases such as "Judische" and "Waifu," Moucka and an interconnected network of co-conspirators targeted cloud storage environments, most notably enterprise software-as-a-service provider Snowflake.
By exploiting accounts that lacked multi-factor authentication (MFA), Moucka’s cybercrime cell successfully breached over 165 corporate organizations. The stolen trove included petabytes of sensitive enterprise data, proprietary system blueprints, and billions of consumer records. Among the high-profile casualties were retail giants, financial institutions, and telecommunications monoliths, including Ticketmaster, LendingTree, Advance Auto Parts, Neiman Marcus, and AT&T. In the case of AT&T alone, the group pilfered the non-content call and text history records of more than 100 million customers.
The U.S. Department of Justice (DOJ) confirmed that Moucka’s operation amassed over $2.5 million in extortion payments. In a brazen escalation, Moucka and his cohorts targeted government officials and security researchers assisting in the multi-agency manhunt, even weaponizing stolen data against family members of a former government official in secondary extortion attempts.
Moucka now faces up to 30 years in prison on the primary counts, alongside a mandatory consecutive two-year sentence for aggravated identity theft. His sentencing hearing is scheduled for October 27.
Chronology of a Global Cyber Heist
The unraveling of the Snowflake extortion syndicate represents a masterclass in modern digital forensics, tracing a trajectory from quiet underground forums to international arrests and landmark guilty pleas.
2020–2023: The Foundation of the Threat Cell
Long before striking Snowflake, the key players in Moucka’s network were honing their tradecraft. Security researchers trace Connor Moucka’s cybercriminal history back to at least 2020, where he operated as a software engineer out of Ontario, launching voice phishing (vishing) attacks and participating in boutique data breaches against U.S. firms. Concurrently, co-conspirator John Erin Binns—operating as "IRDev" and "IntelSecrets"—was carving out his own notorious path. Binns was indicted for his role in the devastating 2021 T-Mobile data breach, which compromised the personal records of at least 76 million customers, before fleeing the United States.
February – October 2024: The Snowflake Campaign
The primary phase of Moucka’s enterprise ignited in early 2024. Leveraging compromised credential lists harvested from infostealer malware or historical leaks, Moucka and his co-conspirators systematically probed corporate accounts hosted on Snowflake. Bypassing systems that neglected to enforce mandatory MFA, they exfiltrated massive volumes of proprietary data. High-profile extortion demands followed rapidly.

By September 2024, investigative journalism by KrebsOnSecurity began mapping the dark nexus connecting Western, English-speaking hackers to online harassment groups, specifically unmasking "Judische" as an Ontario-based software engineer linked to the Snowflake intrusions.
Late 2024: The Net Closes and Arrests Follow
Pressure from the FBI, the Royal Canadian Mounted Police (RCMP), and private cybersecurity incident responders triggered a rapid sequence of events:
- Late October 2024: Armed with a provisional arrest warrant issued by the United States, Canadian authorities apprehended Connor Riley Moucka in Ontario. Surveillance photos later highlighted in RCMP affidavits captured Moucka just nine days prior to his collar.
- November 2024: Investigators publicly linked U.S. Army soldier Cameron "Kiberphant0m" Wagenius to the telecommunications breaches. Wagenius, stationed in South Korea, had utilized Telegram and Discord to boast about his access. Following Moucka’s arrest, a panicked Wagenius doubled down, posting what he claimed were AT&T call logs of major political figures on hacker forums.
July 2025 – Present: Legal Reckoning
The judicial fallout accelerated through mid-2025. Cameron Wagenius pleaded guilty to hacking and extortion charges in July 2025, with his sentencing slated for September 3, 2026. Meanwhile, John Erin Binns surfaced overseas; reportedly incarcerated in Turkey for a period before securing Turkish citizenship—a legal maneuver shielding him from foreign extradition. Finally, Connor Moucka’s guilty plea brings the primary architects of the Snowflake campaign to justice, closing a dark chapter in cloud security history.
