A 26-year-old Canadian man, Connor Riley Moucka of Kitchener, Ontario, has pleaded guilty to computer fraud and conspiracy charges related to hacking and extorting over 165 organizations that utilized the cloud provider Snowflake. Moucka, known by online monikers such as "Judische" and "Waifu," also admitted to stealing call and text history records belonging to more than 100 million AT&T customers.
According to the U.S. Justice Department, Moucka and his co-conspirators used stolen login credentials to access cloud-hosted data from at least 165 Snowflake customers between February and October 2024. The attackers specifically targeted accounts that lacked multi-factor authentication (MFA). Companies affected by these data thefts and subsequent extortion attempts included TicketMaster, Lending Tree, Advance Auto Parts, and Neiman Marcus. Snowflake responded to the incidents by implementing stricter password complexity requirements and enforcing MFA for its users.
The conspirators are reported to have stolen billions of sensitive customer records and terabytes of information, encompassing non-content call and text histories, banking details, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver’s license and passport numbers, Social Security numbers, and other personally identifiable information. They then threatened to publish this data online unless ransoms were paid. The Justice Department stated that over $2.5 million was collected in ransom payments. In one instance, Moucka re-extorted a victim, threatening further data disclosure and using stolen information belonging to a government officer and their family members.
Moucka also engaged in harassment and threats against government officials and security researchers involved in tracking his activities. His admitted involvement in the Snowflake breaches was initially reported in September 2024, identifying him as a software engineer from Ontario with a history of data breaches and voice phishing attacks against U.S. companies since at least 2020. Canadian authorities arrested Moucka in October 2024 based on a provisional U.S. warrant.
One of Moucka's admitted co-conspirators is Cameron Wagenius, an active-duty U.S. Army soldier also known as "Kiberphant0m." Wagenius pleaded guilty in July 2025 to extorting AT&T and Verizon for customer account data. Following Moucka's arrest, Wagenius allegedly posted what he claimed were AT&T call logs for then President-elect Donald Trump and then Vice President Kamala Harris, as well as schematics purportedly stolen from the U.S. National Security Agency (NSA), on hacker forums. Wagenius is scheduled for sentencing on September 3, 2026, and faces a maximum of 20 years for conspiracy to commit wire fraud, five years for extortion related to computer fraud, and a mandatory two-year consecutive sentence for aggravated identity theft.
A third alleged co-conspirator is John Erin Binns, 26, an American who fled the U.S. after being indicted for his role in a 2021 T-Mobile breach that exposed data for 76 million customers. Binns, also known as "IRDev" and "IntelSecrets," was reportedly incarcerated in Turkey but has since been released and resurfaced online. Sources indicate Binns recently obtained Turkish citizenship, which could prevent his extradition to the U.S.
Moucka pleaded guilty to four criminal counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. He faces a mandatory minimum of two years in prison for aggravated identity theft and a maximum of 30 years for the remaining counts. His sentencing is set for October 27.






