Canadian Man Pleads Guilty in Snowflake Extortions

A notorious Canadian cybercrime suspect has pleaded guilty to a string of high-profile extortion cases, including targeting over 165 organizations that used the cloud provider Snowflake. Connor Riley Moucka, aka “Judische” and “Waifu,” admitted to stealing sensitive customer records from AT&T customers, as well as extorting companies like TicketMaster, Lending Tree, and Neiman Marcus.

Moucka’s scheme worked by exploiting stolen login credentials for Snowflake customer accounts that didn’t enforce multi-factor authentication. He and his co-conspirators would then use this access to steal terabytes of sensitive information, including call and text history records, banking data, and social security numbers. This valuable data was then used to extort the companies, threatening to publish it online unless they paid a hefty ransom.

The scope of Moucka’s operation is staggering – over 100 million AT&T customers had their call and text history records stolen, and the hackers made over $2.5 million in ransom payments. But what makes this case even more disturbing is that Moucka went beyond just extorting companies; he also threatened and harassed government officials and security researchers who were trying to track him down.

One of Moucka’s alleged co-conspirators, Cameron “Kiberphant0m” Wagenius, a U.S. Army soldier, has already pleaded guilty to his role in the extortion scheme. Wagenius was involved in extorting AT&T and Verizon for their customer account data and even re-extorted victims by threatening to publish more stolen data online.

The case highlights the importance of robust security measures, particularly multi-factor authentication, to protect sensitive customer data. Companies that don’t take these precautions risk falling victim to sophisticated cybercrime operations like Moucka’s. As the Justice Department puts it, “Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt.” This is a chilling example of how cybercrime can have real-world consequences.

The aftermath of this case will be closely watched – Wagenius is set to be sentenced on September 3, 2026, and Moucka’s plea deal is likely to include significant prison time. The case also serves as a reminder that cybersecurity threats are not just limited to the digital realm; they can have serious consequences for individuals and organizations alike.

In light of this case, companies should take immediate action to strengthen their security measures, including implementing multi-factor authentication and regularly monitoring their cloud-hosted data for suspicious activity. Individuals can also protect themselves by being cautious when receiving unsolicited emails or messages from unknown senders and keeping their personal information secure online.


Source: Krebs on Security — 2026-08-06