September 29, 2026

Mastermind of the Snowflake Cloud Breaches: Connor Riley Moucka Pleads Guilty to Massive Cyber Extortion Ring

mastermind-of-the-snowflake-cloud-breaches-connor-riley-moucka-pleads-guilty-to-massive-cyber-extortion-ring

mastermind-of-the-snowflake-cloud-breaches-connor-riley-moucka-pleads-guilty-to-massive-cyber-extortion-ring

WASHINGTON — Connor Riley Moucka, a 26-year-old Canadian national once earmarked by threat intelligence analysts as one of the most destructive and consequential cybercrime actors of 2024, has formally pleaded guilty to a slate of federal charges. Moucka, a resident of Kitchener, Ontario, entered his guilty plea to computer fraud, wire fraud, conspiracy, and aggravated identity theft. His admissions bring a legal reckoning to a sophisticated cybercriminal campaign that compromised more than 165 major organizations utilizing the cloud analytics platform Snowflake, while simultaneously bleeding sensitive data from over 100 million AT&T customers.

The fallout from Moucka’s actions stretches far beyond standard corporate data theft. Operating under brazen digital aliases such as "Judische" and "Waifu," Moucka and an interconnected network of co-conspirators systematically plundered terabytes of proprietary and personally identifiable information (PII). They then weaponized this data through high-stakes extortion campaigns that netted millions of dollars in ransoms, targeted high-ranking government officials, and exposed critical vulnerabilities in modern cloud infrastructure defenses.


Main Facts: The Scope of the Snowflake and AT&T Compromises

The core of the federal case against Moucka centers on an aggressive, eight-month campaign waged between February and October 2024. According to documents unsealed by the U.S. Department of Justice (DOJ), Moucka and his co-conspirators exploited poor digital hygiene practices within corporate cloud environments.

By leveraging stolen corporate login credentials—many of which belonged to customer accounts that failed to enforce multi-factor authentication (MFA)—the hacking collective breached at least 165 high-profile organizations hosted on the U.S.-based Software-as-a-Service (SaaS) provider Snowflake. The victim pool read like a roster of global commerce, including household names such as Ticketmaster, LendingTree, Advance Auto Parts, and Neiman Marcus.

The haul from these intrusions was staggering. The threat actors downloaded terabytes of corporate data and billions of sensitive customer records. The compromised information encompassed a vast spectrum of private data:

  • Non-content call and text history records for over 100 million AT&T customers;
  • Comprehensive banking and financial records;
  • Corporate payroll databases;
  • Drug Enforcement Administration (DEA) registration numbers;
  • Driver’s license, passport, and Social Security numbers.

Armed with this treasure trove of data, the conspirators employed predatory tactics, directly extorting corporate executives and threatening to dump millions of records onto public cybercrime forums unless substantial cryptocurrency ransoms were paid. According to the DOJ, the collective successfully extorted more than $2.5 million from their corporate victims.


Chronology: From Underground Forums to International Arrests

The anatomy of the Moucka investigation reads like a modern cyber-thriller, tracing a path from clandestine Telegram channels to investigative journalism and, ultimately, cross-border law enforcement intervention.

2020–2023: The Formative Years

Long before the Snowflake breaches made global headlines, Moucka—operating primarily under the alias "Judische"—was honing his tradecraft. Investigators and independent security researchers, notably Brian Krebs of KrebsOnSecurity, tracked Judische’s evolution from an Ontario-based software engineer into a persistent threat actor. Since at least 2020, Judische was linked to numerous corporate data breaches and aggressive voice-phishing (vishing) attacks targeting U.S. enterprises.

September 2024: The Nexus Exposed

The net began to tighten in September 2024, when KrebsOnSecurity published a watershed investigative report detailing the dark nexus between Western, English-speaking cybercriminals and extremist groups that harass and extort minors. The report publicly unmasked "Judische" as a primary orchestrator behind the unfolding Snowflake data thefts, tying his digital footprint directly to the real-world identity of Connor Riley Moucka.

Canadian Man Pleads Guilty in Snowflake Extortions – Krebs on Security

October 2024: The Dragnet Closes

Recognizing the escalating international threat, the Royal Canadian Mounted Police (RCMP), acting on a provisional arrest warrant issued by the United States, arrested Moucka in Ontario on October 30, 2024. Surveillance photographs later filed in court affidavits captured Moucka just nine days prior to his apprehension, seemingly unaware that global law enforcement agencies had closed in on his operations.

July 2025 – Present: Co-Conspirator Pleas and Pending Sentences

As Moucka’s legal proceedings advanced, federal prosecutors dismantled the remainder of his cell. In July 2025, co-conspirator Cameron "Kiberphant0m" Wagenius pleaded guilty to parallel hacking and extortion charges. Moucka’s guilty plea marks the latest milestone in a sprawling prosecution, with his sentencing scheduled for October 27, where he faces a maximum potential penalty of 30 years in prison, alongside a mandatory minimum consecutive sentence of two years for aggravated identity theft.


