September 29, 2026

The Fall of ‘Judische’: How a 26-Year-Old Canadian Masterminded the Snowflake Cloud Heists and AT&T Data Breaches

the-fall-of-judische-how-a-26-year-old-canadian-masterminded-the-snowflake-cloud-heists-and-att-data-breaches

the-fall-of-judische-how-a-26-year-old-canadian-masterminded-the-snowflake-cloud-heists-and-att-data-breaches

WASHINGTON — In the sprawling annals of modern cybercrime, few threat actors achieved such a disruptive and devastating footprint in as short a time as Connor Riley Moucka. Operating under a rotating cast of digital pseudonyms—most notably "Judische" and "Waifu"—the 26-year-old software engineer from Kitchener, Ontario, stood at the epicenter of one of the most consequential waves of corporate extortion and cloud data theft in recent history.

Moucka has officially pleaded guilty in a U.S. federal court to computer fraud, wire fraud, aggravated identity theft, and conspiracy charges. His admissions unspool a staggering campaign that targeted over 165 major organizations, pilfered terabytes of sensitive data, exposed the call and text logs of more than 100 million AT&T customers, and yielded millions of dollars in cryptocurrency ransom payments.

As judicial proceedings draw to a close for Moucka and his co-conspirators, the fallout from the Snowflake and telecommunications breaches continues to reverberate across the global cybersecurity landscape, exposing critical vulnerabilities in cloud posture, supply chain hygiene, and multi-factor authentication enforcement.


Main Facts of the Case

The scope of Moucka’s criminal enterprise, executed between February and October 2024, reads like a cinematic thriller, yet it relied on foundational cybersecurity oversights. According to the U.S. Department of Justice (DOJ), Moucka and his network systematically targeted organizations utilizing cloud storage provider Snowflake.

By exploiting stolen credentials associated with Snowflake customer accounts that failed to enforce robust multi-factor authentication (MFA), the threat actors gained unauthorized access to internal databases. Once inside, they downloaded terabytes of proprietary, financial, and personal data. High-profile corporate victims caught in the crosshairs included household names such as Ticketmaster, LendingTree, Advance Auto Parts, and Neiman Marcus.

Beyond corporate espionage and extortion, Moucka’s syndicate expanded its reach into major telecommunications infrastructure. The group exfiltrated the call and text history records of more than 100 million AT&T customers. The stolen data trove included a cornucopia of Personally Identifiable Information (PII):

Canadian Man Pleads Guilty in Snowflake Extortions – Krebs on Security
  • Social Security numbers and passport details
  • Driver’s license numbers and banking credentials
  • Payroll files and corporate internal documents
  • Drug Enforcement Administration (DEA) registration numbers

In total, the conspirators amassed at least $2.5 million in extortion payments by threatening to leak or publicly auction the stolen assets on underground cybercrime forums. However, the financial extortion was compounded by severe psychological harassment. Federal prosecutors revealed that Moucka and his associates actively targeted government officials, security researchers, and even family members of investigators who were working to unmask them, deploying malicious "re-extortion" tactics using leaked sensitive files.


Chronology of the Cyber Onslaught

The unraveling of the "Judische" network followed a meticulous investigative trail tracked by independent security journalists, international law enforcement, and federal prosecutors over several years.

  • Pre-2020 to 2023: The foundational elements of the conspiracy began taking shape years prior. Co-conspirator John Erin Binns orchestrated a massive 2021 breach at T-Mobile that exposed the records of 76 million customers, eventually fleeing U.S. jurisdiction to evade indictment. Meanwhile, Moucka operated quietly as a software engineer in Ontario, dabbling in voice phishing and localized data breaches since at least 2020.
  • February – October 2024: Moucka and his co-conspirators executed the aggressive Snowflake cloud intrusion campaign. They continuously breached corporate databases, downloaded massive datasets, and launched successive waves of corporate blackmail.
  • September 2024: Investigative reporting by KrebsOnSecurity publicly linked the moniker "Judische" to an Ontario-based software engineer, identifying deep overlapping ties between Western English-speaking cybercriminals and malicious groups that harass and extort minors.
  • Late October 2024: Canadian authorities arrested Connor Riley Moucka in Ontario pursuant to a provisional extradition warrant issued by the United States. Surveillance photos captured him days before local law enforcement closed in. Following his arrest, co-conspirator Cameron Wagenius attempted to spark chaotic re-extortion efforts, posting purported AT&T call logs of high-profile political figures on underground forums.
  • July 2025: Cameron "Kiberphant0m" Wagenius—a U.S. Army soldier stationed in South Korea—pleaded guilty to his role in the AT&T and Verizon extortion schemes.
  • Current Status: Moucka entered his formal guilty plea to four federal counts. He faces sentencing on October 27, where he confronts a mandatory minimum of two years for aggravated identity theft and up to 30 years on the remaining counts. Wagenius is scheduled to be sentenced on September 3, 2026.

