In one of the most significant judicial developments in recent cybersecurity history, 26-year-old Canadian national Connor Riley Moucka—recognized by federal authorities and threat intelligence researchers as one of the most prolific cybercrime threat actors of 2024—has formally pleaded guilty in U.S. federal court. Moucka, a resident of Kitchener, Ontario, admitted to multiple counts of computer fraud, wire fraud, aggravated identity theft, and conspiracy for his central role in a far-reaching campaign that breached and extorted more than 165 major organizations reliant on the cloud data platform Snowflake.
Operating under a rotating constellation of aliases, most prominently “Judische” and “Waifu,” Moucka orchestrated a campaign between February and October 2024 that resulted in the exfiltration of terabytes of highly sensitive corporate and personal data. Among his most devastating breaches was the massive theft of call and text detail records belonging to over 100 million AT&T customers.
Federal prosecutors from the U.S. Department of Justice (DOJ) revealed that Moucka and his co-conspirators leveraged stolen administrative credentials to compromise enterprise accounts that lacked basic security controls, specifically Multi-Factor Authentication (MFA). Through relentless public and private extortion demands, the cybercriminal nexus collected upwards of $2.5 million in illicit cryptocurrency ransom payments. Victims spanned a roster of household names, including Ticketmaster, LendingTree, Advance Auto Parts, and Neiman Marcus, as well as critical government infrastructure and personnel.
The guilty plea marks a watershed moment in the enforcement of international cybercrime laws, exposing the intricate underground web connecting Western cybercriminals, insider threat actors within the military, and fugitive hacker networks operating out of non-extradition safe havens.
Detailed Chronology: From Underground Harassment to Enterprise Cloud Extortion
+-----------------------------------------------------------------------------------+
| TIMELINE OF EVENTS |
+-----------------------------------------------------------------------------------+
| 2020–2023 : Early cybercrime ops (vishing, breach of corporate targets, "Com") |
| Aug 2021 : Co-conspirator John Erin Binns breaches T-Mobile (76M records) |
| Feb 2024 : Moucka network begins systematically targeting Snowflake instances |
| May–Jul '24: Mass extortion of Ticketmaster, AT&T, Neiman Marcus, LendingTree |
| Jul 2024 : AT&T breach revealed; over 100M customer metadata records exposed |
| Sep 2024 : KrebsOnSecurity links alias "Judische" to Ontario software engineer |
| Oct 21, '24: RCMP conducts physical surveillance on Moucka in Kitchener, Ontario |
| Oct 30, '24: Canadian authorities arrest Moucka on U.S. provisional warrant |
| Jul 2025 : Co-conspirator Cameron Wagenius (U.S. Army) pleads guilty |
| Present : Moucka pleads guilty to 4 federal counts; sentencing set for Oct 27 |
+-----------------------------------------------------------------------------------+
The Origins and Underground Evolution (2020–2023)
Long before targeting cloud storage environments, Connor Riley Moucka operated in the shadows of western underground hacker ecosystems. A software engineer by training, Moucka engaged in voice phishing (vishing) campaigns, social engineering schemes, and targeted corporate breaches dating back to at least 2020. Over time, he established deep ties with violent extortion communities colloquially known as "The Com"—underground digital networks characterized by swatting, physical harassment, minor manipulation, and aggressive financial extortion.
Concurrently, future co-conspirator John Erin Binns (aliases “IRDev” and “IntelSecrets”) gained international notoriety in August 2021 by executing a historic breach against T-Mobile, compromising the personal information of 76 million consumers. Binns subsequently fled the United States to evade federal prosecution, setting the stage for future collaborative cyber operations.
The Snowflake Harvest (February – May 2024)
Beginning in early February 2024, Moucka and his network shifted their tactical focus toward cloud-hosted infrastructure. Recognizing that many enterprise clients using the Software-as-a-Service (SaaS) giant Snowflake failed to enforce mandatory multi-factor authentication on administrative accounts, Moucka systematically weaponized stolen credentials harvested from infostealer malware logs (such as RedLine, Vidar, and Lumma).
Rather than exploiting an architectural flaw within Snowflake’s core engine, the conspirators utilized valid login credentials to directly access single-factor customer environments. Over several months, they quietly indexed, queried, and exfiltrated vast repositories of corporate databases containing terabytes of customer PII, financial ledgers, and operational secrets.
The Extortion Offensive (June – August 2024)
By mid-2024, Moucka’s network aggressively transitioned from passive exfiltration to active extortion. Operating under his "Judische" handle, Moucka contacted victim corporations, demanding multimillion-dollar ransoms in exchange for deleting the stolen data and withholding public disclosure.
