**Cybercriminal Behind Massive Snowflake Breach Pleads Guilty**
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024, Connor Riley Moucka, has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud provider Snowflake. He also admitted to stealing call and text history records of more than 100 million AT&T customers.
**The Scale of the Attack**
Between February and October 2024, Moucka and his co-conspirators used stolen login credentials to steal cloud-hosted data belonging to at least 165 customers of a U.S.-based software-as-a-service company. The hackers specifically targeted Snowflake accounts that did not enforce multi-factor authentication (MFA). Their method involved extorting or attempting to extort a host of well-known companies, including TicketMaster, Lending Tree, Advance Auto Parts, and Neiman Marcus.
In response to these data thefts, Snowflake tightened its security protocols by increasing password complexity requirements and enforcing multi-factor authentication universally.
**The Accused and His Methods**
Moucka adopted new nicknames frequently—sometimes operating multiple identities concurrently—but two of his best-known monikers were “Judische” and “Waifu.” His admitted role in the Snowflake data thefts was first documented by KrebsOnSecurity in a September 2024 story that highlighted the overlap between Western, English-speaking cybercriminals and extremist groups that harass and extort minors.
That September 2024 story identified Judische as a software engineer from Ontario who has been involved in numerous data breaches and voice phishing attacks against U.S. companies since at least 2020. A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States.
The U.S. Justice Department says Moucka and others used their unauthorized access to steal billions of sensitive customer records and download terabytes of information. This included individuals’ non-content call and text history records, banking and other financial information, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, social security numbers, and other personally identifiable information. They then extorted victims by threatening to publish this data online.
Moucka also threatened and harassed government officials and security researchers who were helping to track him down. The Justice Department stated that the conspirators made over $2.5 million in ransom payments, and that in at least one instance, Moucka re-extorted a victim with threats of further disclosure of the victim’s stolen data.
One of Moucka’s admitted co-conspirators is Cameron “Kiberphant0m” Wagenius, a U.S. Army soldier who pleaded guilty in July 2025 to extorting AT&T and Verizon for their customer account data. Less than a month before Wagenius’s arrest, KrebsOnSecurity published a deep dive into Kiberphant0m’s various Telegram and Discord identities, revealing how the owner of the accounts told others they were in the Army and stationed in South Korea.
Wagenius is set to be sentenced on September 3, 2026. The government says he faces a maximum penalty of 20 years in prison for conspiracy to commit wire fraud, a maximum penalty of five years in prison for extortion in relation to computer fraud, and a mandatory two-year sentence consecutive to any other prison time for aggravated identity theft.
Another alleged co-conspirator is John Erin Binns, 26, an elusive American man who fled the United States after being indicted for his admitted role in a 2021 breach at T-Mobile that exposed the personal information of at least 76 million customers. Sources close to the investigation said Binns, also known as “IRDev” and “IntelSecrets,” was until recently incarcerated in a Turkish prison but has since been released and resurfaced online. These sources also said Binns recently obtained Turkish citizenship, and under Turkish law, a citizen cannot be extradited to a foreign country.
Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy. He is slated to be sentenced on October 27 and faces a mandatory minimum penalty of two years in prison on the aggravated identity theft count, as well as a maximum penalty of 30 years in prison on the remaining counts. Ultimately, it will be up to the federal judge to determine how much time Moucka actually serves for his extensive cybercriminal record.
For an interview with Moucka prior to his arrest and a deeper look at Binns, see our original report on Moucka’s arrest.
—
## FAQ
**Q1: Who is Connor Riley Moucka?**
A: Connor Riley Moucka is a 26-year-old Canadian man from Kitchener, Ontario, who was once considered one of the most significant cybercrime threat actors of 2024. He has pleaded guilty to multiple charges related to computer fraud, conspiracy, and extortion.
**Q2: What did Moucka and his co-conspirators do?**
A: They used stolen login credentials to gain unauthorized access to Snowflake cloud accounts. They stole data from at least 165 organizations and billions of sensitive customer records from other services. They then threatened to publish this data unless ransom payments were made.
**Q3: Which companies were specifically targeted?**
A: Well-known companies extorted or targeted included TicketMaster, Lending Tree, Advance Auto Parts, and Neiman Marcus.
**Q4: What security changes did Snowflake implement?**
A: In response, Snowflake increased password complexity requirements and enforced multi-factor authentication (MFA) for all users to prevent similar breaches.
**Q5: What happened to the other co-conspirators mentioned?**
A:
– **Cameron “Kiberphant0m” Wagenius**: A U.S. Army soldier who pleaded guilty to extorting AT&T and Verizon. He is scheduled for sentencing in September 2026.
– **John Erin Binns**: An American man indicted for the 2021 T-Mobile breach. He fled the U.S. and was recently released from a Turkish prison; due to his Turkish citizenship, he cannot be extradited.
**Q6: What are the potential penalties for Moucka?**
A: Moucka faces a mandatory minimum of two years for aggravated identity theft and a maximum penalty of 30 years in prison on the remaining counts. His final sentence will be determined by a federal judge.
—
## Conclusion
The case of Connor Riley Moucka serves as a stark reminder of the evolving tactics of cybercriminals who target cloud infrastructure to steal vast amounts of sensitive data. The scale of the breach, impacting over 165 organizations and more than 100 million AT&T customers, underscores the critical need for robust security measures like mandatory multi-factor authentication and strong password policies. As legal proceedings begin for the perpetrators, this case highlights the ongoing global challenge of prosecuting cybercriminals, particularly when they cross international borders.



