Executive Overview
In one of the most financially damaging and widespread cybercrime campaigns in recent history, 26-year-old Canadian national Connor Riley Moucka has pleaded guilty in federal court to computer fraud, wire fraud, aggravated identity theft, and conspiracy. Operating under high-profile digital monikers including "Judische" and "Waifu," Moucka admitted to orchestrating a massive intrusion and extortion campaign that compromised more than 165 corporate entities hosted on the cloud storage platform Snowflake. Among his admitted offenses was the theft of sensitive call and text history records belonging to over 100 million AT&T customers.
Between February and October 2024, Moucka and a network of specialized co-conspirators systematically exploited compromised single-factor authentication credentials to systematically drain terabytes of sensitive enterprise data. The victims encompassed high-profile corporations across retail, telecommunications, financial, and entertainment sectors—including Ticketmaster, LendingTree, Advance Auto Parts, and Neiman Marcus.
The campaign yielded more than $2.5 million in illicit ransom payments, exposed billions of individual data records, and demonstrated how single-factor security oversights at the customer level can translate into catastrophic enterprise exposure.
The prosecution of Moucka highlights the intricate intersection of Western cybercriminal networks, online harassment groups, and nation-state level access mechanics. With co-conspirators ranging from an active-duty U.S. Army soldier to a fugitive threat actor operating out of Turkey, the case exposes the globalized nature of modern cyber extortion and the ongoing friction between international law enforcement and jurisdictional safe havens.
Detailed Chronology
[2020 – 2023] Early Operations: "Judische" conducts voice phishing (vishing) and data breaches targeting U.S. firms.
│
[Feb – Oct 2024] Snowflake Extortion Campaign: Systemic compromise of 165+ un-MFA-protected corporate accounts.
│
[July 2024] AT&T Breach Revealed: Exfiltration of call/text metadata belonging to 100M+ telecommunications users.
│
[Sept 2024] Media Exposure: Investigative reports link "Judische" to broader cyber harassment and extortion rings.
│
[Oct 30, 2024] Law Enforcement Intervention: RCMP arrests Moucka in Kitchener, Ontario, on a U.S. provisional warrant.
│
[July 2025] Co-Conspirator Plea: Active-duty soldier Cameron Wagenius ("Kiberphant0m") pleads guilty to extortion.
│
[Present] Legal Resolution: Moucka pleads guilty to federal charges, awaiting sentencing set for October 27.
The Origins of Threat Actor "Judische" (2020–2023)
Long before the Snowflake attacks made international headlines, the individual behind the moniker "Judische"—identified as software engineer Connor Riley Moucka of Kitchener, Ontario—was active within underground cybercrime ecosystems. Beginning as early as 2020, Moucka engaged in voice phishing (vishing) operations, doxxing campaigns, and corporate breaches.
Over time, investigative findings revealed a direct nexus between Moucka’s network and online "harm groups"—loose collectives of predominantly Western, English-speaking cybercriminals known for abusing stolen data, conducting swatting attacks, and coercing minors into self-harm or financial extortion.
The Snowflake Extortion Spree (February – October 2024)
In early 2024, Moucka and his network identified a critical operational vulnerability: dozens of corporate tenants using Snowflake’s cloud storage platform had not implemented Multi-Factor Authentication (MFA) across their administrative and user accounts. Utilizing credential lists harvested from historical infostealer malware logs, the group engaged in automated credential-stuffing attacks.
Once access was secured, the threat actors engaged in rapid, automated exfiltration of database instances. By mid-2024, the exfiltrated datasets contained billions of individual records. The group then pivoted to direct extortion, contacting corporate executives via encrypted messaging channels and email, threatening to release or sell the stolen data on underground forums unless steep ransoms were paid in cryptocurrency.
Law Enforcement Counteraction and Arrests
The campaign began to unravel as investigative tracking narrowed down the real-world identity of "Judische." In September 2024, public investigative journalism highlighted the link between the high-profile Snowflake breaches, corporate vishing attacks, and Moucka’s identity.
