Canadian Cybercriminal Connor Riley Moucka Pleads Guilty to Massive Snowflake Data Extortion Scheme

Connor Riley Moucka, a 26-year-old software engineer from Kitchener, Ontario, has formally pleaded guilty to a sweeping array of federal charges related to a sophisticated cyber-extortion campaign that compromised over 165 major organizations. The plea, entered in a U.S. federal court, marks a decisive conclusion to one of the most significant cybercrime investigations of 2024, shedding light on a criminal enterprise that targeted the infrastructure of the cloud provider Snowflake and resulted in the theft of sensitive data belonging to more than 100 million AT&T customers.
The scope of the operation, which spanned from February to October 2024, involved the systematic exploitation of unprotected cloud credentials. Moucka, who operated under various pseudonyms including "Judische" and "Waifu," leveraged stolen login information to access the private data of companies that had failed to implement multi-factor authentication (MFA). Among the victims were high-profile entities such as Ticketmaster, LendingTree, Advance Auto Parts, and Neiman Marcus, all of which faced severe extortion threats as the attackers held their proprietary data hostage.
A Chronology of the Breach and Subsequent Arrest
The investigation into Moucka’s activities began in earnest following a series of digital breadcrumbs that linked the "Judische" moniker to a broader network of English-speaking threat actors. Investigative reporting by outlets such as KrebsOnSecurity identified a troubling nexus between these hackers and extremist groups known for harassing minors.
- 2020–2023: Moucka begins engaging in data breaches and voice-phishing campaigns against U.S. corporate entities.
- February 2024: The campaign against Snowflake-hosted accounts accelerates, with Moucka and his co-conspirators systematically harvesting cloud-hosted data.
- September 2024: Public exposure of the "Judische" persona occurs, detailing the overlap between his criminal activities and extremist harassment groups.
- October 2024: Canadian law enforcement authorities, acting on a provisional warrant issued by the United States, apprehend Moucka in Ontario.
- July 2025: Cameron "Kiberphant0m" Wagenius, a U.S. Army soldier and key co-conspirator, enters a guilty plea regarding his role in extorting major telecommunications providers.
- October 2026: Moucka is scheduled for sentencing, facing a maximum potential penalty of 30 years in federal prison.
The Anatomy of the Extortion Network
The conspiracy was not a solo endeavor but a collaborative effort between individuals who leveraged their specific technical skills to maximize damage. Moucka’s primary partner, Cameron Wagenius, utilized his status as a U.S. Army soldier to gain a level of perceived credibility, often boasting of his position while stationed in South Korea. The duo’s tactics went beyond simple data theft; they engaged in "re-extortion," a predatory practice where victims were contacted repeatedly with threats of further data disclosure even after initial ransom payments were processed.

The U.S. Department of Justice (DOJ) confirmed that the conspirators secured over $2.5 million in ransom payments throughout their tenure. In a brazen display of malice, the attackers utilized the stolen personal data of a government official—and that official’s immediate family members—to coerce victims into compliance.
A third figure, John Erin Binns, known by aliases such as "IRDev" and "IntelSecrets," remains a complex variable in the investigation. Binns, who was previously indicted for his involvement in the 2021 T-Mobile data breach that exposed the information of 76 million customers, has reportedly resurfaced after a stint in a Turkish prison. His acquisition of Turkish citizenship presents a significant legal hurdle, as local laws currently prevent his extradition to face charges in the United States.
Broader Data Impact and Corporate Consequences
The sheer volume of information exfiltrated during this period is staggering. The attackers accessed billions of customer records, including:
- Non-content call and text history logs.
- Banking, payroll, and financial account information.
- Drug Enforcement Administration (DEA) registration numbers.
- Sensitive PII (Personally Identifiable Information) including Social Security numbers, passport details, and driver’s license numbers.
The breach forced Snowflake to pivot its security strategy, transitioning from optional security measures to mandatory multi-factor authentication and heightened password complexity requirements. Industry analysts suggest this incident serves as a bellwether for the "Cloud Misconfiguration Crisis." Many companies operate under the assumption that cloud providers are solely responsible for security, yet this case underscores the "shared responsibility model," where the end-user’s failure to enforce basic authentication protocols creates a massive, exploitable attack surface.
Official Responses and Legal Implications
The Department of Justice’s prosecution of Moucka is being viewed as a landmark case in international cyber-law enforcement. Assistant Attorney General and other federal officials have emphasized that the pursuit of these actors will continue regardless of international borders or the complexity of the digital personas utilized.

For Cameron Wagenius, the legal consequences are severe. With a sentencing date set for September 3, 2026, he faces up to 20 years for wire fraud conspiracy and an additional mandatory two-year consecutive sentence for aggravated identity theft. His actions—which included leaking alleged National Security Agency (NSA) schematics and private communication logs of high-profile political figures—have elevated the case from simple financial crime to a matter of national security concern.
Implications for Future Cybersecurity
The case of Connor Riley Moucka highlights several critical vulnerabilities in the modern digital economy:
- The MFA Gap: Despite the ubiquity of multi-factor authentication, the Snowflake breach proves that even the most sophisticated enterprise environments remain vulnerable if basic "hygiene" is neglected.
- The Rise of Re-Extortion: The trend of threat actors continuing to demand payments after a ransom has been paid is becoming a standard feature of modern ransomware-as-a-service (RaaS) models, forcing organizations to rethink the efficacy of paying ransoms.
- Cross-Border Jurisdictional Challenges: The case of John Erin Binns illustrates the difficulty of prosecuting cybercriminals who leverage dual citizenship and safe-haven countries to avoid extradition.
- The Insider Threat Paradigm: The involvement of active-duty military personnel, such as Wagenius, suggests that traditional vetting and operational security protocols may need to be expanded to account for the digital life and extremist ties of personnel.
As the tech sector awaits the final sentencing of Moucka in late October, the case serves as a stark reminder of the fragile state of digital privacy. The collaboration between international law enforcement agencies, led by the RCMP and the U.S. DOJ, provides a roadmap for future investigations, yet the persistence of actors like Binns suggests that the war against organized cybercrime is far from over. The global digital infrastructure remains under constant, evolving pressure from individuals who can, from a simple home computer, bring the operations of Fortune 500 companies to a grinding, multi-million dollar halt.