When organizations delayed or refused payment, the network published samples on illicit hacking forums and Telegram channels. High-profile incidents included:
Ticketmaster: Hundreds of millions of customer records offered for sale.
AT&T: Exfiltration of non-content call and text record metadata impacting virtually all AT&T wireless customers.
Neiman Marcus & Advance Auto Parts: Compromise of customer databases containing payment details, social security numbers, and corporate credentials.
Investigative Breakthrough and Law Enforcement Interception (September – October 2024)
The sheer scale of the Snowflake campaign triggered an international, multi-agency investigation involving the FBI, the U.S. Department of Justice, the Royal Canadian Mounted Police (RCMP), and leading private threat intelligence firms.
In September 2024, an investigative report published by KrebsOnSecurity publicly connected the alias "Judische" to an Ontario-based software engineer, shedding light on his dual identity and ties to violent harassment groups. Armed with actionable intelligence, the RCMP initiated physical surveillance on Moucka in Kitchener, Ontario, capturing photographic evidence on October 21, 2024. Nine days later, on October 30, 2024, Canadian law enforcement executed a provisional arrest warrant issued by U.S. authorities, taking Moucka into custody.
Extradition, Retaliation, and Final Plea (2025–Present)
Following Moucka’s arrest, co-conspirators attempted retaliatory leaks. Cameron "Kiberphant0m" Wagenius, an active-duty U.S. Army soldier stationed in South Korea, posted alleged AT&T call logs belonging to prominent political figures—including then-President-elect Donald Trump and Vice President Kamala Harris—alongside sensitive defense schematics.
Despite these escalation tactics, federal prosecutors built an unassailable evidentiary record. Wagenius pleaded guilty in July 2025 to wire fraud conspiracy and computer extortion. Moucka subsequently capitulated, entering a formal guilty plea to four federal counts covering computer fraud, wire fraud, aggravated identity theft, and conspiracy.
+-----------------------------------------------------------------------------------+
| BREACH & IMPACT METRICS MATRIX |
+-----------------------------------------------------------------------------------+
| Total Victimized Organizations | 165+ Enterprise Cloud Instances |
| Telecommunications Records Stolen | 100 Million+ AT&T Customer Accounts |
| Verified Illicit Ransom Proceeds | $2,500,000+ USD (Cryptocurrency) |
| Stolen Data Categories | PII, SSNs, Passports, DEA Registrations, |
| | Call/Text Metadata, Financial/Payroll Data |
| Primary Initial Access Vector | Infostealer Malware Logs (Unprotected MFA) |
| Maximum Statutory Prison Term | Moucka: Mandatory Min 2 yrs + up to 30 yrs |
| | Wagenius: Mandatory Min 2 yrs + up to 27 yrs |
+-----------------------------------------------------------------------------------+
The Shared Responsibility Model & Cloud Vulnerability
The Snowflake campaign serves as a case study in the failure of corporate identity security. The threat actors did not breach Snowflake’s primary architecture; instead, they exploited the zero-trust paradigm’s weakest link: human credential management.
Because victim organizations had not enabled Multi-Factor Authentication (MFA) on legacy or administrative user accounts, Moucka’s team accessed corporate databases using valid, stolen credentials. The breached data included sensitive metrics such as:
Government Records: Drug Enforcement Administration (DEA) registration numbers, passport numbers, and Social Security Numbers (SSNs).
Financial Records: Banking details, payroll registers, and customer transaction logs.
Telecommunications Metadata: Non-content call and text records, detailing origin, destination, and duration metadata for over 100 million mobile users.
In direct response to this widespread campaign, Snowflake enacted mandatory security posture changes across its customer ecosystem, enforcing strict password complexity standards and requiring multi-factor authentication across all tenant instances.
The Threat Actor Network: Profiles of the Conspirators
1. Connor Riley Moucka ("Judische" / "Waifu")
Role: Lead operator, coordinator of exfiltration, and primary extortion negotiator.
Profile: 26-year-old software engineer from Kitchener, Ontario, with a long history in the Western cybercrime underground ("The Com").
Legal Status: Pleaded guilty to 4 counts. Scheduled for sentencing on October 27. Faces a mandatory minimum of 2 years for identity theft plus up to 30 years for remaining charges.
2. Cameron "Kiberphant0m" Wagenius
Role: Technical collaborator and co-extortionist.
Profile: Active-duty U.S. Army soldier formerly stationed in South Korea. Ran active Discord and Telegram threat channels targeting major telecom carriers, including AT&T and Verizon.
Legal Status: Pleaded guilty in July 2025. Scheduled for sentencing on September 3, 2026. Faces a mandatory minimum 2-year sentence for aggravated identity theft consecutive to a potential 25 years for wire fraud and computer extortion.