Supporting Data and Technical Vectors
The scale of the Snowflake and AT&T breaches underscores the devastating potency of credential stuffing and lax enterprise security hygiene. The technical metrics associated with the criminal operation paint a clear picture of their methodology:
- 165+ Organizations Impacted: The primary vector relied on targeting Snowflake customer tenants that failed to implement robust authentication protocols. Without MFA enforced, a single compromised user credential granted the threat actors deep read access to enterprise cloud repositories.
- 100+ Million AT&T Records: Through lateral movement and coordinated attacks with co-conspirators like Wagenius, the syndicate siphoned extensive telecommunications metadata, exposing non-content call and text logs of virtually the entire AT&T subscriber base.
- Billions of Sensitive Records: Exfiltrated data packets included an expansive array of Personally Identifiable Information (PII), such as:
- Social Security Numbers (SSNs)
- Driver’s license and passport numbers
- Banking, payroll, and financial transaction logs
- Drug Enforcement Administration (DEA) registration numbers
- $2.5 Million in Extortion Yields: The collective operation forced multiple enterprise victims to pay multi-million-dollar ransoms in cryptocurrency to prevent the public leakage of proprietary source code, customer directories, and internal memos.
Official Responses
The Department of Justice, regulatory bodies, and affected private entities have issued strong statements addressing the implications of the case, emphasizing both the severity of the crimes and the necessity of structural security upgrades.
In an official DOJ statement, federal prosecutors underscored the personal and systemic harm caused by the defendants:
"Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt."
The brazen targeting of government personnel, coupled with the exposure of critical telecommunications infrastructure, prompted swift cross-border cooperation. Federal law enforcement agencies in the United States, Canada, and allied international jurisdictions coordinated intelligence sharing to neutralize the threat network.

Following the initial breaches, Snowflake took aggressive remedial action. The cloud provider overhauled its enterprise security baselines, mandating stricter password complexity requirements and rolling out forced multi-factor authentication across all customer environments to eliminate the primary vector utilized by "Judische" and his cohorts. Similarly, telecommunications leaders subjected their internal credential management and vendor access pathways to rigorous third-party security audits.
Implications for Enterprise Security and Global Cybercrime
The guilty plea of Connor Riley Moucka marks a watershed moment for cloud security, illuminating critical vulnerabilities in modern enterprise architectures and the dangerous evolution of online threat syndicates.
The Death of Optional Multi-Factor Authentication
The Snowflake breaches serve as a cautionary tale for the software-as-a-service (SaaS) industry. For years, organizations treated multi-factor authentication as an optional convenience feature rather than an absolute baseline requirement. The exploitation of 165 corporate tenants exposed the catastrophic business risk of relying solely on static passwords. Enterprises worldwide have since been forced to adopt zero-trust architectures, ensuring that identity and access management (IAM) controls are uniformly enforced across all internal and third-party environments.
Insider Threats and the Radicalized Underground
The involvement of U.S. Army soldier Cameron Wagenius highlights a troubling convergence between traditional military personnel and the modern cybercriminal underground. The ease with which radicalized youth transition from online harassment and doxxing forums to high-stakes corporate espionage points to deep cultural shifts within digital subcultures. Threat actors are no longer isolated basement hackers; they are globally distributed cells capable of penetrating Fortune 500 infrastructure and weaponizing telecommunications metadata for geopolitical and financial leverage.
The Geopolitical Asylum Loophole
The case of John Erin Binns underscores the persistent challenges of international law enforcement. By exploiting legal loopholes—such as obtaining citizenship in non-extradition nations like Turkey—indicted cybercriminals can effectively evade American and Canadian courts, remaining online ghosts despite clear forensic attribution.
Ultimately, while Moucka’s guilty plea delivers a major victory for international cybersecurity defense, it serves as a stark reminder that the digital landscape remains under siege by agile, cross-border syndicates willing to exploit every crack in the global cloud perimeter.

