Connor Riley Moucka, a 26-year-old Canadian man from Kitchener, Ontario, has pleaded guilty to federal computer fraud and conspiracy charges in connection with a massive cybercriminal campaign that targeted cloud data for more than 165 organizations utilizing Snowflake and stole call and text logs belonging to over 100 million AT&T customers. According to the U.S. Department of Justice, Moucka operated under multiple online aliases, including “Judische” and “Waifu,” and carried out the extensive data thefts alongside co-conspirators between February and October 2024.
The case represents one of the most significant cloud-infrastructure security breaches of recent years, exposing terabytes of sensitive files and billions of records. Federal prosecutors state that Moucka and his associates exploited stolen login credentials specifically targeting customer accounts that failed to enforce multi-factor authentication. The compromised entities included major brands such as TicketMaster, Lending Tree, Advance Auto Parts, and Neiman Marcus, triggering urgent infrastructure hardening and mandatory password complexity updates across cloud providers.
Following a provisional warrant issued by the United States, Royal Canadian Mounted Police investigators arrested Moucka in Ontario in late October 2024. An affidavit filed during the Canadian proceedings included surveillance imagery of Moucka captured just days prior to his apprehension. The investigation eventually uncovered a sprawling international conspiracy spanning multiple jurisdictions and high-profile targets.
The Snowflake Breach and Extortion Campaign
Between February and October 2024, the conspirators utilized unauthorized credentials to infiltrate cloud environments managed by a prominent U.S.-based software-as-a-service provider. According to court records, the group downloaded vast repositories of sensitive customer data, including banking information, Social Security numbers, passport details, driver’s licenses, Drug Enforcement Administration registration numbers, and non-content call and text history records.
Victim companies faced intense pressure as the hackers threatened to leak stolen corporate and consumer data online unless ransom demands were met. Federal authorities reported that the cybercrime ring collected more than $2.5 million in extortion payments. In addition to corporate targets, investigators revealed that Moucka actively harassed and threatened government officials and security researchers who attempted to track his digital footprint. In at least one instance, prosecutors noted that Moucka attempted to re-extort a victim by leveraging stolen records belonging to a government official and members of that official’s immediate family.
The illicit operation’s exposure began drawing intense public and investigative scrutiny in September 2024, when security journalism first detailed the convergence of Western English-speaking threat actors with extremist networks engaged in harassment and extortion. Canadian authorities moved swiftly, arresting Moucka shortly after those initial disclosures.
Co-Conspirators and Global Legal Fallout
Moucka’s guilty plea unfolds alongside legal proceedings for several admitted co-conspirators linked to the same wave of telecommunications and cloud breaches. Cameron Wagenius, operating under the moniker “Kiberphant0m,” admitted to his role in extorting AT&T and Verizon. Wagenius, identified as a U.S. Army soldier stationed in South Korea, posted claims on hacker forums following Moucka’s arrest asserting he possessed call logs belonging to then President-elect Donald Trump and Vice President Kamala Harris, alongside stolen National Security Agency schematics. Wagenius pleaded guilty and is scheduled to be sentenced on September 3, 2026, facing potential decades in federal custody.
A third individual, 26-year-old American citizen John Erin Binnsโknown online as “IRDev” and “IntelSecrets”โwas previously indicted for his involvement in a 2021 breach at T-Mobile impacting at least 76 million customers. Sources close to the investigation indicated that Binns was recently held in a Turkish prison before securing his release and obtaining Turkish citizenship. Under Turkish legal protections, citizens cannot be extradited to foreign jurisdictions, complicating efforts to bring him before U.S. courts.
Moucka entered formal guilty pleas to four criminal counts, encompassing computer fraud, wire fraud, conspiracy, and aggravated identity theft. Federal prosecutors outlined a statutory framework that includes a mandatory minimum sentence of two years for aggravated identity theft and a maximum penalty of up to 30 years across the remaining charges.
U.S. District Court officials have scheduled Moucka’s sentencing hearing for October 27, where a federal judge will determine the final prison term for his cybercriminal activities. Legal experts and cybersecurity analysts continue to monitor the fallout from the Snowflake compromises as corporations re-evaluate cloud access controls and credential hygiene.
Keep reading