Inside the Snowflake Siege: The Fall of Connor Moucka and the $2.5 Million Cyber Extortion Syndicate

Executive Overview

In one of the most significant legal developments in modern cloud-focused cybercrime, 26-year-old Canadian national Connor Riley Moucka has pleaded guilty in a United States federal court to multiple criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy. Operating under online monikers such as "Judische" and "Waifu," Moucka admitted to orchestrating a devastating, months-long hacking and extortion campaign that compromised more than 165 enterprise organizations utilizing the cloud-hosted data platform Snowflake.

Between February and October 2024, Moucka and a tight-knit network of co-conspirators systematically exploited cloud storage environments to siphon terabytes of ultra-sensitive corporate and personal data. Among the most egregious breaches was the exfiltration of non-content call and text detail records belonging to more than 100 million AT&T customers. The syndicate extracted over $2.5 million in illicit ransom payments by threatening to leak stolen information—ranging from corporate payroll records and Drug Enforcement Administration (DEA) registration numbers to personal bank data and Social Security numbers.

The judicial resolution of Moucka’s case shines a harsh spotlight on systemic cloud security failures, specifically the persistent lack of mandatory multi-factor authentication (MFA) across enterprise accounts. It also reveals the dangerous convergence of traditional financial cybercrime, military insider threats, and online harassment networks.


Detailed Chronology

+-----------------------------------------------------------------------------------+
|                                 TIMELINE OF EVENTS                                |
+-----------------------------------------------------------------------------------+
| 2020 - 2023     | Precursor Attacks & Emergence of "Judische"                       |
|                 | Voice phishing, social engineering, ties to online harassment.    |
|                 | John Erin Binns breaches T-Mobile (76M records) in 2021.          |
+-----------------+-----------------------------------------------------------------+
| Feb - Oct 2024  | The Cloud Extortion Campaign                                    |
|                 | Credential-stuffing attacks hit 165+ Snowflake customer accounts|
|                 | lacking multi-factor authentication (MFA).                      |
+-----------------+-----------------------------------------------------------------+
| Mid-2024        | Telecom Compromise & Active Extortion                           |
|                 | Exfiltration of 100M+ AT&T customer records.                    |
|                 | Syndicate nets $2.5M+ in ransom payments.                       |
+-----------------+-----------------------------------------------------------------+
| Oct 21-30, 2024 | Law Enforcement Strike                                          |
|                 | RCMP conducts surveillance on Moucka in Ontario.                |
|                 | Oct 30: Moucka arrested on U.S. provisional warrant.            |
+-----------------+-----------------------------------------------------------------+
| Nov 2024        | Retaliation & Forum Leaks                                       |
|                 | Co-conspirator "Kiberphant0m" leaks AT&T records of political   |
|                 | figures and alleged NSA schematics on dark web forums.          |
+-----------------+-----------------------------------------------------------------+
| July 2025       | Wagenius Pleads Guilty                                          |
|                 | Former U.S. soldier Cameron Wagenius admits role in scheme.    |
+-----------------+-----------------------------------------------------------------+
| Present / Future| Judicial Rulings & Sentencing                                   |
|                 | Wagenius sentencing: Sept 3, 2026.                              |
|                 | Moucka sentencing: Oct 27 (Faces up to 30+ years).             |
+-----------------------------------------------------------------------------------+

Phase I: Origins and Early Network Formations (2020–2023)

Long before the Snowflake campaign made international headlines, Connor Riley Moucka was an active operative within English-speaking cybercrime undergrounds. Operating out of Kitchener, Ontario, the software engineer participated in extensive voice phishing (vishing) campaigns and corporate network intrusions dating back to at least 2020. During this period, security researchers identified overlap between Moucka’s online aliases and extreme online harassment networks—often referred to loosely as "The Com"—known for extorting targets, swatting, and dox attacks.

