Cybersecurity and Digital Privacy

Canadian Mastermind Behind Massive Snowflake and AT&T Data Extortion Schemes Pleads Guilty in U.S. Federal Court

Connor Riley Moucka, a 26-year-old software engineer from Kitchener, Ontario, who was widely identified as one of the most prolific and consequential cybercrime threat actors of 2024, has formally pleaded guilty to multiple federal charges. Moucka’s guilty plea in a U.S. federal court marks a major milestone in a sprawling, multi-jurisdictional investigation into some of the largest corporate and telecommunications data breaches in recent history. The charges center on a massive, highly coordinated campaign of computer fraud, conspiracy, and extortion targeting more than 165 major organizations utilizing the cloud data platform Snowflake, as well as the catastrophic theft of call and text history records belonging to more than 100 million AT&T customers.

The U.S. Department of Justice confirmed that Moucka entered his guilty plea to four criminal counts, which include computer fraud, wire fraud, aggravated identity theft, and conspiracy. As investigators unraveled the global scope of his operations, Moucka’s case exposed glaring vulnerabilities in enterprise cloud security configurations, insider threat vectors, and the dangerous intersection between elite corporate hackers and violent digital extremist subcultures.

The Anatomy of the Snowflake Extortion Campaign

Between February and October 2024, Moucka and an international cadre of co-conspirators executed a devastating campaign targeting companies relying on Snowflake, a prominent U.S.-based software-as-the-service (SaaS) and cloud storage provider. Rather than exploiting a zero-day vulnerability or breaching Snowflake’s core infrastructure directly, the threat actors capitalized on a simpler, yet devastatingly effective, vector: credential stuffing and stolen credentials.

Investigators established that the hackers systematically targeted Snowflake customer accounts that failed to enforce multi-factor authentication (MFA). Armed with these credentials, the conspirators accessed cloud environments, downloaded terabytes of proprietary data, and harvested billions of sensitive customer records. The list of high-profile corporate victims read like a cross-section of global commerce, including household names such as TicketMaster, LendingTree, Advance Auto Parts, and Neiman Marcus.

Once the data was exfiltrated, Moucka and his associates launched aggressive extortion campaigns. They contacted victim organizations, threatening to leak sensitive databases, proprietary source code, and personally identifiable information (PII) on public-facing cybercrime forums unless substantial ransom payments were met. According to federal prosecutors, the extortion scheme netted the conspirators at least $2.5 million in ransom payments. In several instances, Moucka engaged in brazen re-extortion tactics, demanding additional payments from victims even after initial agreements had been struck or threatening individuals using stolen data belonging to government officials and their families.

A Chronology of Detection, Doxing, and Arrest

Canadian Man Pleads Guilty in Snowflake Extortions – Krebs on Security

The unraveling of Moucka’s digital empire began in earnest through investigative journalism and persistent cyber intelligence tracking.

In September 2024, security researcher Brian Krebs published an investigative piece linking a prominent threat actor known by the monikers "Judische" and "Waifu" to the Snowflake data thefts. The reporting also highlighted an unsettling nexus between English-speaking corporate hackers and extremist groups that harass and extort minors into committing self-harm. "Judische" was identified as an Ontario-based software engineer with a multi-year history of orchestrating data breaches and sophisticated voice-phishing (vishing) attacks against U.S. targets dating back to at least 2020.

Recognizing the escalating international threat, U.S. federal authorities coordinated closely with the Royal Canadian Mounted Police (RCMP). On October 21, 2024, Canadian surveillance captured Moucka in Kitchener, Ontario—just nine days before authorities executed a provisional arrest warrant. Following his capture, Moucka was held in Canadian custody before being extradited to face the full weight of the American judicial system.

The Co-Conspirators: A Global Network of Insiders and Elusive Hackers

Moucka did not operate in a vacuum; federal indictments and investigative reporting revealed a closely knit network of sophisticated cybercriminals spanning military ranks and international borders.

Cameron "Kiberphant0m" Wagenius, a U.S. Army soldier stationed in South Korea, emerged as a critical partner in the enterprise. Wagenius utilized various online personas across Telegram and Discord to coordinate attacks and handle extortion operations. In July 2025, Wagenius pleaded guilty to hacking and extortion schemes involving major telecommunications providers, specifically targeting AT&T and Verizon.

The operations involving Wagenius proved particularly volatile. Investigators noted that following Moucka’s arrest in October 2024, Wagenius attempted to exert leverage by posting purported AT&T call logs belonging to high-profile political figures—including then President-elect Donald Trump and then Vice President Kamala Harris—alongside schematics allegedly stolen from the U.S. National Security Agency (NSA) on hacker forums. Wagenius is currently scheduled to be sentenced on September 3, 2026, facing up to 20 years for wire fraud conspiracy, five years for extortion, and a mandatory consecutive two-year term for aggravated identity theft.

A third key co-conspirator, 26-year-old American citizen John Erin Binns—known online as "IRDev" and "IntelSecrets"—remains an elusive figure. Binns was previously indicted for his role in the catastrophic 2021 T-Mobile data breach, which exposed the records of at least 76 million customers. Sources close to the investigation indicate that Binns fled the United States, spent time incarcerated in a Turkish prison, and has since been released after reportedly acquiring Turkish citizenship. Under Turkish constitutional law, citizens cannot be extradited to foreign jurisdictions, complicating efforts to bring him to a U.S. courtroom.

Canadian Man Pleads Guilty in Snowflake Extortions – Krebs on Security

Broader Industry Implications and the Mandate for Zero Trust

The fallout from the Snowflake and AT&T breaches has prompted a profound reassessment of cloud security postures across the global technology sector. Snowflake itself responded aggressively to the crisis, implementing stringent security enhancements that included mandatory password complexity requirements and the strict enforcement of multi-factor authentication across all customer accounts. Cybersecurity experts noted that the incidents served as an expensive, painful wake-up call for enterprises assuming that cloud infrastructure providers inherently manage application-level access hygiene.

Furthermore, the involvement of an active-duty U.S. military personnel and individuals operating from safe-haven foreign nations underscores the complex geopolitical and insider-threat challenges facing modern national security and corporate defense apparatuses. The ease with which stolen credentials could be leveraged to siphon monumental volumes of sensitive data—ranging from Social Security numbers and DEA registration numbers to driver’s licenses and financial records—has accelerated regulatory scrutiny on data retention policies and corporate transparency mandates.

Judicial Outlook and Sentencing Roadmap

As the legal proceedings draw toward their conclusion, Connor Riley Moucka faces severe penalties for his extensive digital rap sheet. While the mandatory minimum sentence for aggravated identity theft guarantees an additional two consecutive years behind bars, the remaining counts of computer fraud, wire fraud, and conspiracy carry a maximum potential prison sentence of 30 years.

Moucka’s sentencing hearing is officially slated for October 27, where a federal judge will determine the final length of incarceration. The outcome will serve not only as a punitive measure against one of 2024’s most disruptive threat actors, but also as a definitive statement by federal prosecutors regarding the uncompromising prosecution of international cloud extortionists and data brokers.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button