Following close coordination between the U.S. Federal Bureau of Investigation (FBI) and Canadian authorities, the Royal Canadian Mounted Police (RCMP) executed a provisional arrest warrant at Moucka’s home in Kitchener, Ontario, on October 30, 2024. Surveillance photographs captured by Canadian law enforcement prior to his arrest formed part of the extradition affidavit detailing his physical movements and digital footprint.

The Network of Co-Conspirators: Wagenius and Binns
Moucka did not act in isolation. Law enforcement identified two primary co-conspirators operating alongside him:
- Cameron "Kiberphant0m" Wagenius: An active-duty U.S. Army soldier stationed in South Korea. Wagenius was instrumental in facilitating breaches targeting telecommunications giants AT&T and Verizon. He was arrested following digital forensics tracing his Telegram and Discord aliases. Wagenius pleaded guilty in July 2025 to conspiracy to commit wire fraud, computer fraud extortion, and aggravated identity theft.
- John Erin Binns ("IRDev" / "IntelSecrets"): A 26-year-old American citizen previously indicted for orchestrating the infamous 2021 T-Mobile data breach that exposed 76 million customer records. Binns fled the U.S. to Turkey, where he was temporarily detained in a Turkish prison before being released. Binns subsequently acquired Turkish citizenship, creating an extradition barrier under Turkish domestic law.
Supporting Context & Metrics
Technical Mechanics: Credential Exploitation and Infrastructure Hardening
The Snowflake campaign did not rely on zero-day vulnerabilities within Snowflake’s underlying cloud architecture. Instead, it weaponized compromised single-factor identity credentials.
SNOWFLAKE BREACH ANATOMY
┌───────────────────────┐ ┌─────────────────────────┐ ┌─────────────────────────┐
│ Infostealer Malware │ ───► │ Single-Factor Logins │ ───► │ SaaS Platform Access │
│ (Log Harvesting) │ │ (No MFA Enforced) │ │ (Unrestricted Siphoning)│
└───────────────────────┘ └─────────────────────────┘ └─────────────────────────┘
│
▼
┌───────────────────────┐ ┌─────────────────────────┐ ┌─────────────────────────┐
│ Double Extortion │ ◄─── │ Data Exfiltration │ ◄─── │ Terabytes of Sensitive │
│ (Re-extorting victims)│ │ (Database Dumps) │ │ Enterprise Records │
└───────────────────────┘ └─────────────────────────┘ └─────────────────────────┘
The key operational elements included:
- Infostealer Log Utilization: The actors acquired vast repositories of stolen credentials from historical malware infections (e.g., RedLine, Vidar).
- Absence of MFA Enforcement: Victim accounts were accessible using standard username/password combinations without secondary verification.
- Automated Data Scraping: Using customized scripts, the actors queried exposed cloud databases to identify high-value tables containing Personally Identifiable Information (PII) and internal communications.
In response to the breaches, Snowflake adjusted its security baseline, implementing mandatory multi-factor authentication policies and enforcing stricter password complexity requirements for customer instances platform-wide.
Exfiltrated Data Profile and Scope of Impact
The stolen datasets represent one of the largest concentrations of compromised enterprise data on record:
| Metric | Details & Volume |
|---|---|
| Total Targeted Entities | Over 165 corporate organizations using Snowflake SaaS infrastructure. |
| Major Confirmed Victims | AT&T, Ticketmaster, LendingTree, Advance Auto Parts, Neiman Marcus. |
| AT&T Telecommunications Data | Non-content call and text metadata for 100M+ customers (timestamps, counterpart numbers). |
| Total Ransom Extorted | Exceeded $2.5 million paid across multiple corporate victims. |
| Sensitive Data Types Exfiltrated | PII, SSNs, Passports, Driver’s Licenses, Financial/Payroll Records, DEA Numbers. |
Extortion Dynamics and Aggressive Re-Extortion
Moucka and Wagenius implemented double-extortion tactics, demanding payment in exchange for non-disclosure agreements and data deletion promises. However, the conspirators repeatedly violated their own terms.
According to U.S. Department of Justice court filings, Moucka routinely re-extorted victims who had already remitted payment, threatening further disclosures if additional funds were not transferred. In one notable instance of harassment, Moucka utilized stolen data belonging to a government officer and members of a former official’s immediate family to execute high-pressure re-extortion demands, extending his target list to include security researchers and investigators who were tracking his activities.
