Canadian Hacker Connor Riley Moucka Pleads Guilty to Massive Snowflake Data Extortion Scheme

The digital security landscape of 2024 was defined by a series of unprecedented breaches, the most consequential of which has now reached a definitive legal resolution. Connor Riley Moucka, a 26-year-old software engineer from Kitchener, Ontario, has officially pleaded guilty to charges of computer fraud and conspiracy. His admission of guilt marks the end of a destructive rampage that targeted more than 165 organizations utilizing the cloud services of Snowflake, a U.S.-based data warehousing giant. Beyond the corporate breaches, Moucka’s criminal activity extended to the mass exfiltration of sensitive telecommunications data, including the call and text histories of over 100 million AT&T customers.
The scope of the crimes orchestrated by Moucka and his co-conspirators underscores a critical vulnerability in the modern cloud-first economy: the failure to implement universal multi-factor authentication (MFA) across enterprise-level platforms. Between February and October 2024, the group systematically exploited stolen credentials to infiltrate the private cloud environments of some of the world’s most prominent corporations, including Ticketmaster, LendingTree, Advance Auto Parts, and Neiman Marcus.
A Chronology of the Cyber-Infiltration
The operation, which the U.S. Department of Justice (DOJ) describes as one of the most significant cybercrime events of the decade, followed a calculated methodology. The attackers did not rely on complex zero-day exploits; instead, they harvested valid credentials from third-party sources and leveraged them against Snowflake accounts that lacked secondary verification protocols.
The timeline of these events serves as a stark case study in modern threat actor evolution:
- Early 2024: Moucka, operating under the handles "Judische" and "Waifu," begins the systematic campaign against Snowflake customers.
- September 2024: Investigative reporting by KrebsOnSecurity highlights the connection between "Judische" and extremist groups, identifying the actor as an Ontario-based software engineer.
- October 2024: Canadian authorities, acting on a provisional warrant issued by the United States, apprehend Moucka.
- November 2024: The U.S. government formalizes the charges, detailing the extent of the data theft, which included DEA registration numbers, social security records, and financial documents.
- July 2025: Co-conspirator Cameron "Kiberphant0m" Wagenius, a U.S. Army soldier, pleads guilty to his role in the extortion scheme.
- August 2025: Moucka enters his guilty plea in U.S. federal court, acknowledging his role in the conspiracy.
The Anatomy of the Conspiracy
Moucka did not act alone. His collaboration with Cameron Wagenius and John Erin Binns created a tripartite criminal structure that combined technical exploitation with high-stakes extortion.

Wagenius, who was stationed in South Korea during his service in the U.S. Army, acted as a primary engine for the group’s telecommunications-focused attacks. His arrest revealed a disturbing disregard for national security, as he allegedly claimed to possess sensitive schematics belonging to the U.S. National Security Agency (NSA). Following Moucka’s initial arrest, Wagenius reportedly attempted to leverage the chaos by leaking purported call logs belonging to high-ranking U.S. political figures on hacker forums.
The third member, John Erin Binns, remains an outlier in the legal pursuit. Already a known figure to international law enforcement for his involvement in the 2021 T-Mobile data breach, Binns has successfully navigated jurisdictional complexities. Having obtained Turkish citizenship, he has shielded himself from extradition. Sources indicate that Binns—who has operated under the aliases "IRDev" and "IntelSecrets"—has recently resurfaced in online forums, emboldened by the legal protections offered by his adopted nationality.
Financial and Personal Toll
The DOJ estimates that the group successfully extorted over $2.5 million in ransom payments. However, the financial cost to the victimized organizations—in terms of forensic investigations, legal fees, and reputational damage—is likely in the hundreds of millions.
The brutality of the group’s tactics was perhaps most evident in their "re-extortion" methods. In at least one instance, after a victim had already paid a ransom, Moucka targeted a government official and their immediate family, using their personal, stolen data as leverage to demand further payment. This shift toward targeting the families of officials and researchers represents an aggressive escalation in cyber-extortion, moving beyond mere corporate data theft into the realm of personal harassment.
Snowflake’s Response and Industry Implications
In the immediate wake of the breaches, Snowflake faced significant scrutiny regarding its security defaults. The company responded by mandating stricter password complexity requirements and, crucially, enforcing the use of multi-factor authentication across its platform. The incident served as a wake-up call for the SaaS industry, highlighting that even the most robust cloud infrastructure can be compromised if the client-side authentication remains weak.
Cybersecurity analysts point out that the Snowflake incident proves that "credential stuffing"—the automated injection of stolen usernames and passwords—remains the most effective tool in a threat actor’s arsenal. When paired with an organization’s failure to audit its own access logs, the result is a catastrophic exposure of data that, as in this case, included everything from passport numbers to payroll records.

The Legal Consequences
As the judicial process draws to a close, the focus shifts to the sentencing phase. Moucka faces a mandatory minimum of two years for aggravated identity theft and a maximum of 30 years for his other convictions. His sentencing is scheduled for October 27.
Wagenius, meanwhile, is slated for sentencing on September 3, 2026. The charges against him, which include conspiracy to commit wire fraud and extortion related to computer fraud, carry a combined potential of over two decades in prison. The DOJ’s aggressive pursuit of these individuals signals a shift in federal strategy: moving away from viewing cybercrime as a purely technological issue and toward treating it as a violent, organized criminal enterprise that requires severe, deterrent-focused sentencing.
Broader Impact on Cybersecurity Policy
The arrest and conviction of Moucka and his co-conspirators have provided researchers with a wealth of information regarding the "dark nexus" between professional cybercriminals and extremist groups. The investigation revealed that the lines between profit-driven hacking and ideological harassment have blurred, with the same tools used to breach corporate servers being repurposed to dox, harass, and extort private individuals.
The incident has also prompted a re-evaluation of how the U.S. government handles digital evidence and extradition. The case of John Erin Binns, in particular, highlights the persistent problem of "cyber-havens," where threat actors can exploit international borders to evade prosecution. As the digital economy continues to expand, the ability of law enforcement to cooperate across borders—and to secure the cooperation of foreign governments—will be the primary determinant in the effectiveness of global cybersecurity.
Ultimately, the Moucka case serves as a definitive reminder that in the interconnected world of 2024, no organization is too large to be overlooked, and no credential is too small to be valuable. The legal fallout will be felt for years to come, not only in the sentencing of those responsible but in the mandatory security standards that have since been forced upon the cloud industry, ensuring that the vulnerabilities exploited by "Judische" and "Kiberphant0m" are significantly more difficult to replicate in the future.







