Executive Overview
In a landmark development for cybersecurity enforcement, 26-year-old Canadian national Connor Riley Moucka has formally pleaded guilty to multiple federal charges, including computer fraud, wire fraud, aggravated identity theft, and conspiracy. Once identified by threat intelligence analysts as one of the most destructive and consequential cybercrime actors of 2024, Moucka admitted to orchestrating a massive hacking and extortion campaign that targeted more than 165 major organizations utilizing cloud storage provider Snowflake.
Operating under various online aliases—most notably “Judische” and “Waifu”—Moucka and an elite cell of co-conspirators systematically plundered terabytes of sensitive corporate and government data. Their operations compromised the digital perimeters of some of the world’s most recognizable brands, including Ticketmaster, LendingTree, Advance Auto Parts, and Neiman Marcus. Beyond the Snowflake breaches, Moucka’s digital trail intersected with some of the largest telecommunications hacks in recent history, including the large-scale theft of call and text history records belonging to more than 100 million AT&T customers.
The fallout from Moucka’s guilty plea highlights profound systemic vulnerabilities in corporate cloud security, particularly the failure to enforce mandatory multi-factor authentication (MFA). It also underscores the alarming convergence of sophisticated cybercrime syndicates, insider threats, and transnational underground networks. As Moucka awaits his sentencing hearing scheduled for October 27, federal prosecutors are preparing for a series of related trials involving high-profile co-conspirators whose digital audacity extended to targeting government officials, security researchers, and even high-ranking political figures.
Detailed Chronology of the 2024 Cloud Extortion Campaign
The catastrophic series of breaches that came to define the 2024 threat landscape did not begin in a vacuum. According to court documents filed by the U.S. Department of Justice (DOJ) and investigative reports by cybersecurity journalist Brian Krebs, Moucka’s criminal trajectory escalated dramatically between February and October 2024.
The Snowflake Intrusion Vector
Moucka and his associates leveraged a remarkably simple yet devastatingly effective attack vector. Rather than exploiting complex zero-day vulnerabilities within Snowflake’s core infrastructure, the threat actors capitalized on stale, leaked, or brute-forced corporate credentials. Specifically, they targeted Snowflake customer accounts that failed to enforce multi-factor authentication.
Once inside these improperly secured cloud environments, the actors utilized specialized scripts to download massive volumes of proprietary data. The stolen troves included banking and financial information, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver’s licenses, passports, and Social Security numbers.
Extortion and Re-Extortion Tactics
Armed with billions of sensitive records, the hackers systematically contacted corporate executives. They issued high-stakes ultimatums: pay a ransom in cryptocurrency or watch proprietary data leak publicly on underground hacker forums.
The DOJ revealed that Moucka’s operation amassed over $2.5 million in extortion payments. However, compliance with ransom demands rarely guaranteed safety. In a particularly brazen display of malice, Moucka engaged in "re-extortion"—a practice where victims who had already paid ransoms were targeted a second time with threats of further leaks. In at least one documented instance, Moucka utilized the stolen personal data of a government official and the official’s immediate family members to exert psychological pressure and demand additional payouts.

The Net Closes: Arrest and Extradition
Moucka’s identity as "Judische" first came to light in September 2024 through investigative reporting that linked English-speaking cybercriminals to extremist groups specializing in online harassment and swatting. Investigators discovered that Moucka, operating from Kitchener, Ontario, was a software engineer with a multi-year history of conducting data breaches and voice-phishing campaigns against U.S. enterprises.
Following the publication of these findings and coordinated intelligence-sharing between American and Canadian law enforcement, the Royal Canadian Mounted Police (RCMP) arrested Moucka on October 30, 2024, acting on a provisional arrest warrant issued by the United States. A surveillance photo captured by the RCMP just nine days prior to his arrest depicts a calm, unassuming young man completely unaware that federal nets were rapidly closing around him.
The Co-Conspirators: A Transnational Web of Threat Actors
Moucka did not operate alone. The sprawling criminal enterprise relied on a tightly knit, highly specialized network of global co-conspirators who brought distinct capabilities to the syndicate.
+-------------------------------------------------------------------------+
| THE SNOWFLAKE CYBERCRIME CELL |
+-------------------------------------------------------------------------+
| | |
v v v
+---------------+ +-----------------+ +-----------------+
| Connor Moucka | | Cameron Wagenius| | John Erin Binns |
| (a.k.a. | | (a.k.a. | | (a.k.a. |
| Judische/ | | Kiberphant0m) | | IRDev/ |
| Waifu) | | | | IntelSecrets) |
+---------------+ +-----------------+ +-----------------+
| - Canadian | | - U.S. Army | | - American |
| national | | soldier | | fugitive |
| - Pleaded | | - Pleaded | | - Indicted in |
| guilty to | | guilty to | | 2021 T-Mobile |
| fraud, | | extortion, | | breach |
| conspiracy, | | wire fraud, | | - Residing in |
| identity | | identity | | Turkey with |
| theft | | theft | | citizenship |
+---------------+ +-----------------+ +-----------------+
Cameron "Kiberphant0m" Wagenius
One of Moucka’s primary co-conspirators was Cameron Wagenius, an active-duty U.S. Army soldier stationed in South Korea who operated under the handle "Kiberphant0m." Wagenius pleaded guilty in July 2025 to charges stemming from his role in extorting major telecommunications providers, including AT&T and Verizon.
