Mastermind of Massive Cloud Extortion Campaign Pleads Guilty in U.S. Federal Court

Executive Overview

In one of the most significant legal breakthroughs against modern cybercrime rings, Connor Riley Moucka—a 26-year-old Canadian national previously identified by cybersecurity researchers as one of the most destructive threat actors of 2024—has formally pleaded guilty in a U.S. federal court. Moucka admitted to his pivotal role in a widespread conspiracy to hack, breach, and extort more than 165 enterprise organizations utilizing the cloud-based data warehousing platform Snowflake.

Operating under digital aliases such as "Judische" and "Waifu," the Kitchener, Ontario resident engaged in a months-long campaign between February and October 2024. Alongside a network of specialized co-conspirators, Moucka systematically weaponized stolen corporate credentials to compromise cloud environments, exfiltrate terabytes of highly sensitive proprietary data, and demand million-dollar ransoms. Among his admitted exploits was the catastrophic compromise of AT&T infrastructure, resulting in the theft of call and text history records belonging to more than 100 million telecommunications customers.

The U.S. Department of Justice (DOJ) confirmed that the syndicate secured over $2.5 million in extortion payments throughout its operational run. Beyond standard corporate extortions, the network engaged in aggressive personal harassment, doxxing, and re-extortion campaigns targeting government officials, security researchers, and high-profile figures.

Moucka’s guilty plea addresses four felony counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. As federal courts prepare for sentencing, the case stands as a critical watershed moment for enterprise Software-as-a-Service (SaaS) security, highlighting the extreme risk posed by unmonitored credentials and single-factor authentication in enterprise cloud architectures.


Detailed Chronology

[2020–2023] ----------------------------------------------------------------->
• Moucka engages in initial voice phishing & cyber breach activities.
• John Erin Binns breaches T-Mobile (76M records), escapes to Turkey.

[Feb 2024 – Oct 2024] ------------------------------------------------------->
• Snowflake Extortion Campaign: 165+ targets breached via stolen credentials.
• Major victims hit: Ticketmaster, Neiman Marcus, Advance Auto Parts, AT&T.
• Over $2.5M in illicit cryptocurrency ransoms collected.

[Sept 2024 – Oct 2024] ------------------------------------------------------>
• Investigations link "Judische" to broader cyber harassment networks.
• Oct 21: RCMP surveillance captures photo of Moucka in Ontario.
• Oct 30: Canadian authorities execute provisional U.S. warrant; Moucka arrested.

[Nov 2024 – Mid 2025] ------------------------------------------------------->
• Kiberphant0m leaks retaliatory logs (Trump, Harris) & NSA schematics.
• July 2025: Co-conspirator Cameron Wagenius (Kiberphant0m) pleads guilty.

[Late 2025 – Late 2026] ----------------------------------------------------->
• Moucka enters guilty plea; faces mandatory minimums & up to 30 years.
• Sept 3, 2026: Scheduled sentencing for Cameron Wagenius.
• Oct 27: Scheduled sentencing for Connor Riley Moucka.

The Origins and Early Operations (2020–2023)

Moucka’s path to becoming an elite cyber threat actor began years before the Snowflake campaign. A software engineer by trade, Moucka established himself within Western, English-speaking cybercriminal subcultures as early as 2020. During this period, he specialized in sophisticated voice phishing (vishing) schemes, social engineering tactics, and initial access operations aimed at corporate networks across North America.

Simultaneously, co-conspirator John Erin Binns ("IRDev," "IntelSecrets") achieved notorious prominence in 2021 by breaching T-Mobile and stealing personal data from 76 million consumers. Facing pending U.S. indictments, Binns fled the country to evade prosecution, eventually establishing residence in Eastern Europe and Turkey—setting the stage for future cross-border technical alliances.

The Snowflake Extortion Blitz (February 2024 – October 2024)

By early 2024, Moucka, Binns, and an active-duty U.S. Army soldier named Cameron "Kiberphant0m" Wagenius consolidated their capabilities into an aggressive cloud-focused campaign. Rather than exploiting zero-day vulnerabilities in Snowflake’s core software infrastructure, the group targeted individual enterprise user accounts.

Exploiting stolen credentials previously harvested by global infostealer malware networks (such as RedLine, Vidar, and Lumma), the hackers searched specifically for corporate accounts that lacked Multi-Factor Authentication (MFA). Between February and October 2024, the actors systematically logged into at least 165 corporate Snowflake environments, harvesting massive volumes of cloud-hosted data.

High-profile corporate targets fell in rapid succession, including:

Canadian Man Pleads Guilty in Snowflake Extortions – Krebs on Security
  • Ticketmaster: Massive database compromises affecting millions of event attendees.
  • Neiman Marcus & Advance Auto Parts: Mass corporate record exfiltrations containing customer details and transactional history.
  • LendingTree: Breach of financial data and customer background applications.
  • AT&T: Exfiltration of non-content call and text record metadata impacting over 100 million users.

