Mastermind Behind Massive Cloud Extortion Ring Pleads Guilty: Inside the Breach of Snowflake, AT&T, and Over 165 Enterprise Targets

Executive Overview

In one of the most significant legal breakthroughs against modern cloud-focused cybercrime, 26-year-old Canadian national Connor Riley Moucka has pleaded guilty to multiple federal charges in connection with a massive, multi-million-dollar cyber-extortion campaign. Moucka—widely recognized in cybersecurity circles under the handles “Judische” and “Waifu”—was formally identified by federal prosecutors as a core perpetrator behind the unauthorized access and extortion of more than 165 corporate entities that utilized the cloud database platform Snowflake.

Between February and October 2024, Moucka and his network systematically targeted enterprise cloud repositories using compromised credentials, exfiltrating vast volumes of highly sensitive corporate and personal data. Among the breached organizations were major household brands, including Ticketmaster, LendingTree, Advance Auto Parts, and Neiman Marcus. Additionally, Moucka admitted to orchestrating the theft of non-content call and text record histories belonging to more than 100 million AT&T customers.

The illicit campaign netted the conspiracy more than $2.5 million in extorted ransom payments. Beyond corporate financial theft, the threat actor group repeatedly weaponized stolen data to harass victims, security researchers, and government officials. Moucka pleaded guilty to four federal counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. He faces a mandatory minimum sentence of two years in federal prison for aggravated identity theft, alongside a potential maximum penalty of 30 years on the accompanying charges.


Detailed Chronology

[2020 – 2023] -------------------------------------------------------------------
 • Binns executes 2021 T-Mobile breach (76M records exposed); flees to Turkey.
 • Moucka begins voice phishing and corporate data intrusion operations.

[February – May 2024] -----------------------------------------------------------
 • Moucka & co-conspirators launch systematic credential-stuffing attacks against 
   unprotected Snowflake accounts.
 • Exfiltration of terabytes of data from Ticketmaster, LendingTree, and others.

[July 2024] ----------------------------------------------------------------------
 • Massive AT&T data breach exposed; records of 100M+ customers compromised.

[September 2024] -----------------------------------------------------------------
 • Investigative exposure links alias "Judische" to an Ontario software engineer 
   and dark web harassment networks ("The Com").

[October 2024] -------------------------------------------------------------------
 • Royal Canadian Mounted Police (RCMP) arrest Moucka in Kitchener, Ontario, 
   on a U.S. provisional warrant.
 • Retaliatory leaks by co-conspirator "Kiberphant0m" (Trump/Harris call logs).

[July 2025 – Late 2026] ----------------------------------------------------------
 • Co-conspirator Cameron Wagenius ("Kiberphant0m") pleads guilty (July 2025).
 • Moucka pleads guilty to federal counts; sentencing set for October 27.
 • Wagenius scheduled for sentencing on September 3, 2026.

The Genesis and Evolution of the Intrusion Ring (2020–2023)

The operational roots of this cybercriminal network extend back several years prior to the 2024 Snowflake campaign. Co-conspirator John Erin Binns (operating under aliases “IRDev” and “IntelSecrets”) established a precursor blueprint in August 2021 when he breached telecommunications giant T-Mobile, exposing the sensitive personal information of at least 76 million customers. Binns subsequently fled the United States to avoid federal prosecution.

Concurrently, Moucka emerged within online underground communities as an adept operator specializing in voice phishing (vishing), social engineering, and corporate network intrusions dating back to at least 2020.

The Snowflake Cloud Campaign (February – October 2024)

Starting in early 2024, the syndicate shifted its operational posture toward centralized cloud infrastructure. Recognizing that many enterprise clients hosted critical repositories on Snowflake without enforcing Multi-Factor Authentication (MFA), Moucka and his associates systematically leveraged credential-stealer logs purchased from dark web marketplaces.

Using stolen single-factor authentication credentials, the perpetrators compromised single sign-on (SSO) and database management accounts across at least 165 organization environments. Throughout the spring and summer of 2024, the group silently downloaded terabytes of corporate data, payroll databases, customer records, and identity documents before issuing ransom demands.

