Canadian Man Pleads Guilty in Snowflake-Linked Data Extortion Case

Connor Riley Moucka, a 26-year-old man from Kitchener, Ontario, has pleaded guilty in the United States to charges stemming from a campaign that allegedly targeted more than 165 organizations using Sn...

Connor Riley Moucka, a 26-year-old man from Kitchener, Ontario, has pleaded guilty in the United States to charges stemming from a campaign that allegedly targeted more than 165 organizations using Snowflake cloud accounts.

According to the U.S. Department of Justice, Moucka and other conspirators accessed Snowflake customer environments between February and October 2024 using stolen credentials. The targeted accounts reportedly lacked multifactor authentication. The group allegedly copied large volumes of data and threatened to release it unless victims paid.

Companies identified by investigators as targets included Ticketmaster, LendingTree, Advance Auto Parts and Neiman Marcus. The Justice Department said the stolen information included financial and payroll records, government registration details, driver’s license and passport numbers, Social Security numbers, and other personal data. The attackers are also accused of obtaining non-content call and text records associated with more than 100 million AT&T customers.

Prosecutors said the conspirators received more than $2.5 million in ransom payments. In at least one case, Moucka allegedly demanded additional payment after using previously stolen information to threaten a victim again. Authorities also accused him of harassing government personnel and security researchers involved in investigating the activity.

Moucka, who used online aliases including “Judische” and “Waifu,” entered guilty pleas to computer fraud, wire fraud, aggravated identity theft and conspiracy. He is scheduled to be sentenced on October 27. The identity-theft conviction carries a mandatory minimum two-year prison term, while the other charges carry maximum penalties of up to 30 years, subject to the court’s decision and applicable sentencing rules.

Other alleged participants

The case also involves Cameron “Kiberphant0m” Wagenius, a U.S. Army soldier who pleaded guilty in 2025 to charges related to extortion involving AT&T and Verizon customer data. His sentencing is scheduled for September 3, 2026.

Authorities have also linked John Erin Binns, known online as “IRDev” and “IntelSecrets,” to the broader investigation. Binns was previously indicted in connection with the 2021 T-Mobile breach, although the supplied account says he has not been extradited from Turkey.

Snowflake responded to the 2024 incidents by strengthening password requirements and expanding multifactor-authentication enforcement. The case highlights the risks of compromised credentials, particularly where cloud accounts lack phishing-resistant authentication controls.