3. John Erin Binns ("IRDev" / "IntelSecrets")
Role: Technical advisor and senior threat actor.
Profile: 26-year-old U.S. citizen responsible for the massive 2021 T-Mobile breach. Fled the U.S. to avoid federal charges and was subsequently detained in Turkey.
Legal Status: Recently released from Turkish detention after acquiring Turkish citizenship. Under Turkish constitutional law, citizens cannot be extradited to foreign jurisdictions, effectively placing Binns beyond the immediate reach of U.S. law enforcement.
The guilty plea brought stern statements from high-ranking officials across law enforcement agencies, underscoring the severity of Moucka’s actions and the global scope of the investigation.
U.S. Department of Justice
In an official statement announcing the plea agreement, the U.S. Department of Justice highlighted the malicious nature of the extortion tactics, particularly Moucka’s targeting of public servants:
"Moucka and his co-conspirators systematically looted the private cloud infrastructure of major corporations, stealing sensitive records belonging to hundreds of millions of Americans. When victims refused to capitulate, Moucka doubled down, engaging in aggressive re-extortion tactics that targeted government officials and their families. Today’s plea demonstrates that geographic borders offer no shield to cybercriminals who threaten our national security and economic stability."
Federal Law Enforcement and International Partners
Investigators emphasized the role of international cooperation between the FBI, the U.S. Secret Service, and the Royal Canadian Mounted Police (RCMP). Canadian authorities noted that Moucka’s arrest followed extensive cross-border intelligence sharing, culminating in the execution of the provisional arrest warrant in Ontario.
A senior cybersecurity investigator tracking the group remarked:
"The unraveling of Connor Moucka’s operations dismantles a critical bridge between corporate ransomware-style extortion and the chaotic, harassment-driven subculture of ‘The Com.’ This prosecution sends an unambiguous signal to threat actors operating out of Western jurisdictions that technical tradecraft will not prevent attribution."
Future Outlook and Enterprise Implications
The guilty plea of Connor Riley Moucka resolves a dramatic chapter in cloud security, but its ripples will reverberate through enterprise risk management and international cyber jurisprudence for years to come.
+-----------------------------------------------------------------------------------+
| FUTURE OUTLOOK & TAKEAWAYS |
+-----------------------------------------------------------------------------------+
| Institutional Mandates : Mandatory MFA across all enterprise SaaS platforms. |
| Judicial Benchmarks : Severe sentencing precedents for cloud data extortion. |
| Safe Haven Challenges : Ongoing geopolitical friction regarding non-extradition |
| jurisdictions (e.g., Turkey, Russia). |
| Identity Security Shift : Transition from basic password policies to continuous |
| Identity Threat Detection and Response (ITDR). |
+-----------------------------------------------------------------------------------+
1. The Redefinition of Enterprise Cloud Risk
The Snowflake breaches marked a structural shift in how cloud service providers and enterprise clients manage identity risk. The campaign exposed a common flaw in enterprise governance: assuming the cloud vendor enforces baseline identity security.
Organizations are rapidly moving toward enforced Identity Threat Detection and Response (ITDR) frameworks.
Mandatory Multi-Factor Authentication (MFA), FIDO2-compliant passkeys, and the elimination of legacy single-factor API integrations are transitioning from industry "best practices" to non-negotiable regulatory requirements.
2. Legal Benchmarks and Judicial Precedents
With Moucka slated for sentencing on October 27 and Wagenius facing his sentencing on September 3, 2026, the federal judiciary is positioned to establish stern sentencing benchmarks for cloud data exfiltration and extortion.
The application of mandatory minimums for aggravated identity theft—stacked consecutively on top of wire and computer fraud convictions—ensures that core threat actors in major breach campaigns face significant prison sentences.
The inclusion of harassment, swatting, and re-extortion of government personnel as aggravating factors will likely lead to sentences approaching the statutory maximums.
3. The Safe-Haven Dilemma
The case of John Erin Binns underscores the persistent challenge of jurisdictional safe havens. Despite world-wide law enforcement coordination, threat actors who manage to obtain citizenship or asylum in non-extradition nations like Turkey or Russia remain largely insulated from Western judicial systems.
As Binns resurfaces online to participate in underground cyber communities, federal authorities face a growing strategic dilemma: how to neutralize high-tier cybercriminals operating from behind national borders that refuse to honor international arrest warrants.
Ultimately, while the conviction of Connor Riley Moucka closes the book on one of 2024’s most destructive cyber extortion networks, it serves as a stark reminder of the persistent vulnerability inherent in enterprise cloud environments—where a single unauthenticated login can compromise the personal data of hundreds of millions of people.