Canadian Cybercrime Threat Actor Connor Riley Moucka Pleads Guilty to Massive Snowflake Extortion and Data Theft Scheme

Connor Riley Moucka, a 26-year-old software engineer from Kitchener, Ontario, has formally pleaded guilty to a series of federal charges stemming from his role as a central figure in one of the most significant cybercrime campaigns of 2024. Once known in dark-web circles by the monikers "Judische" and "Waifu," Moucka admitted to orchestrating a sophisticated campaign of computer fraud, conspiracy, and extortion that targeted over 165 organizations utilizing the cloud services provider Snowflake. His admission marks a pivotal conclusion to a high-stakes investigation into the theft of sensitive data belonging to millions of individuals, including the call and text records of more than 100 million AT&T customers.
The U.S. Department of Justice confirmed that Moucka, alongside a network of co-conspirators, exploited lax security protocols—specifically accounts failing to implement multi-factor authentication (MFA)—to infiltrate enterprise environments. The breach campaign, which spanned from February to October 2024, resulted in the exfiltration of terabytes of proprietary data, setting off a cascading series of extortion attempts that impacted major corporations, including Ticketmaster, LendingTree, Advance Auto Parts, and Neiman Marcus.
A Chronology of the Breach and Subsequent Arrest
The trajectory of the investigation reveals a rapid escalation from digital reconnaissance to global enforcement action.
- 2020–2023: Early indicators of Moucka’s activity begin to surface, with investigations linking his "Judische" persona to various data breaches and voice-phishing operations targeting U.S. entities.
- February 2024: Moucka and his associates commence the systematic exploitation of Snowflake customer accounts, utilizing stolen credentials to gain unauthorized access to cloud-hosted databases.
- September 2024: Cybersecurity outlet KrebsOnSecurity publishes a comprehensive report identifying the intersection between English-speaking cybercriminals and extremist groups, explicitly naming Moucka as a primary actor in the Snowflake-related thefts.
- October 2024: Following a surge in extortion demands and the publication of stolen data, the Royal Canadian Mounted Police (RCMP) arrest Moucka in Ontario on a provisional warrant issued by the United States.
- July 2025: Co-conspirator Cameron "Kiberphant0m" Wagenius pleads guilty to his role in the extortion of major telecommunications providers.
- Present Day: Moucka enters his guilty plea in U.S. federal court, with sentencing scheduled for October 27, 2025.
The Network of Conspirators
The operation was not the work of a lone actor but rather a collaborative effort involving individuals who utilized encrypted communication platforms like Telegram and Discord to coordinate their strikes.

Cameron Wagenius, a U.S. Army soldier, emerged as a critical partner in the scheme. Investigations into Wagenius’s digital footprint revealed that he was operating from his duty station in South Korea, where he maintained his "Kiberphant0m" identity. His involvement extended beyond corporate extortion; following the arrest of Moucka, Wagenius reportedly attempted to leverage his remaining access to leak sensitive data, including claims regarding the call logs of high-profile political figures and schematics purportedly stolen from the National Security Agency (NSA). Wagenius faces a multi-decade prison sentence, with a hearing set for September 2026.
The third individual named in the government’s investigation, John Erin Binns, represents a persistent challenge for international law enforcement. An American national previously indicted for a 2021 breach of T-Mobile that exposed the records of 76 million users, Binns has successfully evaded capture through a series of international maneuvers. Reports suggest that after a period of incarceration in Turkey, Binns secured Turkish citizenship, effectively insulating himself from extradition efforts under current Turkish legal statutes.
Scope of the Data Theft and Financial Impact
The sheer volume of information compromised in this campaign is staggering. The conspirators allegedly siphoned billions of records, encompassing a wide spectrum of personally identifiable information (PII). Among the stolen data were Drug Enforcement Administration (DEA) registration numbers, passport information, Social Security numbers, driver’s license details, and comprehensive banking and payroll records.
Financially, the group successfully extorted more than $2.5 million in ransom payments. However, the true cost of the operation is measured not just in direct ransoms, but in the operational disruption caused to 165 major organizations. In a particularly aggressive move, the conspirators engaged in "re-extortion"—a tactic where victims, having already paid a ransom, were threatened with further data exposure unless additional payments were made. In one documented instance, Moucka targeted a government official by leveraging the stolen data of the official’s own immediate family members.
Institutional Responses and Security Shifts
The fallout from the Snowflake breach forced a widespread reassessment of cloud security standards. Snowflake, while noting that its own internal systems were not compromised, responded to the incident by mandating stricter password complexity requirements and enforcing universal multi-factor authentication for its clients.

The incident serves as a case study for the "shared responsibility model" in cloud computing. While cloud providers maintain the infrastructure, customers remain responsible for the configuration of access controls. The fact that the breach was predicated on the absence of MFA highlights the persistent vulnerability of enterprise credentials in the modern threat landscape.
Broader Implications for Cybersecurity
The case of Connor Riley Moucka underscores the evolving nature of the "Dark Nexus"—the blurred line between traditional financially motivated cybercrime and the ideologically driven harassment carried out by extremist groups. The DOJ’s intervention highlights a maturing international response to cross-border cybercrime, where intelligence-sharing between agencies like the RCMP and U.S. federal authorities is increasingly effective.
Furthermore, the involvement of a U.S. service member like Wagenius raises significant questions regarding the vetting and digital hygiene of personnel with access to secure networks. The ability of actors like Binns to weaponize citizenship to avoid justice also points to a growing "safe harbor" problem in international law, where cybercriminals can effectively render themselves untouchable by relocating to jurisdictions with restrictive extradition treaties.
As Moucka awaits his sentencing, the legal proceedings stand as a stern warning to the broader hacking community. With a mandatory minimum of two years for aggravated identity theft and a potential maximum of 30 years for the remaining charges, the severity of the sentence will likely serve as a benchmark for future prosecutions of large-scale, enterprise-level extortion schemes.
For corporations, the message is equally clear: the era of perimeter-based security is over. In a landscape where threat actors are highly mobile, technically proficient, and willing to target the families of government officials, the implementation of robust identity and access management (IAM) is no longer a luxury but a fundamental necessity for business continuity and legal compliance. As the digital ecosystem continues to consolidate data into cloud environments, the success of this investigation proves that while the reach of cybercriminals is vast, the reach of international law enforcement—though often slow—is becoming increasingly capable of dismantling even the most complex digital criminal enterprises.





