Canadian Cybercriminal Connor Riley Moucka Pleads Guilty to Massive Snowflake Extortion and Data Theft Scheme

Connor Riley Moucka, a 26-year-old software engineer from Kitchener, Ontario, has officially entered a guilty plea in U.S. federal court, marking a definitive conclusion to one of the most high-profile cybercrime investigations of 2024. Once known in the digital underground by the monikers “Judische” and “Waifu,” Moucka stood at the center of a sophisticated campaign that compromised the cloud infrastructure of Snowflake, a major U.S.-based software-as-a-service provider. His criminal activities, which spanned from February to October 2024, resulted in the unauthorized access of data belonging to at least 165 corporate organizations and the theft of sensitive personal information from over 100 million AT&T customers.
The scope of Moucka’s operations was vast, involving the systematic exploitation of stolen login credentials to infiltrate customer accounts that failed to enforce multi-factor authentication (MFA). By bypassing these security hurdles, Moucka and his co-conspirators were able to exfiltrate terabytes of proprietary data, including banking information, Social Security numbers, passport records, and Drug Enforcement Administration (DEA) registration numbers.
A Chronology of the Breach and Escalation
The timeline of Moucka’s descent into high-stakes digital extortion began in earnest in early 2024. Between February and October, he operated under a shroud of shifting digital identities, often maintaining multiple personas simultaneously to evade detection.
- February 2024: The commencement of the Snowflake intrusion campaign, targeting companies that utilized the cloud provider without robust MFA protocols.
- September 2024: KrebsOnSecurity published a pivotal investigative report identifying “Judische” as a Canadian software engineer linked to extremist groups and targeted harassment campaigns. This report provided the first public link between the Snowflake breaches and a known malicious actor.
- October 2024: Canadian law enforcement authorities, acting on a provisional warrant issued by the United States, arrested Moucka in Ontario. A surveillance photograph taken just nine days prior to his apprehension depicted a man seemingly unaware of the closing investigative net.
- July 2025: Cameron “Kiberphant0m” Wagenius, a U.S. Army soldier, pleaded guilty to his role in the extortion scheme, specifically regarding the telecommunications data thefts.
- October 2027 (Upcoming): Moucka is scheduled for sentencing, where he faces a mandatory minimum of two years for aggravated identity theft and a maximum of 30 years for wire fraud and computer fraud charges.
The Triad of Co-Conspirators
Moucka’s criminal enterprise was not a solo endeavor. The U.S. Department of Justice has outlined a collaborative structure involving at least two other prominent figures in the cybercriminal landscape.

Cameron Wagenius, a U.S. Army soldier stationed in South Korea, emerged as a key associate. Known as “Kiberphant0m,” Wagenius utilized his position to facilitate the theft and extortion of data from major telecommunications firms. His activities became increasingly brazen; following Moucka’s arrest, Wagenius reportedly posted what he claimed to be the call logs of then-President-elect Donald Trump and Vice President Kamala Harris on various hacker forums. His sentencing is set for September 3, 2026, where he faces severe penalties, including a potential 20-year prison term for wire fraud.
The third individual named in the investigative files is John Erin Binns, 26, also known as “IRDev” and “IntelSecrets.” Binns is a veteran of the cybercrime world, previously indicted for his involvement in the 2021 T-Mobile data breach that exposed the personal information of 76 million people. According to sources close to the investigation, Binns recently obtained Turkish citizenship. This development has created a significant legal hurdle, as Turkish law generally prohibits the extradition of its citizens to foreign nations, effectively shielding him from U.S. prosecution for the time being.
Corporate and Government Impact
The fallout from the Snowflake breach forced a rapid reevaluation of security standards across the industry. Major corporations, including TicketMaster, Lending Tree, Advance Auto Parts, and Neiman Marcus, found themselves at the mercy of the hackers, who threatened to publish stolen data unless exorbitant ransom demands were met. The U.S. Justice Department confirmed that the conspirators successfully extorted over $2.5 million in payments from their victims.
The severity of the crimes reached a new level when the conspirators turned their focus toward those attempting to stop them. In a move that shocked investigators, Moucka engaged in “re-extortion”—a tactic where a victim is pressured to pay additional funds even after an initial ransom is met, under the threat of further leaks. In one instance, Moucka utilized the stolen personal data of a government official and their immediate family members to force compliance.
Snowflake, for its part, responded to the crisis by mandating stricter password complexity requirements and enforcing universal multi-factor authentication for its clients. The incident serves as a stark reminder that even enterprise-grade cloud solutions are vulnerable when user-side security practices remain lax.

Analysis of the Threat Landscape
The case of Moucka and his cohorts highlights a disturbing trend in modern cybercrime: the convergence of professional hacking, extortion, and targeted psychological warfare. Unlike traditional state-sponsored actors who may seek to influence geopolitics, this group was driven primarily by financial gain and, at times, a desire to harass and intimidate.
The ease with which these individuals were able to move between identities and cross borders suggests a highly fragmented international law enforcement environment. While the arrest of Moucka represents a significant victory for the Royal Canadian Mounted Police and the U.S. Department of Justice, the continued freedom of individuals like Binns underscores the challenges of global digital policing.
Furthermore, the involvement of a U.S. soldier in these activities raises serious questions about internal vetting and the security of military personnel who may possess the technical skills required for advanced cyber-operations. The use of stolen DEA registration numbers and NSA schematics as leverage in negotiations also points to an increasing overlap between criminal data theft and the potential compromise of national security infrastructure.
Legal Implications and Sentencing Outlook
As Moucka prepares for his October sentencing, the legal community is watching closely to see how the court balances the sheer scale of the harm caused against the defendant’s cooperation or lack thereof. With a mandatory two-year term for identity theft already on the table, the presiding judge has the discretion to impose a sentence up to 30 years for the remaining charges.
This case is widely expected to serve as a bellwether for how U.S. courts handle international cyber-extortion cases moving forward. The combination of high-volume data theft and the weaponization of personal information against government officials has set a high bar for sentencing severity. For organizations, the lesson remains clear: the absence of multi-factor authentication is not merely a technical oversight—it is a critical vulnerability that can be leveraged by a motivated attacker to compromise millions of lives and destabilize corporate operations on a global scale. As digital threats evolve, the transition from reactive security to proactive, zero-trust architectures has become a requirement for survival in the digital economy.







