A Canadian Man’s Descent into Cybercrime: Guilty Plea Reveals Extensive Hacking and Extortion Scheme
Connor Riley Moucka, a 26-year-old from Kitchener, Ontario, has pleaded guilty to computer fraud and conspiracy to hack and extort over 165 organizations that used the cloud data storage provider Snowflake. The extensive hacking and extortion scheme, which spanned from February to October 2024, resulted in the theft of sensitive customer records from at least 100 million AT&T customers.
The investigation into Moucka’s activities revealed a sophisticated operation involving stolen login credentials, malware, and social engineering tactics. The hackers targeted Snowflake customer accounts that did not enforce multi-factor authentication, allowing them to gain unauthorized access to cloud-hosted data. Once inside, they stole sensitive information, including individuals’ non-content call and text history records, banking and financial information, payroll records, and more.
Moucka’s role in the scheme was extensive, with him using various aliases, including “Judische” and “Waifu.” He even went so far as to threaten and harass government officials and security researchers who were helping to track him down. The conspirators made over $2.5 million in ransom payments, with Moucka re-extorting a victim by threatening to publish their stolen data online.
The investigation into Moucka’s activities also uncovered connections to other high-profile hacking cases. One of his co-conspirators, Cameron “Kiberphant0m” Wagenius, is a U.S. Army soldier who pleaded guilty in July 2025 to extorting AT&T and Verizon for their customer account data. Another alleged co-conspirator, John Erin Binns, fled the United States after being indicted for his role in a 2021 breach at T-Mobile.
The sheer scale of Moucka’s hacking and extortion scheme is staggering, with billions of sensitive customer records stolen and terabytes of information downloaded. The fact that he used this data to extort victims by threatening to publish their stolen data online is a chilling reminder of the dangers of cybercrime.
As we look at the details of this case, it becomes clear why security experts are emphasizing the importance of multi-factor authentication and robust password management practices. In many cases, hackers like Moucka rely on weak passwords or lack of MFA to gain access to cloud-hosted data. The fact that Snowflake responded to the data thefts by increasing password complexity requirements and enforcing MFA is a crucial step in preventing similar attacks in the future.
For individuals and organizations looking to protect themselves from hacking and extortion schemes, there are some key takeaways. Firstly, ensure that multi-factor authentication is enabled on all accounts, especially those used for cloud storage. Secondly, use robust password management practices, including complex passwords and regular updates. Finally, be aware of phishing scams and social engineering tactics that hackers like Moucka may use to gain access to your data.
In conclusion, the guilty plea of Connor Riley Moucka marks a significant victory in the fight against cybercrime. However, it also serves as a reminder of the ongoing threat posed by sophisticated hacking operations. By staying informed and taking proactive steps to secure our online presence, we can reduce the risk of falling victim to such attacks.
Source: Krebs on Security — 2026-08-06