Supporting Data: The Co-Conspirators and Global Network

Moucka did not operate in a vacuum. Federal indictments and investigative reporting reveal a tight-knit, highly destructive ecosystem of co-conspirators who utilized encrypted messaging applications like Telegram and Discord to coordinate attacks, launder ransom payments, and torment their victims.

Cameron "Kiberphant0m" Wagenius

One of Moucka’s most active partners was Cameron Wagenius, a U.S. Army soldier stationed in South Korea who operated under the handle "Kiberphant0m." Wagenius pleaded guilty in July 2025 to participating in the extortion scheme targeting telecommunications giants AT&T and Verizon.

Wagenius’s digital bravado ultimately contributed to his downfall. Investigators mapped his online personas across multiple forums, unmasking his military status through digital breadcrumbs and selfies posted to social media. Following Moucka’s arrest in October 2024, a panicked or defiant Wagenius escalated his activities by posting what he claimed were AT&T call logs belonging to then President-elect Donald Trump and then Vice President Kamala Harris, alongside stolen National Security Agency (NSA) schematics, onto public hacker forums. Wagenius is currently awaiting sentencing, scheduled for September 3, 2026, and faces up to 20 years for wire fraud, five years for computer fraud extortion, and mandatory time for identity theft.

John Erin Binns ("IRDev" / "IntelSecrets")

The third principal figure in the broader orbit of these high-profile breaches is John Erin Binns, a 26-year-old American fugitive. Indicted for his admitted role in the massive 2021 T-Mobile data breach—which exposed the personal details of at least 76 million customers—Binns fled the United States to evade prosecution.

According to sources close to the federal investigation, Binns recently spent time incarcerated in a Turkish prison before being released. During his evasion, Binns reportedly acquired Turkish citizenship under the handle "IRDev" or "IntelSecrets." Under Turkish constitutional and legal frameworks, citizens cannot be extradited to foreign jurisdictions, complicating efforts by U.S. authorities to bring him to American soil to face trial.


Official Responses and Corporate Accountability

The sheer magnitude of the Snowflake and AT&T breaches prompted intense scrutiny from federal regulators, lawmakers, and cybersecurity watchdogs, forcing sweeping operational overhauls across the technology and telecommunications sectors.

In an official statement following Moucka’s guilty plea, the U.S. Department of Justice underscored the malicious and vindictive nature of the defendants’ tactics. Prosecutors highlighted that Moucka and his associates did not merely steal and ransom corporate data; they weaponized personal information to retaliate against those who stood in their way.

Canadian Man Pleads Guilty in Snowflake Extortions – Krebs on Security

The DOJ revealed that in a particularly egregious display of malicious compliance and intimidation, Moucka attempted to re-extort a corporate victim by using the stolen personal data of a government official and members of that official’s immediate family. "Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt," the DOJ stated, emphasizing the calculated and harassing nature of the criminal enterprise.

Snowflake, the epicenter of the cloud intrusions, faced immediate reputational and operational fallout. Security analysts pointed out that the breaches were largely enabled by the failure of corporate clients to enforce multi-factor authentication on legacy or forgotten service accounts. In response, Snowflake overhauled its security architecture, permanently raising password complexity requirements and making multi-factor authentication a mandatory, non-negotiable default for all customer accounts.

AT&T, similarly battered by the exposure of hundreds of millions of customer call and text logs, invested heavily in third-party forensic audits and infrastructure hardening, while cooperating closely with the FBI and the DOJ throughout the multi-year investigation.


Implications: The Future of Cloud Security and Insider Threats

The guilty plea of Connor Riley Moucka serves as a watershed moment for modern cybersecurity, illuminating several critical vulnerabilities and shifting trends in global threat landscapes.

1. The Perils of Cloud Misconfigurations

As global enterprises accelerate their migration to cloud-native storage and SaaS providers like Snowflake, the traditional perimeter defense model has vanished. The Snowflake breaches demonstrated that sophisticated threat actors no longer need to exploit complex, zero-day software vulnerabilities to compromise a network. Instead, they can simply harvest unmonitored, single-factor-authenticated credentials, walking through the front door with digital impunity.

2. The Fusion of Extortion and Harassment

Moucka and Wagenius’s actions underscore a dark evolution in cybercriminal psychology. Modern threat actors increasingly rely on psychological warfare—harassing corporate executives, doxxing government officials, and threatening vulnerable individuals. The involvement of active-duty military personnel, such as Wagenius, also highlights the persistent threat of radicalized or financially motivated insider actors within critical national infrastructure and defense apparatuses.

3. Geopolitical Safe Havens

The ongoing evasion of John Erin Binns underscores the persistent legal and geopolitical hurdles facing international law enforcement. Cybercriminals who successfully acquire citizenship in non-extradition nations like Turkey can effectively shield themselves from American justice, operating as digital mercenaries with relative impunity as long as they remain within sovereign safe harbors.

As Connor Riley Moucka awaits his October 27 sentencing hearing—where a federal judge will determine the ultimate duration of his confinement—the digital security community is left to reckon with the heavy price of lax authentication protocols. The case stands as a stark warning to corporations worldwide: in the era of cloud computing, security is only as strong as its weakest credential.