Following successful exfiltrations, the actors established communication with victim executives, issuing extortion demands backed by threats to release sensitive files on public hacking forums or sell them to rival criminal actors.

Surveillance, Arrest, and Retaliatory Leaks (Late 2024)

As federal law enforcement agencies intensified their joint investigation alongside the Royal Canadian Mounted Police (RCMP), investigative reporters and cyber intelligence specialists linked Moucka’s online handles ("Judische" and "Waifu") directly to real-world infrastructure in Ontario.

On October 21, 2024, RCMP investigators captured surveillance imagery of Moucka in Kitchener, Ontario. Nine days later, on October 30, Canadian law enforcement executed a provisional arrest warrant issued by the United States, taking Moucka into custody.

In the immediate wake of Moucka’s arrest, his co-conspirator Cameron Wagenius ("Kiberphant0m") launched a series of retaliatory leaks. Posting on underground illicit forums, Wagenius published what he claimed were AT&T call logs belonging to prominent political figures—including then-President-elect Donald Trump and then-Vice President Kamala Harris—as well as classified schematics allegedly stolen from the U.S. National Security Agency (NSA).

Legal Reckoning (2025–2026)

In July 2025, Cameron Wagenius pleaded guilty in federal court to his role in extorting major telecommunications providers, including AT&T and Verizon. Shortly thereafter, Moucka reached a plea agreement with federal prosecutors, formally admitting to all major counts of computer intrusion, wire fraud, extortion, and aggravated identity theft.


Supporting Context & Metrics

The quantitative scale of the Snowflake extortion campaign highlights the extreme risk exposure inherent in centralized SaaS repositories. By targeting cloud databases housing consolidated enterprise data, Moucka and his co-conspirators caused vast financial, operational, and regulatory damages.

+-------------------------------------------------------------------------+
|                       CAMPAIGN METRICS & IMPACT                         |
+-------------------------------------------------------------------------+
| Victim Organizations Breached          | 165+ Enterprise Cloud Instances |
| AT&T Customer Records Compromised      | 100,000,000+ Unique Users       |
| Total Extortion Proceeds Collected     | $2,500,000+ USD                 |
| Maximum Statutory Sentence (Moucka)    | Up to 32 Years Total Imprisonment|
| Mandatory Minimum (Identity Theft)    | 2 Years Consecutive             |
+-------------------------------------------------------------------------+

Stolen Data Composition

The exfiltrated datasets comprised billions of individual rows of corporate and personal information, creating substantial identity theft and national security concerns:

  • Personally Identifiable Information (PII): Social Security Numbers (SSNs), driver’s license details, passport numbers, and birth records.
  • Government & Professional Credentials: Drug Enforcement Administration (DEA) registration numbers assigned to medical professionals.
  • Telecommunications Metadata: Non-content call logs, SMS interaction records, cell site location data, and communication frequency metrics.
  • Corporate Financials: Complete payroll ledgers, internal wire details, banking records, and proprietary financial filings.

Extortion Tactics and Re-Extortion Mechanics

The group leveraged advanced psychological pressure strategies during negotiations. If a victim organization paid an initial ransom to secure a non-disclosure or deletion agreement, the group did not always honor the settlement.

In at least one case highlighted by the Justice Department, Moucka engaged in re-extortion against a previously settled victim. To increase pressure during the second extortion attempt, Moucka deployed stolen, unreleased PII belonging to a federal government officer and members of that officer’s immediate family.

Canadian Man Pleads Guilty in Snowflake Extortions – Krebs on Security
+-------------------------------------------------------------------------+
|                  ATTACK VECTOR ANALYSIS & MITIGATION                    |
+-------------------------------------------------------------------------+
| Attack Phase       | Cybercriminal Strategy     | Defense Countermeasure |
+--------------------+----------------------------+-----------------------+
| Initial Access     | Infostealer Logs /         | Mandatory MFA Enforcement|
|                    | Unmonitored Single-Factor  | & SSO Integration     |
+--------------------+----------------------------+-----------------------+
| Privilege Escalation| Utilizing Validated Admin | Dynamic Access Reviews|
|                    | Enterprise Credentials     | & Privilege Scrubber  |
+--------------------+----------------------------+-----------------------+
| Data Exfiltration  | Bulk Querying of Unlocked  | Anomalous Egress Monitoring|
|                    | Cloud Warehouses           | & Query Rate-Limiting |
+--------------------+----------------------------+-----------------------+
| Extortion Phase    | Ransom Demands via Telegram| Secure Offsite Backup |
|                    | & Doxxing Harassment       | & Incident Playbooks  |
+-------------------------------------------------------------------------+

Profiles of the Cybercrime Triumvirate & Official Statements

The investigation revealed a complex, decentralized network connecting Western threat actors, active military personnel, and overseas fugitives.

