Canadian Hacker Behind Massive Snowflake and AT&T Data Extortion Schemes Pleads Guilty in U.S. Federal Court

The landscape of modern enterprise cybersecurity was fundamentally shaken in 2024 by a series of high-profile data breaches that exposed the sensitive personal information of hundreds of millions of individuals globally. At the epicentre of these sweeping digital assaults was a young Canadian software engineer whose online aliases became synonymous with large-scale corporate extortion. Connor Riley Moucka, a 26-year-old resident of Kitchener, Ontario, has formally entered a guilty plea in a U.S. federal court, admitting to computer fraud, wire fraud, conspiracy, and aggravated identity theft. His legal capitulation marks a pivotal milestone in one of the most destructive cybercrime prosecutions of the decade.
Federal prosecutors detailed how Moucka and an international network of co-conspirators leveraged compromised credentials to infiltrate cloud storage provider Snowflake, holding terabytes of sensitive corporate and consumer data hostage. The syndicate’s campaign targeted over 165 major organizations, extracting staggering volumes of personally identifiable information (PII) and generating millions of dollars in illicit ransom payments. Alongside the Snowflake incursions, Moucka admitted to his involvement in the massive theft of call and text history records belonging to more than 100 million customers of telecommunications giant AT&T.
The Mechanics of the Snowflake Infiltrations
The operation orchestrated by Moucka and his associates exploited a persistent vulnerability in corporate cybersecurity hygiene: the absence of enforced multi-factor authentication (MFA). Between February and October 2024, the threat actors utilized pre-existing lists of stolen login credentials to gain unauthorized access to Snowflake customer accounts that lacked robust security controls. Once inside the cloud-hosted environments, the hackers downloaded vast repositories of proprietary and consumer data.
The roster of victimized corporations reads as a ledger of prominent North American enterprises, including Ticketmaster, LendingTree, Advance Auto Parts, and Neiman Marcus. Rather than merely stealing intellectual property or financial assets for underground resale, the cybercriminals weaponized the data directly against the affected companies. They threatened to publish the pilfered records on public forums unless substantial cryptocurrency ransoms were paid.
According to the U.S. Department of Justice, the conspiracy successfully extorted upwards of $2.5 million from targeted entities. However, the perpetrators’ tactics extended far beyond initial extortion demands. In several documented instances, Moucka engaged in secondary extortion, re-targeting victims with threats of further data leaks after initial ransoms had already been paid. In a particularly brazen display of malice, Moucka utilized the stolen personal data of a government official and members of that official’s family to exert pressure during a secondary shakedown.