Concurrently, American national John Erin Binns ("IRDev" / "IntelSecrets") gained notoriety in 2021 by breaching T-Mobile’s infrastructure and stealing personal data belonging to 76 million customers. Binns subsequently fled the United States to avoid prosecution, establishing an operational base abroad while remaining deeply embedded in high-tier database theft communities.

Phase II: The Cloud Harvesting Operation (February – October 2024)

In early 2024, Moucka and his network identified a widespread structural weakness: dozens of major corporate entities hosted vast repositories of sensitive customer and operational data on Snowflake cloud storage instances without enforcing multi-factor authentication.

Using stolen credentials gathered from infostealer malware logs available on underground markets, the conspirators initiated an automated campaign to systematically log into unmanaged Snowflake accounts. Over eight months, they targeted and breached at least 165 high-profile organizations, including:

Canadian Man Pleads Guilty in Snowflake Extortions
  • Ticketmaster
  • LendingTree
  • Advance Auto Parts
  • Neiman Marcus
  • Santander Bank

Phase III: The Telecommunications Heist and Re-Extortion

As the cloud campaign expanded, the conspirators compromised telecommunications records, extracting call and text logs from AT&T and Verizon. To monetise these massive caches, Moucka and his team contacted corporate executives directly, demanding ransoms paid in cryptocurrency in exchange for deleting the exfiltrated databases.

In several instances, when victims refused to pay or resisted initial extortion demands, Moucka engaged in aggressive re-extortion. He targeted individual executives, government officials, and cybersecurity investigators. In one notable case, Moucka utilized stolen personal records belonging to a government officer and their immediate family members to force compliance.

Phase IV: Takedown, Retaliation, and Guilty Pleas

By autumn 2024, joint investigations involving the Federal Bureau of Investigation (FBI), the Royal Canadian Mounted Police (RCMP), and private cybersecurity firms narrowed in on Moucka. On October 21, 2024, RCMP investigators conducted physical surveillance on Moucka in Kitchener, capturing photographic evidence later attached to extradition affidavits. On October 30, Canadian authorities arrested Moucka on a provisional U.S. arrest warrant.

Immediately following Moucka’s arrest, co-conspirator Cameron Wagenius ("Kiberphant0m") attempted to retaliate and re-assert leverage. Posting to underground forums, Wagenius published what he claimed were AT&T call records belonging to key political figures, alongside technical schematics allegedly stolen from the U.S. National Security Agency (NSA).

However, law enforcement rapidly unraveled Wagenius’s real-world identity—a U.S. Army soldier stationed in South Korea. Wagenius was apprehended and subsequently pleaded guilty to extortion and computer fraud charges in July 2025. Moucka’s formal guilty plea followed shortly thereafter.


Supporting Context & Metrics

Quantitative Breach Metrics

The scale of the campaign makes it one of the largest coordinated extortion schemes in history. Data exfiltrated across the 165 breached cloud accounts included:

Metric / Category Impact Scale
Total Organizations Breached 165+ entities
Telecommunications Records Stolen 100 million+ customer call/text logs
Total Ransom Payments Collected > $2.5 million USD
Data Types Exfiltrated PII, SSNs, Passports, Financial Records, DEA Numbers, Payroll
Max Potential Prison Time (Moucka) 30 years + mandatory minimum 2 years consecutive
    [Infostealer Logs / Dark Web Credentials]
                        │
                        ▼
    [Snowflake Accounts (No MFA Enforced)]
                        │
                        ▼
   ┌────────────────────┴────────────────────┐
   │                                         │
   ▼                                         ▼
[Corporate PII & Financials]       [Telecom Metadata (100M+ Records)]
   │                                         │
   └────────────────────┬────────────────────┘
                        │
                        ▼
           [Extortion & Re-Extortion]
                        │
                        ▼
     [$2.5M+ Paid / High-Profile Leaks]

The Threat Actor Triad

1. Connor Riley Moucka ("Judische" / "Waifu")

  • Role: Lead operative, data exfiltration architect, primary extortion negotiator.
  • Background: 26-year-old software engineer based in Kitchener, Ontario. Long history in vishing, data breaches, and online harassment networks.
  • Legal Status: Pleaded guilty to computer fraud, wire fraud, conspiracy, and aggravated identity theft. Awaiting sentencing on October 27.

