A 26-year-old Canadian national, once identified as one of the most significant and consequential cybercrime threats of 2024, has entered a formal plea of guilty to charges of computer fraud and conspiracy. Connor Riley Moucka, a resident of Kitchener, Ontario, admitted to orchestrating a sophisticated hacking and extortion campaign that targeted more than 165 organizations utilizing the cloud services provider Snowflake. Beyond the scope of the Snowflake attacks, Moucka further admitted to the large-scale theft of call and text history records belonging to more than 100 million AT&T customers, a disclosure that highlights the staggering breadth of his criminal activity.
The U.S. Justice Department revealed that between February and October 2024, Moucka and a network of co-conspirators leveraged stolen login credentials to infiltrate cloud-hosted data environments. By systematically targeting Snowflake customer accounts that failed to enforce robust multi-factor authentication (MFA) protocols, the group gained unauthorized access to vast troves of sensitive information. The list of victims impacted by these breaches includes a variety of high-profile entities, such as TicketMaster, LendingTree, Advance Auto Parts, and Neiman Marcus. In the wake of these security failures, Snowflake implemented more stringent password complexity requirements and mandated the use of multi-factor authentication to bolster its platform’s defenses.
Moucka, who operated under a revolving door of digital monikers—most notably "Judische" and "Waifu"—frequently managed multiple online identities simultaneously to obscure his tracks. His criminal career, however, did not begin in 2024. Investigative reports from KrebsOnSecurity first linked the identity of "Judische" to the Snowflake data thefts in September 2024, uncovering a disturbing nexus between Western, English-speaking cybercriminals and extremist groups that have been known to harass and coerce minors into committing self-harm.
Prior to his identification as a major threat actor, intelligence gathered by security researchers depicted Judische as a software engineer based in Ontario who had been active in data breaches and voice-phishing campaigns against U.S. corporations since at least 2020. The scrutiny intensified following a series of digital footprints that culminated in his arrest by Canadian authorities, acting on a provisional warrant issued by the United States.

The Justice Department’s filings detail a campaign of industrial-scale data theft. The conspirators allegedly exfiltrated billions of individual customer records, amounting to terabytes of sensitive information. The nature of this stolen data was comprehensive, encompassing non-content call and text logs, banking and financial records, payroll data, and official government credentials, including Drug Enforcement Administration (DEA) registration numbers. Furthermore, the hackers successfully obtained passport numbers, driver’s license information, and Social Security numbers. This data was not merely stolen; it was weaponized to extort victims under the threat of public disclosure.
The scope of Moucka’s operations extended beyond corporate entities; he also engaged in the targeted harassment of government officials and security researchers who were instrumental in the investigation into his activities. According to the Justice Department, the conspirators successfully extorted over $2.5 million in ransom payments. In a particularly egregious example of his methodology, Moucka engaged in a practice known as "re-extortion," where a victim is targeted repeatedly even after an initial ransom payment has been made. In one instance, Moucka utilized the stolen personal data of a government official—and that of their immediate family members—to coerce further payment, demonstrating a calculated and ruthless approach to his criminal enterprise.
The investigation into the Snowflake extortion scheme also identified two primary co-conspirators who worked in tandem with Moucka. One of these individuals is Cameron "Kiberphant0m" Wagenius, a U.S. Army soldier who entered his own guilty plea in July 2025 regarding a conspiracy to extort telecommunications giants AT&T and Verizon. Investigative deep dives into Wagenius’s history on platforms like Telegram and Discord revealed that he had frequently boasted about his military service and his stationing in South Korea while operating under his digital aliases.
Wagenius, much like Moucka, demonstrated a propensity for escalation. Shortly after Moucka’s arrest, Wagenius posted what he claimed to be sensitive information on various hacker forums, including AT&T call logs associated with then-President-elect Donald Trump and then-Vice President Kamala Harris. He also claimed to possess schematics allegedly stolen from the U.S. National Security Agency (NSA). Wagenius is currently awaiting sentencing, which is scheduled for September 3, 2026. He faces significant legal jeopardy, including a maximum of 20 years in prison for conspiracy to commit wire fraud, five years for extortion related to computer fraud, and a mandatory two-year consecutive sentence for aggravated identity theft.

The third individual identified in the conspiracy is John Erin Binns, a 26-year-old American who had previously been indicted for his role in the 2021 T-Mobile breach, an incident that resulted in the exposure of personal information for at least 76 million customers. Binns, known in cybercriminal circles as "IRDev" or "IntelSecrets," has proven to be an elusive figure. While investigators tracked him to a Turkish prison, he has since been released and has reportedly resurfaced in the online community. Sources close to the investigation indicate that Binns has successfully obtained Turkish citizenship. Because Turkish law typically prohibits the extradition of its own citizens to foreign jurisdictions, Binns remains a complex challenge for U.S. prosecutors seeking to hold him accountable for his alleged role in the global wave of data breaches.
For Moucka, the legal ramifications are severe. He has pleaded guilty to four criminal counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. He is scheduled to be sentenced on October 27. Under the current charges, he faces a mandatory minimum of two years for the aggravated identity theft count, with a potential maximum sentence of 30 years for the remaining charges. Ultimately, the length of his incarceration rests with the federal judge presiding over the case, who must weigh the massive scale of the data he compromised and the lives affected by his extortionate tactics against his admission of guilt.
The arrest and conviction of Moucka serve as a stark reminder of the vulnerabilities inherent in modern cloud infrastructure and the degree to which credential-based attacks can cripple even the most robust organizations. As the legal proceedings conclude, the case remains a landmark example of how federal authorities, international law enforcement, and private security researchers collaborate to unmask individuals who operate in the shadows of the dark web. The fallout from the Snowflake breach continues to resonate through the cybersecurity industry, serving as a catalyst for a broader movement toward universal multi-factor authentication and a renewed focus on the security of third-party cloud service providers.

