CyberSecurity

Canadian Hacker Pleads Guilty in Massive Snowflake Data Extortion Scheme

Published

on

The Guilty Plea That Shook the Cloud Security World

In a case that has sent ripples through the cybersecurity community, a 26-year-old Canadian man has admitted to orchestrating one of the most significant cloud data thefts of 2024. Connor Riley Moucka, from Kitchener, Ontario, pleaded guilty to computer fraud and conspiracy charges linked to hacking and extorting over 165 organizations that relied on Snowflake.

The plea, entered in a U.S. federal court, also covers the theft of call and text history records belonging to more than 100 million AT&T customers. It’s a staggering scale of intrusion that experts say underscores the persistent vulnerability of cloud-based systems.

How the Snowflake Attacks Unfolded

Between February and October 2024, Moucka and his co-conspirators used stolen login credentials to breach the cloud-hosted data of at least 165 customers of a U.S.-based software-as-a-service company. The U.S. Justice Department detailed how the hackers specifically targeted Snowflake customer accounts that had failed to enable multi-factor authentication.

The list of victimized companies reads like a who’s who of American business: TicketMaster, Lending Tree, Advance Auto Parts, and Neiman Marcus all fell prey to the scheme. In response, Snowflake tightened its security protocols, mandating stronger password requirements and enforcing multi-factor authentication across its platform.

The Extortion Tactics

The stolen data was vast and deeply personal. According to the Justice Department, the hackers obtained “billions of sensitive customer records” and downloaded terabytes of information, including financial details, payroll records, DEA registration numbers, driver’s license numbers, passport numbers, and social security numbers. The group then threatened to publish this data online unless victims paid up.

It wasn’t just about the money. The conspirators made over $2.5 million in ransom payments, but Moucka went further, re-extorting at least one victim with threats of further disclosure. In a particularly brazen move, he used the stolen data of a government officer and that officer’s family members in this second round of threats.

Who Is Connor Riley Moucka?

Moucka operated under multiple online aliases, most notably “Judische” and “Waifu.” He was first identified in a September 2024 report by KrebsOnSecurity, which linked the Judische moniker to a software engineer from Ontario involved in data breaches and voice phishing attacks since at least 2020.

Just over a month after that report, Canadian authorities arrested Moucka on a provisional warrant from the United States. The investigation revealed that Moucka didn’t just target corporations—he also threatened and harassed government officials and security researchers who were helping track him down.

The Co-Conspirators and Their Fates

Moucka wasn’t working alone. His admitted co-conspirator, Cameron “Kiberphant0m” Wagenius, a U.S. Army soldier, pleaded guilty in July 2025 to extorting AT&T and Verizon for customer account data. Wagenius faces up to 20 years in prison for wire fraud conspiracy, plus additional sentences for extortion and aggravated identity theft.

The third alleged co-conspirator, John Erin Binns, remains at large. Binns, known online as “IRDev” and “IntelSecrets,” fled the U.S. after being indicted for a 2021 T-Mobile data breach that exposed the personal information of at least 76 million customers. Recent reports suggest Binns has obtained Turkish citizenship, which under Turkish law makes extradition to foreign countries nearly impossible.

Sentencing and Implications

Moucka pleaded guilty to four criminal counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. He’s scheduled for sentencing on Oct. 27 and faces a mandatory minimum of two years on the identity theft charge, with a maximum of 30 years on the other counts. The final sentence will be determined by the federal judge.

This case serves as a stark reminder of the importance of basic security hygiene. The Snowflake attacks exploited a simple vulnerability—accounts without multi-factor authentication. For businesses, the lesson is clear: complacency in cybersecurity can have catastrophic consequences.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version