Canadian Man Pleads Guilty to Snowflake Hacks, AT&T Theft

A Canadian software engineer pleads guilty to one of the largest cloud data heists, affecting over 165 organizations and 100 million AT&T customers.

By Central
Connor Riley Moucka admitted to using stolen credentials to access Snowflake accounts and extort millions.
Highlights
  • The hackers exploited Snowflake accounts without multi-factor authentication to steal terabytes of data.
  • Moucka and his co-conspirators extorted over $2.5 million from victim organizations.
  • The AT&T breach exposed call and text records of more than 100 million customers.

In a case that underscores the escalating threat of cloud-based data theft, a 26-year-old Canadian software engineer once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers. The guilty plea, entered in a U.S. federal court, marks a significant milestone in one of the largest and most brazen data heists of the past decade, exposing critical vulnerabilities in enterprise cloud security and the shadowy networks that exploit them.

The Snowflake Breach: How Stolen Credentials and Missing MFA Enabled a Global Data Heist

Between February and October 2024, Moucka and his co-conspirators systematically targeted Snowflake customer accounts that had failed to enable multi-factor authentication (MFA). Using stolen login credentials—likely obtained through phishing, credential-stuffing attacks, or purchases from underground forums—the group gained unauthorized access to cloud-hosted data belonging to at least 165 organizations. The victims spanned multiple industries, including ticketing, automotive parts, retail, and financial services, with well-known companies such as TicketMaster, Lending Tree, Advance Auto Parts, and Neiman Marcus among those extorted. The hackers threatened to publish the stolen data unless ransom payments were made, collectively extracting over $2.5 million in illicit payments.

The scale of the data theft was staggering. According to the U.S. Department of Justice, Moucka and his associates downloaded terabytes of information containing billions of sensitive customer records. This included individuals’ non-content call and text history records, banking and other financial information, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, social security numbers, and other personally identifiable information. The AT&T data breach alone exposed the call and text records of more than 100 million customers, a violation that has drawn intense regulatory scrutiny and class-action litigation.

What specific vulnerability did the Snowflake hackers exploit?

The attackers targeted stolen credentials for Snowflake customer accounts that did not enforce multi-factor authentication (MFA). By logging in as legitimate users without the additional layer of security that MFA provides, the hackers could bypass basic authentication and access the data directly. Snowflake responded after the breaches by increasing password complexity requirements and enforcing MFA for all customer accounts, but the damage had already been done. This case serves as a stark reminder that cloud service providers are only as secure as the authentication practices of their customers.

From Software Engineer to Cybercriminal: The Dual Identity of “Judische” and “Waifu”

Moucka frequently adopted new nicknames—sometimes operating multiple identities concurrently—but two of his best-known monikers were “Judische” and “Waifu.” His role in the Snowflake data thefts was first documented by cybersecurity journalists in September 2024, in a story that explored the dark nexus between Western, English-speaking cybercriminals and extremist groups that harass and extort minors. That investigation identified Judische as a software engineer from Ontario who had been involved in numerous data breaches and voice phishing attacks against U.S. companies since at least 2020. A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States, acting on a surveillance photo taken just nine days before his capture.

The Justice Department revealed that Moucka also threatened and harassed government officials and security researchers who were helping to track him down. In one particularly troubling instance, he re-extorted a victim—a government officer—by threatening further disclosure of stolen data that included information about the officer’s immediate family members. This escalation from simple extortion to targeted harassment and intimidation highlights the profound personal risk that data breaches pose to individuals, not just corporations.

Who were Moucka’s co-conspirators?

Two other individuals have been identified as key co-conspirators in the scheme. Cameron “Kiberphant0m” Wagenius, a U.S. Army soldier, pleaded guilty in July 2025 to extorting AT&T and Verizon for their customer account data. Wagenius, who was stationed in South Korea during the period of his criminal activity, also re-extorted victims after Moucka’s arrest. Immediately following Moucka’s apprehension, Kiberphant0m posted on hacker forums what he claimed were the AT&T call logs for then President-elect Donald Trump and for then Vice President Kamala Harris, as well as schematics allegedly stolen from the U.S. National Security Agency (NSA). Wagenius is set to be sentenced on September 3, 2026, and faces a maximum penalty of 20 years in prison for conspiracy to commit wire fraud, five years for extortion in relation to computer fraud, and a mandatory two-year consecutive sentence for aggravated identity theft.

The third alleged co-conspirator is John Erin Binns, 26, an elusive American man who fled the United States after being indicted for his admitted role in a 2021 breach at T-Mobile that exposed the personal information of at least 76 million customers. Sources close to the investigation said Binns, also known as “IRDev” and “IntelSecrets,” was until recently incarcerated in a Turkish prison but has since been released and resurfaced online. Those sources added that Binns recently obtained Turkish citizenship, and under Turkish law a citizen cannot be extradited to a foreign country. This development complicates efforts to bring him to justice and underscores the international dimensions of modern cybercrime.

The Dark Nexus: Why Was Moucka Considered a Top Threat Actor of 2024?

Moucka’s activities were not limited to the Snowflake breaches. Authorities described him as one of the most consequential cybercrime threat actors of 2024 because of his ability to orchestrate large-scale data thefts across multiple sectors, his sophisticated use of multiple online identities to evade detection, and his willingness to harass both corporate victims and individual security researchers. His methods—targeting cloud environments with weak authentication, re-extorting victims, and leaking stolen data for maximum reputational damage—set a new standard for operational ruthlessness in the cybercriminal underground.