Unmasking and Law Enforcement Intervention (September – October 2024)

In September 2024, investigative reporting published by KrebsOnSecurity revealed critical overlaps between high-profile cloud extortions and violent online harassment networks colloquially known as "The Com." The investigation identified "Judische" as an Ontario-based software engineer who had operated under multiple concurrent digital identities.

Canadian Man Pleads Guilty in Snowflake Extortions – Krebs on Security

Following formal requests and coordination with U.S. federal law enforcement, the Royal Canadian Mounted Police (RCMP) executed a provisional arrest warrant on October 30, 2024, taking Moucka into custody at his residence in Kitchener, Ontario.

Retaliation, Co-Conspirator Pleas, and Judicial Milestones (2024–2026)

Following Moucka’s capture, co-conspirator Cameron “Kiberphant0m” Wagenius, an active-duty U.S. Army soldier stationed in South Korea, engaged in chaotic retaliatory disclosures. Wagenius leaked data dumps on cybercrime forums containing alleged AT&T metadata for high-profile political figures, including then President-elect Donald Trump and then Vice President Kamala Harris, alongside schematics purportedly originating from the National Security Agency (NSA).

Wagenius was subsequently apprehended and pleaded guilty in July 2025 for his primary role in extorting telecommunications providers AT&T and Verizon. Meanwhile, Moucka entered his formal guilty plea in U.S. federal court, setting the stage for final sentencing.


Supporting Context & Metrics

Key Campaign Metrics

  • Total Enterprise Compromises: 165+ organizations using Snowflake.
  • Impacted Individual Records: 100+ million AT&T customer accounts.
  • Confirmed Financial Extortion Proceeds: In excess of $2.5 million USD.
  • Volume of Stolen Material: Terabytes of data across dozens of cloud database instances.
+------------------------------------------------------------------------+
|                      Extortion & Impact Summary                        |
+------------------------------------------------------------------------+
|  Primary Vector:         Stolen Credentials / Non-MFA Cloud Accounts   |
|  Direct Ransoms Paid:    >$2.5 Million USD                             |
|  Notable Victims:        AT&T, Ticketmaster, LendingTree,              |
|                          Advance Auto Parts, Neiman Marcus             |
|  Data Types Stolen:      Call/Text Logs, PII, SSNs, Passports,         |
|                          DEA Numbers, Banking & Payroll Records        |
+------------------------------------------------------------------------+

The Attack Vector: MFA Exploitation in SaaS Architectures

The technical breakdown of the Snowflake breaches highlighted systemic gaps in identity management rather than zero-day vulnerabilities in Snowflake’s core architecture. The attackers utilized historical infostealer malware logs (e.g., RedLine, Vidar, Lumma) containing valid username and password combinations previously harvested from infected employee devices.

Because the targeted customer accounts had not mandated Multi-Factor Authentication (MFA), the attackers bypassed perimeter defenses effortlessly. In direct response to the campaign, Snowflake updated its security posture, instituting stricter password complexity requirements and enforcing mandatory MFA policies across its customer base.

Stolen Data Categories

The exfiltrated assets constituted a comprehensive inventory of personal, financial, and organizational data:

  • Telecommunications Metadata: Non-content call and text transaction histories (originating/terminating numbers, call duration, cell tower identifiers).
  • Personally Identifiable Information (PII): Social Security numbers, driver’s license details, passport numbers, and full names.
  • Financial & Corporate Data: Banking credentials, direct deposit payroll manifests, internal company financial projections, and customer payment histories.
  • Regulated Identifiers: Drug Enforcement Administration (DEA) registration numbers tied to healthcare providers.

Psychological Tactics and Re-Extortion

Moucka and his associates frequently employed psychological pressure tactics that exceeded typical ransomware operations. When victims paid initial demands, the perpetrators routinely reneged on promises to destroy the exfiltrated databases.

In at least one instance detailed by the U.S. Department of Justice, Moucka executed a secondary extortion attempt against a victim company using sensitive personal data belonging to a government official and members of the official’s immediate family. Additionally, Moucka engaged in active campaigns of intimidation, harassment, and targeted threats against cybersecurity researchers and federal investigators attempting to track his infrastructure.

