Canadian Cybercriminal Connor Riley Moucka Pleads Guilty to Massive Snowflake Data Breach and Global Extortion Campaign

Connor Riley Moucka, a 26-year-old software engineer from Kitchener, Ontario, has officially entered a guilty plea in a U.S. federal court, marking a definitive conclusion to one of the most prolific and disruptive cybercrime sagas of 2024. Once operating under the ominous online aliases "Judische" and "Waifu," Moucka admitted to his central role in a sophisticated campaign of computer fraud, conspiracy, and extortion that compromised more than 165 organizations utilizing the cloud services provider Snowflake. His criminal activities, which spanned from February to October 2024, extended far beyond corporate data theft, encompassing the unauthorized acquisition of sensitive records belonging to over 100 million AT&T customers.
The scale of the breach represents a significant milestone in modern cybersecurity history, illustrating the vulnerabilities inherent in cloud-hosted data environments. Moucka’s guilty plea to four criminal counts—including wire fraud, conspiracy, and aggravated identity theft—comes as a stark reminder of the evolving threat landscape where individual actors, operating from the relative anonymity of the internet, can exert profound pressure on multinational corporations and national infrastructure.
The Anatomy of the Snowflake Intrusion
The methodology employed by Moucka and his co-conspirators relied on a fundamental weakness in cybersecurity hygiene: the absence of robust multi-factor authentication (MFA). By obtaining stolen login credentials, the threat actors gained unauthorized access to Snowflake customer accounts. The breach was not merely an act of data exfiltration; it was a calculated extortion scheme. Victims, which included prominent industry leaders such as TicketMaster, Lending Tree, Advance Auto Parts, and Neiman Marcus, were subjected to threats of public data disclosure unless ransom demands were met.
The Justice Department’s investigation revealed that the attackers successfully downloaded terabytes of proprietary information. The stolen datasets were staggering in scope and sensitivity, containing banking details, payroll records, Drug Enforcement Administration (DEA) registration numbers, passport information, driver’s licenses, and social security numbers. In a disturbing display of malice, the attackers utilized this information to engage in "re-extortion"—a tactic where victims who had already paid a ransom were targeted again with threats that additional, even more sensitive, data would be leaked if further payments were not made.

Chronology of the Criminal Enterprise
The trajectory of this criminal enterprise highlights the speed at which modern cyber-threats move.
- 2020–2023: Early indicators of Moucka’s activity appear, with reports of his involvement in data breaches and voice phishing campaigns against various U.S. entities.
- February 2024: The commencement of the coordinated Snowflake intrusion campaign begins.
- September 2024: KrebsOnSecurity publishes a comprehensive investigation identifying "Judische" as an Ontario-based software engineer, linking him to extremist groups and widespread corporate extortion.
- October 2024: Canadian authorities arrest Moucka on a provisional warrant issued by the United States.
- July 2025: Co-conspirator Cameron "Kiberphant0m" Wagenius pleads guilty to extortion charges related to the telecommunications sector.
- August 2025–Present: Legal proceedings reach their final stages, with sentencing hearings scheduled for late 2025 and 2026.
The Web of Conspirators
Moucka did not operate in a vacuum. The investigation identified a global network of collaborators, most notably Cameron Wagenius, a U.S. Army soldier stationed in South Korea at the time of his activities. Wagenius, known online as "Kiberphant0m," operated with a level of brazenness that included posting claims on hacker forums regarding the theft of call logs for then-President-elect Donald Trump and Vice President Kamala Harris. His eventual arrest and subsequent guilty plea have provided investigators with a clearer picture of the coordination required to manage such a vast database of stolen records.
The third key figure, John Erin Binns, remains an elusive subject of international law enforcement. Indicted for his role in the 2021 T-Mobile breach that affected 76 million individuals, Binns—also known as "IRDev"—reportedly fled to Turkey. Recent reports suggest that Binns has secured Turkish citizenship, a legal status that complicates, if not entirely prevents, his extradition to the United States. The case of Binns serves as a persistent challenge for international cooperation in cybersecurity, where jurisdictional boundaries often provide a safe harbor for high-profile cybercriminals.
Institutional Responses and Security Implications
In the wake of the breaches, Snowflake undertook a comprehensive review of its security protocols. The provider moved to mandate multi-factor authentication for all customer accounts and increased password complexity requirements. These changes were a direct response to the realization that the primary vector for these attacks was not a flaw in the Snowflake software itself, but the failure of customers to secure their access points.
The broader implications of this case are significant. Cybersecurity experts point to the "human element" as the primary vulnerability in these incidents. By targeting accounts that lacked basic security layers, the perpetrators were able to bypass complex encryption and perimeter defenses. Furthermore, the use of stolen data to harass government officials and security researchers demonstrates a shift toward more aggressive, personalized cyber-attacks designed to intimidate those tasked with tracking criminal activity.

Analysis: The Cost of Extortion
The Justice Department has confirmed that the conspirators extracted over $2.5 million in ransom payments. However, this figure likely represents only a fraction of the total economic damage. The cost to the affected companies includes not only the ransom payments but also the expenses associated with forensic investigations, legal fees, regulatory fines, and the inevitable erosion of consumer trust.
The re-extortion of a government officer and their family members represents a tactical escalation that has drawn significant attention from federal prosecutors. By weaponizing the private information of government employees, the conspirators attempted to create a sense of personal vulnerability that would force victims into compliance. This behavior marks a departure from purely profit-driven cybercrime and aligns more closely with state-level intimidation tactics, though the motivations in this case remained fundamentally rooted in financial gain.
Legal Outlook and Sentencing
Moucka’s legal future is now in the hands of the federal judiciary. With a maximum penalty of 30 years in prison for the combined counts of wire fraud, conspiracy, and computer fraud, alongside a mandatory two-year minimum for aggravated identity theft, the sentence will likely serve as a benchmark for future cybercrime prosecutions. His sentencing, currently slated for October 27, will be scrutinized by the cybersecurity community as an indicator of how the U.S. judicial system intends to handle the rise of "consequential" threat actors.
Cameron Wagenius, meanwhile, awaits his sentencing on September 3, 2026. The accumulation of prison time for both individuals underscores the severity with which the U.S. government views the unauthorized access of cloud environments and the theft of telecommunications metadata.
Conclusion
The case of Connor Riley Moucka serves as a definitive case study in the modern cyber-threat environment. It highlights the convergence of independent hackers, the strategic targeting of cloud infrastructure, and the exploitation of individual user negligence. As corporations continue to shift their data to cloud-based environments, the necessity for robust, enforced security standards has never been more apparent. While Moucka’s capture and conviction provide a sense of justice for the millions affected by his actions, the ongoing activities of figures like John Erin Binns remind us that the global digital battlefield remains inherently volatile and difficult to police. The legacy of the 2024 Snowflake extortion campaign will likely influence cybersecurity policy, corporate data governance, and international law enforcement cooperation for years to come.






