By Global Cybersecurity Desk
Published in association with investigative reporting archives
Main Facts
Connor Riley Moucka, a 26-year-old Canadian citizen from Kitchener, Ontario, has officially pleaded guilty to computer fraud, wire fraud, conspiracy, and aggravated identity theft in a U.S. federal court. Once flagged by international threat intelligence agencies as one of the most consequential and destructive cybercrime actors of 2024, Moucka admitted to spearheading a massive hacking and extortion campaign that targeted more than 165 major organizations utilizing the cloud data warehousing platform Snowflake.
Beyond the Snowflake breach, Moucka confessed to pilfering sensitive call and text history records belonging to more than 100 million AT&T customers. Operating under a rotating roster of online aliases—most notably “Judische” and “Waifu”—Moucka and an elite cell of co-conspirators systematically exploited stolen corporate credentials to download terabytes of proprietary and personally identifiable information (PII).
The U.S. Department of Justice (DOJ) revealed that the cybercriminal syndicate raked in upwards of $2.5 million in extortion payments by threatening to leak stolen corporate data, government registries, and sensitive financial records onto public cybercrime forums. Following an intense international manhunt, Moucka was apprehended by Canadian authorities in October 2024 under a provisional U.S. warrant and subsequently extradited. He now faces a maximum penalty of 30 years in federal prison, alongside a mandatory minimum two-year consecutive sentence for aggravated identity theft, with his sentencing hearing scheduled for October 27.
Chronology of the Spree
The timeline of Moucka’s illicit operations highlights an escalating trajectory of increasingly brazen enterprise breaches, cyber-extortion, and direct harassment of investigators:
- 2020–2023: Operating primarily under the moniker "Judische," Moucka establishes himself within English-speaking cybercrime undergrounds, engaging in voice phishing (vishing) and localized corporate data breaches targeting U.S. firms. During this period, he intersects with extremist digital ecosystems known for harassment, swatting, and the extortion of minors.
- February – October 2024: Moucka, alongside co-conspirators, executes a widespread campaign exploiting cloud-hosted data accounts on Snowflake. By leveraging stolen credentials that lacked Multi-Factor Authentication (MFA), the threat actors breach over 165 high-profile corporate environments, including Ticketmaster, LendingTree, Advance Auto Parts, and Neiman Marcus.
- September 2024: Investigative journalist Brian Krebs publishes a landmark exposè identifying "Judische" as an Ontario-based software engineer tied to both corporate data breaches and predatory online harm groups.
- October 21, 2024: Royal Canadian Mounted Police (RCMP) surveillance operatives photograph Moucka in Ontario just nine days before his arrest.
- October 30, 2024: Acting on a U.S. provisional arrest warrant, Canadian law enforcement officials officially arrest Moucka in Ontario, halting his campaign.
- Late 2024 – Early 2025: Following Moucka’s capture, co-conspirators attempt to pick up the mantle. Cameron "Kiberphant0m" Wagenius publicly posts what he claims are AT&T call logs belonging to prominent political figures, alongside alleged U.S. National Security Agency (NSA) schematics, in an effort to pressure victims into paying ransoms.
- July 2025: U.S. Army soldier Cameron Wagenius pleads guilty to his role in the hacking and extortion conspiracy.
- October 2025 (Upcoming): Connor Riley Moucka faces formal sentencing in a U.S. federal court.
Supporting Data and Technical Operations
The scope of the Snowflake data thefts and subsequent telecommunications breaches represents one of the largest data compromises in recent history. According to forensic analyses and DOJ filings, the operation relied less on zero-day vulnerabilities and more on brute-force persistence and credential stuffing.

The Snowflake Vulnerability
The attackers targeted customer accounts that failed to enforce Multi-Factor Authentication (MFA). By utilizing leaked or reused administrative and employee credentials sourced from prior infostealer malware infections, Moucka and his associates bypassed basic perimeter defenses. Once inside the Snowflake cloud environments, they exfiltrated massive datasets containing:
- Non-content call and text history records (affecting over 100 million AT&T customers).
- Banking, credit card, and granular financial transaction records.
- Internal corporate payroll data and tax filings.
- Drug Enforcement Administration (DEA) registration numbers.
- Driver’s license, passport, and Social Security numbers (SSNs).
Financial Impact and Re-Extortion Tactics
The enterprise ransom demands were steep, netting the conspirators more than $2.5 million in cryptocurrency payments. However, the syndicate’s methods crossed ethical boundaries even within the criminal underworld through "re-extortion"—a tactic where victims who paid ransoms were immediately hit with subsequent demands under threat of further data leaks.
In one particularly egregious instance highlighted by federal prosecutors, Moucka utilized the stolen personal data of a government official—as well as the immediate family members of a former government official—to apply intense pressure during a re-extortion attempt.
Co-Conspirators and Global Reach
Moucka did not operate in a vacuum. Federal investigations revealed an interconnected web of international hackers collaborating on Telegram, Discord, and specialized dark web forums.
1. Cameron “Kiberphant0m” Wagenius
Wagenius, a U.S. Army soldier stationed in South Korea during parts of his criminal enterprise, served as a core partner in the AT&T and Verizon extortion schemes. After Moucka’s arrest, Wagenius attempted to intimidate investigators and government officials by leaking high-profile telecom data and classified-sounding documents. Wagenius pleaded guilty in July 2025 and is scheduled to be sentenced on September 3, 2026. He faces up to 25 years in combined prison time, plus mandatory consecutive sentences for identity theft.
2. John Erin Binns (“IRDev” / “IntelSecrets”)
The third primary figure linked to the network is John Erin Binns, a 26-year-old American indicted for his role in the massive 2021 T-Mobile data breach that exposed records of over 76 million customers. Investigative sources indicate that Binns fled the United States and was temporarily incarcerated in a Turkish prison. Following his release, Binns reportedly acquired Turkish citizenship. Under Turkish constitutional law, citizens cannot be extradited to foreign jurisdictions, effectively shielding him from U.S. prosecution unless he travels abroad.

Official Responses and Industry Implications
The fallout from the Snowflake compromises and telecom attacks has triggered sweeping overhauls in cloud security compliance and corporate accountability.
Snowflake’s Security Pivot
In the wake of the attacks, Snowflake faced heavy scrutiny regarding default security postures. The company responded aggressively by upgrading its platform architecture. Snowflake instituted mandatory complex password policies and rolled out platform-wide enforcement mechanisms making Multi-Factor Authentication (MFA) compulsory for all customer accounts—a move cybersecurity experts argued should have been standard industry practice long before the 2024 breaches.
Department of Justice Stance
U.S. law enforcement officials have pointed to the dismantling of the Moucka-Wagenius ring as a milestone in international cyber-policing. The coordinated effort between the U.S. Department of Justice, the FBI, the Royal Canadian Mounted Police (RCMP), and military investigators underscores the borderless nature of modern cloud infrastructure threats.
Federal prosecutors emphasized that the severity of Moucka’s crimes—ranging from corporate extortion to the harassment of government officials and their families—warrants a stern judicial message. As Connor Riley Moucka prepares to face sentencing, the case stands as a stark warning about the dangerous convergence of cloud misconfigurations, insider threats, and transnational cyber extortion rings in the digital age.