Wagenius’s digital footprint was exposed after investigators tracked his activities across various Telegram and Discord channels. True to the syndicate’s aggressive nature, Wagenius also engaged in re-extortion. Immediately following Moucka’s arrest in late 2024, Wagenius posted what he claimed were AT&T call logs belonging to high-profile political figures—including then-President-elect Donald Trump and then-Vice President Kamala Harris—alongside schematics allegedly stolen from the U.S. National Security Agency (NSA). Wagenius faces up to 20 years for wire fraud, five years for extortion, and a mandatory consecutive two-year sentence for aggravated identity theft, with his sentencing scheduled for September 3, 2026.
John Erin Binns ("IRDev")
The third major figure tied to the broader infrastructure of these high-level data thefts is 26-year-old American fugitive John Erin Binns. Indicted for his central role in the massive 2021 T-Mobile breach that exposed the personal data of at least 76 million customers, Binns has managed to evade direct U.S. custody.
According to intelligence sources, Binns—known online as "IRDev" and "IntelSecrets"—was briefly incarcerated in a Turkish prison before being released. During his time abroad, Binns acquired Turkish citizenship. Under Turkish constitutional law, citizens cannot be extradited to foreign jurisdictions, rendering him largely insulated from direct U.S. prosecution unless he travels outside Turkey’s borders.
Supporting Context, Metrics, and Technological Impact
The breadth of the Snowflake and AT&T breaches places Moucka’s syndicate among the most destructive threat groups in modern corporate history.

- 165+ Organizations Impacted: Snowflake enterprise customers across retail, entertainment, financial services, and software sectors were forced to conduct costly incident responses, forensic investigations, and legal notifications.
- 100 Million+ AT&T Records: The unauthorized exfiltration of non-content call and text history logs exposed nearly the entire subscriber base of a primary North American telecommunications carrier.
- $2.5 Million in Extortion Proceeds: Documented cryptocurrency transfers demonstrate the immediate financial yield of the conspiracy, though indirect costs—including plunging stock values, regulatory fines, and remediation expenditures—run into the hundreds of millions of dollars.
- The MFA Imperative: The attacks served as a harsh wake-up call for the cloud computing industry. In response to the wave of compromises, Snowflake drastically overhauled its security posture, implementing mandatory multi-factor authentication for all user accounts and enforcing stricter password complexity benchmarks.
Official Statements and Legal Ramifications
The conclusion of Moucka’s guilty plea hearing brought stern warnings from federal prosecutors regarding the evolving nature of cybercrime, which increasingly bridges the gap between financial extortion and national security threats.
"Connor Riley Moucka utilized sophisticated hacking techniques, stolen credentials, and ruthless extortion tactics to target American corporations, government infrastructure, and private citizens," prosecutors noted in official court filings. "The severity of his actions—ranging from the industrial-scale theft of cloud-hosted data to the targeted harassment of public officials—demands a significant and uncompromising federal penalty."
Moucka pleaded guilty to four distinct criminal counts:
- Conspiracy to commit computer fraud and wire fraud
- Computer fraud
- Wire fraud
- Aggravated identity theft
He faces a mandatory minimum sentence of two years in federal prison for the aggravated identity theft charge, to be served consecutively with any penalty handed down for the remaining counts. With a maximum potential prison sentence of 30 years across all counts, the final determination rests entirely with the presiding federal judge during the October 27 sentencing hearing.
Future Outlook: Lessons for Enterprise Security
The guilty plea of Connor Riley Moucka closes a major chapter in the saga of the 2024 cloud extortions, but the broader cybersecurity landscape remains fraught with persistent threats.
The case offers three critical takeaways for enterprise risk management:
- Mandatory MFA is Non-Negotiable: The root cause of the Snowflake breaches was not a software vulnerability in the cloud platform itself, but rather the human element and lax administrative configurations. Organizations must mandate phishing-resistant multi-factor authentication across all enterprise tiers, leaving zero administrative or user accounts unverified.
- The Insider Threat Matrix: The involvement of active-duty military personnel like Cameron Wagenius demonstrates that state-bound defense personnel and corporate contractors remain vulnerable to radicalization and financial exploitation within underground hacker channels.
- Geopolitical Safe Havens: The case of John Erin Binns highlights the enduring challenge of international law enforcement. Cybercriminals who successfully secure citizenship in non-extradition nations can effectively operate with impunity, requiring intelligence agencies to rely on covert disruption tactics rather than traditional extradition treaties.
As federal courts prepare to sentence Moucka in October and Wagenius in September 2026, the digital underground is watching closely. While these prosecutions signal a decisive victory for transnational law enforcement, they also serve as a stark reminder of the perpetual vigilance required to safeguard the global digital infrastructure.