Canadian Man Pleads Guilty in Snowflake Extortions – Krebs on Security

The Co-Conspirators: Network Breakdown

                    +-----------------------------+
                    |    Connor Riley Moucka      |
                    |     "Judische" / "Waifu"    |
                    |  (Canadian Lead Operator)   |
                    +--------------+--------------+
                                   |
         +-------------------------+-------------------------+
         |                                                   |
+--------v--------------------+             +----------------v-------------------+
|  Cameron "Kiberphant0m"     |             |      John Erin Binns               |
|         Wagenius            |             |   "IRDev" / "IntelSecrets"         |
| (U.S. Army / Extortionist)  |             |  (Fugitive / T-Mobile Intruder)    |
+-----------------------------+             +------------------------------------+

Cameron "Kiberphant0m" Wagenius

Cameron Wagenius served as a primary collaborator alongside Moucka, leveraging online identities to facilitate communication and leak stolen data assets. While serving as an active-duty military service member in South Korea, Wagenius orchestrated extortion operations against AT&T and Verizon.

Wagenius entered a guilty plea in July 2025. He is scheduled to be sentenced on September 3, 2026, facing up to 20 years for conspiracy to commit wire fraud, up to five years for computer fraud extortion, and a mandatory consecutive two-year term for aggravated identity theft.

John Erin Binns ("IRDev")

John Erin Binns represents a complex geopolitical challenge for international law enforcement. After claiming responsibility for the 2021 T-Mobile network intrusion, Binns fled the U.S. to evade prosecution.

According to sources familiar with the investigation, Binns was detained for a period in a Turkish prison but has since been released. Crucially, Binns acquired Turkish citizenship during his residence in the country. Under Article 38 of the Turkish Constitution, Turkish citizens cannot be extradited to a foreign state for criminal prosecution, effectively granting Binns a safe haven from U.S. extradition warrants.


Official Statements

U.S. Department of Justice Statement:
"Moucka and his co-conspirators used unauthorized access to steal billions of sensitive customer records and download terabytes of information… They then extorted victims by threatening to publish data online. Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt."

Cybersecurity & Infrastructure Security Agency (CISA) Advisory Reflection:
"The compromised Snowflake instances serve as a stark reminder that single-factor authentication on enterprise cloud endpoints represents an unacceptable operational risk. Organizations must mandate multi-factor authentication across all cloud interfaces immediately."


Future Outlook

The guilty plea of Connor Riley Moucka marks a critical legal milestone in countering enterprise-scale cloud extortion. However, the systemic vulnerabilities exploited throughout the 2024 campaign highlight broad, lingering risks for modern cloud-reliant enterprises.

Lessons for Corporate Cloud Governance

  1. Mandatory Identity-First Security: The core vulnerability exploited in these intrusions was not a flaw in cloud software code, but a systemic failure of Identity and Access Management (IAM). Organizations must transition to strict Zero Trust Access models, enforcing phishing-resistant MFA (such as FIDO2/WebAuthn keys) across all external-facing enterprise software.
  2. Infostealer Ecosystem Mitigation: Organizations must actively monitor underground markets for compromised corporate credentials harvested by infostealer malware, invalidating leaked sessions before threat actors can operationalize them.
  3. Data Retention & Exfiltration Defense: Companies storing vast data sets in cloud data warehouses must institute strict egress filtering, automated data-loss prevention (DLP) protocols, and minimized data-retention schedules to reduce exposure surface during an intrusion.

Judicial Next Steps

  • Connor Riley Moucka: Scheduled for final sentencing on October 27. He faces a mandatory minimum of two years for aggravated identity theft alongside a statutory maximum of up to 30 years across remaining wire and computer fraud charges.
  • Cameron Wagenius: Scheduled for sentencing on September 3, 2026, where he faces up to 27 years in federal custody.
  • John Erin Binns: Remains an active fugitive abroad under foreign protection, continuing to operate within online cybercrime circles beyond the reach of Western extradition frameworks.

Leave a Reply

Your email address will not be published. Required fields are marked *