                  +--------------------------------+
                  |  CONNOR RILEY MOUCKA          |
                  |  "Judische" / "Waifu"          |
                  |  • Lead Operator & Hacker      |
                  |  • Canadian National (26)      |
                  +---------------+----------------+
                                  |
         +------------------------+------------------------+
         |                                                 |
+--------v-----------------------+       +-----------------v--------------+
| CAMERON WAGENIUS               |       | JOHN ERIN BINNS                |
| "Kiberphant0m"                 |       | "IRDev" / "IntelSecrets"       |
| • Ex-U.S. Army Soldier         |       | • Fugitive / T-Mobile Hacker   |
| • Extortion & Data Brokerage   |       | • Obtained Turkish Citizenship |
+--------------------------------+       +--------------------------------+

1. Connor Riley Moucka ("Judische" / "Waifu")

  • Role: Primary execution officer, cloud intrusion architect, direct negotiator.
  • Background: A 26-year-old software developer from Kitchener, Ontario, Moucka moved within extreme online harassment ecosystems (frequently referred to as "The Com"). These networks often overlap with swatting rings, minor harassment, and financial extortion groups.
  • Legal Status: Pleaded guilty to four counts including wire fraud, computer fraud, and aggravated identity theft. Facing a mandatory minimum of 2 years on identity theft charges and up to 30 years on remaining federal charges. Sentencing is scheduled for October 27.

2. Cameron "Kiberphant0m" Wagenius

  • Role: Operational handler, infrastructure administrator, extortion distributor.
  • Background: A U.S. Army soldier stationed in South Korea during the height of the campaign. Wagenius managed Telegram and Discord channels used to broker stolen databases and coordinate ransom threats.
  • Legal Status: Pleaded guilty in July 2025 to conspiracy to commit wire fraud, computer fraud extortion, and aggravated identity theft. Scheduled for sentencing on September 3, 2026. Faces a maximum penalty of 20 years for wire fraud, 5 years for computer extortion, and a mandatory 2-year consecutive term for aggravated identity theft.

3. John Erin Binns ("IRDev" / "IntelSecrets")

  • Role: Senior advisor, infrastructure strategist, breach specialist.
  • Background: An American national who gained infamy following the 2021 breach of T-Mobile. Binns fled the U.S. to evade prosecution, later resurfacing in Turkey.
  • Current Status: Binns was briefly incarcerated in a Turkish facility before being released. Sources close to federal intelligence confirm that Binns recently obtained Turkish citizenship. Under Turkish constitutional law, native citizens are shielded from extradition to foreign nations, presenting significant jurisdictional barriers for U.S. prosecutors.

Official Statements

Following the formal submission of Moucka’s guilty plea, the U.S. Department of Justice issued a public statement condemning the multi-year campaign:

"Connor Riley Moucka and his co-conspirators executed a modern, multi-million-dollar cyber extortion enterprise that intentionally targeted critical business cloud infrastructure, compromising the private records of tens of millions of North American citizens. Cybercriminals operating across international borders should take clear note: geographic distance and digital aliases provide no permanent sanctuary from federal prosecution."

Snowflake responded to the breach vector investigations by executing major structural platform security updates, requiring baseline password updates across all customer tenants and enforcing mandatory Multi-Factor Authentication (MFA) protocols for administrative and access controls.


Future Outlook & Systemic Cyber Risk

The resolution of the case against Connor Riley Moucka offers key security takeaways for enterprise organizations, cloud service providers, and global law enforcement agencies.

The Identity Management Imperative

The Snowflake intrusions emphasized that modern enterprise perimeters no longer rest on centralized network firewalls, but on identity and access controls. The root cause of the breaches across 165+ major corporate entities was not a zero-day exploit within Snowflake’s core architecture, but rather:

  1. Infostealer Proliferation: Millions of employee credentials are routinely harvested by background malware and traded on dark web marketplaces.
  2. Single-Factor Exposure: Legacy enterprise accounts were permitted to access sensitive data warehouses using basic username/password combinations.
  3. Inadequate SaaS Identity Governance: A lack of centralized Identity and Access Management (IAM) controls meant security teams often lacked visibility into unmonitored cloud instances.

As enterprise architectures transition heavily toward SaaS infrastructure, enforcement of passwordless authentication, FIDO2-compliant hardware keys, and strict MFA rules has become essential to defending corporate networks.

The Problem of Foreign Safe Havens

The case also illustrates the growing jurisdictional limitations facing international law enforcement. While domestic coordination between the U.S. Department of Justice and the Royal Canadian Mounted Police led to Moucka’s successful arrest, the case of John Erin Binns underscores how cybercriminals leverage sovereign borders and local citizenship laws to evade justice.

As threat groups continue operating across foreign jurisdictions, public-private partnerships, rapid credential revocation, and zero-trust cloud architectures remain the most effective defenses against cross-border cyber extortion schemes.

Leave a Reply

Your email address will not be published. Required fields are marked *