Connor Riley Moucka, a resident of Kitchener, Ontario, has entered a guilty plea to charges of computer fraud and conspiracy related to hacking and extorting more than 165 organizations relying on the Snowflake cloud platform. The 26-year-old also confessed to obtaining call and text history records belonging to over 100 million AT&T subscribers. Prosecutors have characterized Moucka as among the most significant cybercriminal actors active during 2024.
According to the U.S. Justice Department, from February through October 2024, Moucka worked alongside accomplices to leverage compromised login credentials in order to access cloud-based information held by at least 165 clients of a U.S. software-as-a-service provider. The criminal group focused on Snowflake user accounts lacking multi-factor authentication protections, subsequently extorting or attempting to extort numerous prominent enterprises such as TicketMaster, Lending Tree, Advance Auto Parts, and Neiman Marcus. In response to these incidents, Snowflake implemented stricter password requirements and mandated multi-factor authentication across its platform.
Moucka operated under multiple aliases, frequently rotating between identities and sometimes maintaining several simultaneously. Among his most recognized handles were "Judische" and "Waifu." KrebsOnSecurity initially documented the connection between Judische and the Snowflake breaches in a September 2024 article examining links between English-speaking Western cybercriminals and extremist networks engaged in harassment and extortion of minors. That reporting identified Judische as an Ontario-based software engineer with involvement in numerous data breaches and voice phishing schemes targeting American companies dating back to at least 2020. Canadian law enforcement apprehended Moucka on a U.S. provisional warrant roughly one month after this reporting.
Prosecutors allege that Moucka and his associates exploited their unauthorized access to obtain billions of sensitive customer records and extract terabytes of data. The stolen information encompassed "non-content call and text history records, banking and other financial information, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver's license numbers, passport numbers, social security numbers and other personally identifiable information." The conspirators then leveraged these records through extortion threats to publish the data publicly. Beyond targeting commercial victims, Moucka also intimidated government officials and security researchers involved in investigating his activities. The group obtained more than $2.5 million through ransom demands, and in at least one case, Moucka re-extorted a victim by threatening additional disclosure of previously stolen information.
The Justice Department noted that "Moucka used the stolen data of a government officer and members of a then-former government officer's immediate family in this re-extortion attempt."
Co-Conspirators

Cameron "Kiberphant0m" Wagenius, a U.S. Army soldier, represents one of Moucka's identified co-conspirators. Wagenius entered a guilty plea in July 2025 to extorting AT&T and Verizon for customer account information. Prior to Wagenius's arrest, KrebsOnSecurity published an investigation detailing Kiberphant0m's various Telegram and Discord accounts over time, documenting how the account operator claimed military service and assignment to South Korea. Wagenius also engaged in re-extortion of victims, and following Moucka's arrest, posted materials on hacker forums purporting to be AT&T call logs for then President-elect Donald Trump and then Vice President Kamala Harris, as well as schematics allegedly obtained from the U.S. National Security Agency. Wagenius faces sentencing on September 3, 2026, with potential penalties including a maximum 20 years for conspiracy to commit wire fraud, a maximum five years for extortion tied to computer fraud, and a mandatory consecutive two-year sentence for aggravated identity theft.
John Erin Binns, 26, serves as the third alleged co-conspirator. This American fugitive departed the United States following his indictment for participation in a 2021 T-Mobile breach that compromised personal data of at least 76 million customers. Operating under aliases including "IRDev" and "IntelSecrets," Binns had been detained in a Turkish prison according to sources familiar with the investigation, though he has since gained release and reappeared online. Those sources indicate Binns has recently obtained Turkish citizenship, which under Turkish law prevents his extradition to another nation.
Sentencing and Penalties

Moucka entered guilty pleas to four counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. His sentencing is scheduled for October 27. He faces a mandatory minimum two-year sentence on the aggravated identity theft charge and potential maximum penalties of 30 years on the remaining counts. The ultimate prison duration will be determined by the federal judge presiding over the case.
Source: Krebs on Security