Chronology of an International Cyber Hunt
The unravelling of Moucka’s criminal enterprise unfolded through a high-stakes convergence of investigative journalism, digital forensics, and international law enforcement cooperation.
- 2020–2023: Moucka, operating under various online personas—most notably "Judische" and "Waifu"—engaged in a multi-year campaign of data breaches, software engineering, and voice phishing attacks directed primarily at U.S.-based companies.
- February 2024: The core Snowflake intrusion campaign commences, with threat actors systematically accessing corporate cloud accounts via unauthenticated credential sets.
- September 2024: Investigative reporting published by KrebsOnSecurity identifies the user "Judische" as an Ontario-based software engineer connected to a broader nexus of cybercriminals and extremist groups known for harassing and extorting minors.
- October 21, 2024: Royal Canadian Mounted Police (RCMP) surveillance captures imagery of Moucka in Ontario, just days before his apprehension.
- Late October 2024: Canadian authorities arrest Moucka on a provisional extradition warrant issued by the United States. Following his capture, co-conspirators attempt to retaliate by leaking allegedly sensitive data, including telecommunications logs and government schematics.
- July 2025: Co-conspirator Cameron "Kiberphant0m" Wagenius pleads guilty to related hacking and extortion charges involving AT&T and Verizon.
- Present Day: Moucka formally pleads guilty in U.S. federal court, facing a sentencing hearing scheduled for October 27, where he confronts a maximum penalty of 30 years in prison alongside a mandatory minimum two-year consecutive sentence for aggravated identity theft.
The Co-Conspirator Network: Soldiers, Exiles, and Fugitives
Moucka did not operate in a vacuum; federal indictments have illuminated a tightly knit, highly specialized cadre of digital mercenaries whose operations spanned multiple continents and institutional domains.
Among Moucka’s primary admitted co-conspirators is Cameron Wagenius, operating under the moniker "Kiberphant0m." Wagenius, a U.S. Army soldier stationed in South Korea during portions of his illicit activities, pleaded guilty in July 2025 to extortion schemes targeting major U.S. telecom providers. Investigative deep-dives into Wagenius’s digital footprint across Telegram and Discord revealed a soldier who blended military service with high-level cybercrime. In an aggressive attempt to derail investigations following Moucka’s arrest, Wagenius published files on underground forums claiming to contain the call logs of high-ranking political figures, alongside documents purportedly stolen from the U.S. National Security Agency (NSA). Wagenius is scheduled to be sentenced on September 3, 2026, facing up to 20 years for wire fraud, five years for computer fraud extortion, and mandatory time for identity theft.
A third key figure linked to the broader infrastructure of these breaches is John Erin Binns, a 26-year-old American fugitive. Indicted for his role in a massive 2021 T-Mobile data breach that exposed the records of at least 76 million customers, Binns—known online as "IRDev" and "IntelSecrets"—managed to evade U.S. custody. Intelligence sources indicate that Binns was previously detained in a Turkish prison before securing his release and acquiring Turkish citizenship. Under domestic Turkish legal protections, citizens cannot be extradited to foreign jurisdictions, rendering Binns largely insulated from direct U.S. prosecution barring a significant geopolitical shift.
Corporate and Institutional Fallout

The cascading impacts of the Snowflake and AT&T breaches prompted a profound reassessment of cloud security paradigms and enterprise risk management. Snowflake, while maintaining that its core database architecture was not directly compromised due to a systemic vulnerability, faced intense scrutiny over customer-level security configurations. In response to the breaches, the cloud provider instituted mandatory baseline security enhancements, including stricter password complexity requirements and the universal enforcement of multi-factor authentication across all customer accounts.
For the telecommunications sector, the theft of hundreds of millions of call and text logs laid bare the systemic risks associated with centralized data repositories maintained by third-party cloud vendors. The exposure of non-content metadata—while lacking audio or message text—still presented severe national security and privacy concerns, enabling sophisticated pattern analysis and surveillance capabilities for malicious actors.
Law enforcement agencies have lauded the successful prosecution of Moucka as a testament to the efficacy of cross-border intelligence sharing. The U.S. Justice Department, alongside the RCMP and cybersecurity researchers, pieced together fragmented digital personas to dismantle a network that treated corporate networks as open-air markets for extortion.
Implications for the Future of Enterprise Defense
The legal reckoning facing Connor Riley Moucka serves as both a deterrent and a stark reminder of the vulnerabilities inherent in modern digital infrastructure. As cloud adoption accelerates across every vertical of the global economy, the attack surface for sophisticated threat actors expands exponentially.
Security analysts emphasize that the Snowflake and AT&T incidents underscore the non-negotiable necessity of zero-trust architecture, rigorous identity and access management (IAM), and the elimination of legacy authentication methods. Threat actors like Moucka and Wagenius capitalized not on zero-day exploits or insurmountable technical barriers, but on the simple human and administrative oversight of left-open doors.
As Moucka awaits his sentencing hearing on October 27, the judicial proceedings send an unmistakable message to the underground cybercrime ecosystem: while digital anonymity and geographic dispersal can delay justice, the convergence of relentless investigative journalism and coordinated international law enforcement increasingly closes the net around even the most prolific threat actors.