The case also highlighted the convergence of traditional financially motivated cybercrime with more sinister activities. The September 2024 investigation that first linked Moucka to the breaches also documented how he and other English-speaking threat actors were involved in extremist groups that harass and extort minors into self-harm. While Moucka’s guilty plea does not directly address those allegations, the broader pattern suggests a willingness to use any lever—financial, psychological, or reputational—to coerce compliance from victims.

What penalties does Connor Riley Moucka face?

Moucka pleaded guilty to four criminal counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. He is slated to be sentenced on October 27. The mandatory minimum penalty for aggravated identity theft is two years in prison, which must be served consecutively to any other sentence. On the remaining counts, he faces a maximum penalty of 30 years in prison. Ultimately, it will be up to the federal judge to determine how much time Moucka actually serves given his extensive cybercriminal rap sheet, the scale of the damage, and the degree of his cooperation with authorities. Given the precedent set by other high-profile cybercriminals, a sentence near the upper end of the range is possible, especially considering the re-extortion of a government official and the harassment of security researchers.

Broader Implications for Cloud Security and Data Privacy

The Snowflake case serves as a watershed moment for cloud service providers and enterprises that rely on them. It demonstrates that even the most advanced cloud platforms are vulnerable when customers fail to implement basic security measures like multi-factor authentication. Snowflake’s post-breach response—increasing password complexity and enforcing MFA—was necessary but reactive. Organizations must adopt a proactive stance: auditing all third-party integrations, enforcing MFA on every account, monitoring for unusual login patterns, and implementing data access controls that limit what even legitimate users can see and download.

The theft of AT&T call and text history records has also reignited debates about telecommunications data retention policies. While the content of calls and texts was not exposed (only metadata such as dates, times, and phone numbers), such metadata can still reveal sensitive information about individuals’ social networks, travel patterns, and personal relationships. The breach affected more than 100 million customers, making it one of the largest telecommunications data breaches in U.S. history. Calls for stricter data minimization practices—where companies retain only the data absolutely necessary for business operations—have grown louder.

How did the hackers extort over $2.5 million from victims?

The conspirators employed a classic double-extortion model: they first stole the data, then contacted victims with demands for payment in cryptocurrency. If a victim refused, the hackers threatened to publish the stolen data on the dark web or on public leak sites. In at least one instance, Moucka re-extorted a victim who had already paid, threatening further disclosure of new data he claimed to possess. This tactic increases psychological pressure on victims, who may fear that paying once does not guarantee the end of the attacks. The Justice Department noted that the conspirators made over $2.5 million in ransom payments, a figure that likely understates the total economic damage when accounting for business disruption, legal fees, and reputation repair.

The Geopolitical Angle: Binns, Turkey, and the Challenge of Extradition

The case of John Erin Binns illustrates a growing challenge in international cybercrime enforcement: identity shopping for citizenship. Binns, a U.S. citizen, fled to Turkey after the 2021 T-Mobile breach and, according to sources, recently obtained Turkish citizenship. Under Turkish law, a citizen cannot be extradited to a foreign country, effectively placing him beyond the reach of U.S. law enforcement. While Turkey has cooperated with the U.S. on some cases, the principle of non-extradition of citizens is a well-established legal doctrine in many countries. Binns’ case may force prosecutors to consider alternative approaches, such as diplomatic pressure, sanctions, or cooperation with Turkish authorities to prosecute him locally. This development highlights the need for international treaties that address cybercrime extradition more effectively, or for the U.S. to pursue prosecutions in safe-haven countries where the accused holds citizenship.

What Organizations Can Learn from the Snowflake and AT&T Breaches

For enterprises, the Moucka guilty plea is a reminder that cybercriminals are constantly scanning for low-hanging fruit—specifically, accounts with weak or no multi-factor authentication. Security leaders must implement a zero-trust architecture that assumes all credentials can be compromised. This means requiring MFA for every user, including service accounts and APIs; using conditional access policies that flag unusual login locations or devices; and deploying anomaly detection tools that can identify bulk data exfiltration in real time. Additionally, organizations should conduct regular security audits of their cloud service providers’ configurations and ensure that contracts include data protection responsibilities.

For individuals, the breaches involving AT&T and other companies underscore the importance of monitoring one’s own digital footprint. Consumers should regularly check for data breaches using services like Have I Been Pwned, consider freezing their credit, and be on alert for phishing attempts that might leverage stolen personal information. The exposure of social security numbers, passport numbers, and driver’s license details makes identity theft a real and immediate risk for millions of people.

A Forward-Looking Perspective on Cybercrime Enforcement

The guilty pleas of Moucka and Wagenius represent important wins for law enforcement, but the rapid evolution of cybercriminal tactics—especially the use of cloud-native attacks and the emergence of safe-havens for fugitives—means that the battle is far from over. The U.S. Justice Department’s ability to coordinate with Canadian authorities to arrest Moucka within weeks of his identification shows the value of international cooperation. However, the involvement of a U.S. Army soldier and the presence of a third conspirator now protected by Turkish citizenship reveal the porous boundaries between national security, military service, and cybercrime. As cloud adoption continues to grow and threat actors become more sophisticated, the onus falls on both companies and governments to harden defenses, close extradition loopholes, and ensure that the consequences for such devastating breaches are severe enough to deter future attackers.

Share This Article