2. Cameron Wagenius ("Kiberphant0m")

  • Role: Co-conspirator, extortion broker, political leak agent.
  • Background: Active-duty U.S. Army soldier formerly stationed in South Korea. Managed multiple Discord and Telegram identities used to auction and leak stolen corporate data.
  • Legal Status: Pleaded guilty in July 2025. Scheduled for sentencing on September 3, 2026. Faces up to 27 years in federal prison.

3. John Erin Binns ("IRDev" / "IntelSecrets")

  • Role: Co-conspirator, infrastructure and data broker.
  • Background: 26-year-old American citizen wanted for the 2021 T-Mobile data breach. Fled the U.S. and was briefly detained in Turkey.
  • Legal Status: Recently released from Turkish custody after obtaining Turkish citizenship. Under Turkish constitutional law, native citizens are shielded from extradition to foreign countries, leaving Binns beyond the reach of U.S. law enforcement for the time being.

Official Statements

U.S. Department of Justice

In an official statement issued upon the entry of Moucka’s guilty plea, the U.S. Department of Justice emphasized the scope of the conspiracy and the personal nature of the harassment:

Canadian Man Pleads Guilty in Snowflake Extortions

"Moucka and his co-conspirators engaged in a relentless scheme to hack into cloud storage databases, steal billions of sensitive records, and hold corporate America hostage… When victims hesitated, Moucka escalated his tactics—harassing public officials, targeting security researchers, and even re-extorting victims using stolen personal data belonging to a government officer and members of their immediate family."

Enterprise Response: Snowflake

Following public disclosure of the breaches in mid-2024, Snowflake issued technical guidance affirming that its core platform infrastructure had not been compromised. Instead, the breach stemmed entirely from compromised user credentials lacking multi-factor protection.

In response to the fallout, Snowflake updated its security architecture across its global client base:

  1. Mandatory MFA: Enforced multi-factor authentication requirements for all customer accounts.
  2. Password Complexity Standards: Automatically elevated minimum password complexity thresholds.
  3. Session Monitoring: Implemented enhanced anomaly-detection mechanisms for unusual bulk data exfiltration queries.

Future Outlook & Strategic Takeaways

The Strategic Shift in Identity Security

The Snowflake extortion saga serves as a watershed moment for enterprise identity access management (IAM). The campaign demonstrated that sophisticated threat actors no longer need zero-day exploits to inflict multi-million-dollar damage; basic credential stuffing against single-factor entry points is sufficient to dismantle perimeter defenses. Organizations are increasingly shifting toward mandatory FIDO2-compliant hardware keys and automated risk-based access policies to prevent infostealer-based credential abuse.

International Extradition and Safe Havens

The divergent fates of the co-conspirators highlight the persistent challenges of sovereign borders in combatting global cybercrime:

  • Canada–U.S. Cooperation: The swift cross-border tracking and provisional arrest of Moucka underscore the efficiency of bilateral legal assistance treaties (MLATs) between Five Eyes allies.
  • The Extradition Loophole: John Erin Binns’ successful acquisition of Turkish citizenship illustrates how cybercriminals actively exploit non-extradition nations to evade federal indictments, creating safe havens from which they can continue operating online.

Legal Precedents and Mandatory Sentencing

As Moucka faces his October 27 sentencing date and Wagenius awaits his September 2026 hearing, federal prosecutors are signaling a zero-tolerance stance toward cyber extortion that targets national critical infrastructure and government personnel.

With mandatory minimums attached to aggravated identity theft and potential decades-long terms for wire fraud, the sentences handed down in this case are expected to set a critical judicial baseline for cloud-era cybercrime prosecutions.

Leave a Reply

Your email address will not be published. Required fields are marked *