Supporting Data and Co-Conspirator Profiles

The federal indictments and subsequent guilty pleas paint a portrait of a tight-knit, highly volatile digital syndicate operating across international borders. The operation relied on three primary actors whose distinct skill sets and operational errors ultimately facilitated their downfall.

1. Connor Riley Moucka ("Judische" / "Waifu")

A 26-year-old Canadian national residing in Kitchener, Ontario. Moucka utilized shifting nicknames to obscure his tracks, though his digital fingerprints frequently overlapped with extremist and extortionist forums. He managed the logistical heart of the Snowflake extortions, coordinating data leaks and spearheading the brazen re-extortion of victims—including using stolen records belonging to government officials and their families.

2. Cameron "Kiberphant0m" Wagenius

A U.S. Army soldier stationed in South Korea. Investigative deep-dives into Telegram and Discord logs exposed Wagenius’s military affiliations and his orchestration of telecommunications hacks against AT&T and Verizon. Wagenius pleaded guilty in July 2025. Facing a potential 20-year sentence for wire fraud, 5 years for computer extortion, and a mandatory consecutive 2 years for identity theft, Wagenius is slated for sentencing in late 2026. Following Moucka’s arrest, Wagenius desperately attempted to deflect attention by leaking purported phone logs of high-ranking political figures, including then-President-elect Donald Trump and then-Vice President Kamala Harris, alongside stolen U.S. National Security Agency (NSA) schematics.

3. John Erin Binns ("IRDev" / "IntelSecrets")

A 26-year-old American hacker indicted for his central role in the 2021 T-Mobile breach. Rather than facing trial in the United States, Binns fled abroad. Intelligence sources indicate that Binns recently secured Turkish citizenship. Because Turkish law generally prohibits the extradition of its own citizens to foreign nations, Binns has effectively insulated himself from immediate U.S. prosecution, even as he has resurfaced across various online platforms.

Canadian Man Pleads Guilty in Snowflake Extortions – Krebs on Security

Official Responses and Industry Impact

The fallout from the Snowflake cloud breaches served as a painful wake-up call for the software-as-a-service (SaaS) and cloud security sectors. Security analysts noted that the attacks did not stem from a vulnerability or zero-day exploit within Snowflake’s core architecture. Instead, the breaches exploited compromised credentials belonging to third-party corporate clients who had neglected to enforce multi-factor authentication.

In the wake of the attacks, Snowflake instituted sweeping security updates. The company drastically raised password complexity requirements and mandated the implementation of multi-factor authentication across all customer accounts to eliminate the precise vector leveraged by Moucka and his accomplices.

U.S. law enforcement officials lauded the cross-border cooperation between the Department of Justice, the FBI, the Royal Canadian Mounted Police (RCMP), and international partners.

"Connor Riley Moucka thought he could hide behind shifting digital monikers, encrypted chat platforms, and international borders while terrorizing hundreds of American companies and millions of citizens," said a senior Justice Department official following the guilty plea. "Today’s plea demonstrates that the long arm of international law enforcement, paired with diligent private-sector intelligence, will systematically dismantle these cybercriminal ecosystems, no matter how sophisticated their extortion tactics may be."


Broader Implications for Cybersecurity

The prosecution of the "Judische" network highlights several troubling trends and critical lessons for the future of digital defense:

  1. The Insider and Military Threat Nexus: The involvement of active-duty U.S. soldier Cameron Wagenius underscores a growing risk of radicalized or financially motivated military personnel leveraging specialized operational security knowledge to aid transnational cyber syndicates.
  2. The Weaponization of Re-Extortion: Moucka and Wagenius’s willingness to re-extort victims—and target government investigators and their families—marks an escalating psychological brutality in modern ransomware and extortion campaigns. Threat actors are no longer content with a single payout; they weaponize compliance and personal fear to extract recurring dividends.
  3. The Limits of International Extradition: The sanctuary found by John Erin Binns in Turkey highlights the ongoing geopolitical hurdles in international cybercrime enforcement. When hackers acquire citizenship in non-extradition nations, traditional judicial avenues stall, emphasizing the need for robust domestic containment and preemptive identification.
  4. The Non-Negotiable Necessity of MFA: Perhaps the most fundamental takeaway for enterprise security leaders is that basic hygiene—specifically mandatory multi-factor authentication and proactive credential rotation—remains the single most effective barrier against multi-million-dollar breaches. Organizations can no longer treat MFA as an optional administrative preference; as the Snowflake incident proved, a single unprotected account can compromise an entire enterprise supply chain.

As Connor Riley Moucka awaits his October sentencing hearing, the digital underworld watches closely. For a threat actor who once fancied himself untouchable behind the pseudonyms "Judische" and "Waifu," the reality of federal penitentiaries stands as a stark testament to the closing window for cyber impunity.