Connor Riley Moucka, a 26-year-old Canadian man from Kitchener, Ontario, has formally pleaded guilty to a sweeping array of computer fraud and conspiracy charges. Once identified by cybersecurity experts as one of the most consequential threat actors of 2024, Moucka’s admission brings a significant legal chapter to a close in a case that rattled the foundations of cloud security and exposed the vulnerabilities of major corporations worldwide.
Beyond his role in the high-profile compromise of the cloud data platform Snowflake, Moucka also admitted to his involvement in a separate, massive data theft involving the call and text history records of more than 100 million AT&T customers. His guilty plea marks the culmination of an intensive international investigation into a series of coordinated digital intrusions that resulted in the theft of billions of records and millions of dollars in illicit ransom payments.
The Anatomy of the Snowflake Breach
According to the U.S. Justice Department, the campaign orchestrated by Moucka and his co-conspirators unfolded between February and October 2024. The attackers exploited stolen login credentials to gain unauthorized access to cloud-hosted data belonging to at least 165 customers of a major U.S.-based software-as-a-service (SaaS) provider.
The hackers specifically targeted accounts that lacked robust multi-factor authentication (MFA) protocols. By bypassing these security gaps, the group successfully exfiltrated vast quantities of sensitive information. Among the high-profile victims caught in the crosshairs were household names such as TicketMaster, Lending Tree, Advance Auto Parts, and Neiman Marcus. The sheer scale of the breach prompted an industry-wide scramble, forcing Snowflake to significantly overhaul its security posture by mandating stricter password complexity requirements and enforcing MFA across its platform.
Moucka, who often operated under multiple, shifting digital identities, was most frequently known to the security community by the handles "Judische" and "Waifu." His activities were first brought to light by KrebsOnSecurity in September 2024, which detailed the alarming intersection between English-speaking cybercriminals and extremist groups that harass and extort minors. Investigative reporting identified "Judische" as a software engineer from Ontario with a history of involvement in data breaches and voice phishing attacks dating back to at least 2020. This scrutiny ultimately led to his arrest by Canadian authorities in October 2024, acting on a provisional warrant issued by the United States.

A Campaign of Theft and Re-Extortion
The scope of the data stolen by Moucka’s collective was staggering. Federal prosecutors revealed that the group downloaded terabytes of information, including non-content call and text records, banking and financial data, payroll information, and government-issued identifiers such as Social Security numbers, driver’s license numbers, and passport details. Even more alarming, the hackers obtained Drug Enforcement Administration (DEA) registration numbers, posing a significant risk to public health and security infrastructure.
Once the data was in their possession, the perpetrators pivoted to extortion, threatening to leak the stolen information online unless their demands were met. The Justice Department confirmed that the conspirators successfully extorted over $2.5 million in ransom payments. In a particularly aggressive display of criminality, Moucka and his associates frequently engaged in "re-extortion"—a tactic where victims who paid the initial ransom were targeted again with threats of further data exposure.
In one instance, the group targeted a government official and their immediate family members, utilizing their stolen personal data to apply additional pressure. Beyond their primary victims, the group actively harassed and intimidated security researchers and government officials who were working to track their movements, demonstrating a level of malice that transcended standard financial cybercrime.
The Network of Co-conspirators
Moucka did not operate in a vacuum. The investigation identified two primary co-conspirators, both of whom have histories of high-level cybercriminal activity. The first, Cameron "Kiberphant0m" Wagenius, was a U.S. Army soldier who pleaded guilty in July 2025 to extorting both AT&T and Verizon for customer account data. Prior to his arrest, investigative deep dives into Wagenius’s activity on Telegram and Discord platforms revealed his boasting about his military service and his stationing in South Korea.
The fallout from the investigation was compounded by the actions of Wagenius following Moucka’s arrest. In an attempt to assert continued leverage, Wagenius posted what he claimed were the private AT&T call logs of then President-elect Donald Trump and Vice President Kamala Harris on various hacker forums. He also claimed to have leaked schematics stolen from the U.S. National Security Agency (NSA). Wagenius, who is currently awaiting a September 3, 2026, sentencing date, faces a potential 20-year prison sentence for wire fraud, alongside mandatory consecutive sentencing for aggravated identity theft.

The third individual named in the investigation is 26-year-old John Erin Binns, known online as "IRDev" and "IntelSecrets." Binns is a well-known figure in the cybersecurity community, having been indicted for his role in the 2021 T-Mobile breach that compromised the personal data of 76 million customers. Following the indictment, Binns fled the United States and spent time in a Turkish prison. Recent reports indicate that he has been released and has resurfaced online. Crucially, sources suggest that Binns has acquired Turkish citizenship, potentially shielding him from extradition under Turkish law, which prohibits the extradition of its own citizens.
Sentencing and Legal Consequences
For Connor Riley Moucka, the legal reality is stark. He has entered guilty pleas for four criminal counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. He is scheduled to be sentenced on October 27, facing a mandatory minimum of two years for the aggravated identity theft charge and a maximum of 30 years for the remaining counts.
While the mandatory minimum provides a floor for his punishment, the final duration of his incarceration will rest in the hands of the federal judge. The case serves as a grim reminder of the evolving threat landscape, where individual actors—often working from the comfort of their homes—can leverage stolen credentials and aggressive extortion tactics to bring global corporations and government entities to their knees. As the justice system processes the participants in these breaches, the broader cybersecurity community continues to grapple with the lasting impacts of the data stolen and the security vulnerabilities that remain exposed in the wake of their campaign.