Following Moucka’s arrest in late 2024, Wagenius posted samples of sensitive stolen records on underground hacker forums, claiming possession of AT&T call logs associated with prominent U.S. political figures, alongside technical schematics allegedly belonging to the National Security Agency (NSA).
Official Statements
The legal filings and press releases surrounding the guilty pleas of Moucka and his co-conspirators offer clear insights into federal law enforcement’s position on globalized cyber extortion.
A spokesperson for the U.S. Department of Justice emphasized the scope of the group’s actions:

"Moucka and his co-conspirators used unauthorized access to steal billions of sensitive customer records and download terabytes of information, including individuals’ non-content call and text history records, banking information, payroll records, and government identification numbers. They then systematically extorted victims by threatening to publish this data online, showing a total disregard for individual privacy and public security."
Court filings detailing Moucka’s re-extortion efforts highlighted the specific targeting of public servants:
"The defendant utilized the stolen data of a government officer and members of a then-former government officer’s immediate family in a re-extortion attempt. The conspirators demonstrated an escalating pattern of extortion, threats, and harassment directed at corporate victims, government personnel, and independent security researchers."
The Royal Canadian Mounted Police (RCMP), which executed the search warrant and arrest in Kitchener, noted in court affidavits that digital forensic evidence seized at the scene directly linked Moucka’s physical devices to active extortion channels used to communicate with compromised victims.
Future Outlook
Judicial Penalties and Sentencing Timeline
The legal proceedings for the core members of the extortion ring are nearing their final phases in federal court:
- Connor Riley Moucka: Having pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy, Moucka faces a mandatory minimum of two years in prison on the identity theft charge, alongside a maximum statutory penalty of 30 years in prison for the remaining counts. His formal sentencing hearing is scheduled for October 27.
- Cameron Wagenius: Scheduled to be sentenced on September 3, 2026. Under his plea agreement, Wagenius faces a maximum penalty of 20 years for conspiracy to commit wire fraud, up to five years for computer fraud extortion, and a mandatory consecutive two-year term for aggravated identity theft.
UPCOMING SENTENCING MILESTONES
┌──────────────────────────────────────────┐ ┌──────────────────────────────────────────┐
│ CONNOR RILEY MOUCKA │ │ CAMERON WAGENIUS │
│ Scheduled Sentencing: October 27 │ │ Scheduled Sentencing: September 3, 2026 │
│ • Mandatory Min: 2 Years (Agg. ID Theft) │ │ • Wire Fraud Consp: Max 20 Years │
│ • Statutory Max: Up to 30 Years │ │ • Computer Extortion: Max 5 Years │
└──────────────────────────────────────────┘ │ • Aggravated ID Theft: 2 Years (Consec.) │
└──────────────────────────────────────────┘
Jurisdictional Safe Havens: The Case of John Erin Binns
The case of John Erin Binns underscores the growing challenge posed by state citizenship laws in cybercrime prosecution. While Moucka and Wagenius face federal prison sentences, Binns remains insulated from U.S. prosecution in Turkey.
Having successfully acquired Turkish citizenship following his release from local custody, Binns is currently protected by Article 38 of the Turkish Constitution, which prohibits the extradition of citizens to foreign nations for criminal prosecution. Despite remaining under active federal indictment in the United States, Binns has resurfaced online, illustrating the tactical use of sovereign legal frameworks by high-profile cybercriminals to evade justice.
Broader Lessons for Enterprise Cybersecurity
The resolution of the Snowflake data extortion cases serves as a case study for modern corporate security architecture:
- The Single-Factor Vulnerability Hazard: The entire multi-terabyte exfiltration campaign was built on credential reuse and the absence of enforced MFA. Organizations can no longer treat multi-factor authentication as an optional configuration for cloud services.
- Third-Party SaaS Risk Exposure: Centralized cloud service platforms represent high-value targets for global cybercrime syndicates. Compromising a single misconfigured enterprise account can expose entire supply chains.
- The Unreliability of Ransom Agreements: The group’s frequent use of re-extortion demonstrates that paying criminal entities offers no legal or operational guarantee of data deletion or permanent protection from future leaks.
