{"id":26117,"date":"2026-09-18T10:12:39","date_gmt":"2026-09-18T18:12:39","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/18\/canadian-man-pleads-guilty-in-snowflake-extortions\/"},"modified":"2026-09-18T10:12:39","modified_gmt":"2026-09-18T18:12:39","slug":"canadian-man-pleads-guilty-in-snowflake-extortions","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/18\/canadian-man-pleads-guilty-in-snowflake-extortions\/","title":{"rendered":"Canadian Man Pleads Guilty in Snowflake Extortions"},"content":{"rendered":"<p>A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud provider <strong>Snowflake<\/strong>. <strong>Connor Riley Moucka<\/strong>, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&#038;T customers.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_69625\" style=\"width: 759px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-69625\" height=\"575\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2024\/11\/moucka-surveillance.png\" width=\"749\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-69625\">A surveillance photo of Connor Riley Moucka, a.k.a. \u201cJudische\u201d and \u201cWaifu,\u201d dated Oct 21, 2024, 9 days before Moucka\u2019s arrest. This image was included in an affidavit filed by an investigator with the Royal Canadian Mounted Police (RCMP).<\/p>\n<\/div>\n<p>The U.S. Justice Department said between February and October 2024, Moucka and co-conspirators used stolen login credentials to steal cloud-hosted data belonging to at least 165 customers of a U.S.-based software-as-a-service company.<\/p>\n<p>The hackers targeted stolen credentials for Snowflake customer accounts that did not enforce multi-factor authentication, and extorted or attempted to extort a host of well-known companies, including TicketMaster, Lending Tree, Advance Auto Parts and Neiman Marcus. Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.<\/p>\n<p>Moucka adopted new nicknames frequently \u2014 sometimes operating multiple identities concurrently \u2014 but two of his best-known monikers were \u201c<strong>Judische<\/strong>\u201d and \u201c<strong>Waifu<\/strong>.\u201d Judische\u2019s admitted role in the Snowflake data thefts was first documented by KrebsOnSecurity in <a href=\"https:\/\/krebsonsecurity.com\/2024\/09\/the-dark-nexus-between-harm-groups-and-the-com\" rel=\"noopener\" target=\"_blank\">a September 2024 story<\/a> about the overlap between Western, English-speaking cybercriminals and extremist groups that harass and extort minors into harming themselves or others.<\/p>\n<p>That September 2024 story identified Judische as a software engineer from Ontario who has been involved in numerous data breaches and voice phishing attacks against U.S. companies since at least 2020. A little more than a month later, Canadian authorities <a href=\"https:\/\/krebsonsecurity.com\/2024\/11\/canadian-man-arrested-in-snowflake-data-extortions\/\" rel=\"noopener\" target=\"_blank\">arrested Moucka<\/a> on a provisional warrant from the United States.<\/p>\n<p>The government says Moucka and others used their unauthorized access to steal billions of sensitive customer records and download terabytes of information, \u201cincluding individuals\u2019 non-content call and text history records, banking and other financial information, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver\u2019s license numbers, passport numbers, social security numbers and other personally identifiable information. They then extorted victims by threatening to publish data online.\u201d<\/p>\n<p>Moucka also threatened and harassed government officials and security researchers who were helping to track him down. The Justice Department said the conspirators made over $2.5 million in ransom payments, and that in at least one instance, Moucka re-extorted a victim with threats of further disclosure of the victim\u2019s stolen data.<\/p>\n<p>\u201cMoucka used the stolen data of a government officer and members of a then-former government officer\u2019s immediate family in this re-extortion attempt,\u201d reads <a href=\"https:\/\/www.justice.gov\/opa\/pr\/canadian-man-pleads-guilty-hacking-us-cloud-storage-provider-and-extorting-its-customers\" rel=\"noopener\" target=\"_blank\">a statement<\/a> from the Justice Department.<span id=\"more-74093\"><\/span><\/p>\n<p>One of Moucka\u2019s admitted co-conspirators is <strong>Cameron \u201cKiberphant0m\u201d Wagenius<\/strong>, a U.S. Army soldier who <a href=\"https:\/\/www.justice.gov\/opa\/pr\/former-us-soldier-pleads-guilty-hacking-and-extortion-scheme-involving-telecommunications\" rel=\"noopener\" target=\"_blank\">pleaded guilty in July 2025<\/a> to extorting AT&#038;T and Verizon for their customer account data. Less than a month before Wagenius\u2019s arrest, KrebsOnSecurity published\u00a0<a href=\"https:\/\/krebsonsecurity.com\/2024\/11\/hacker-in-snowflake-extortions-may-be-a-u-s-soldier\/\" rel=\"noopener\" target=\"_blank\">a deep dive<\/a>\u00a0into Kiberphant0m\u2019s various Telegram and Discord identities over the years, revealing how the owner of the accounts told others they were in the Army and stationed in South Korea.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_69974\" style=\"width: 758px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-69974\" height=\"741\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2024\/12\/camwagenius-selfie.png\" width=\"748\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-69974\">One of several selfies on the Facebook page of Cameron Wagenius.<\/p>\n<\/div>\n<p>Kiberphant0m also re-extorted victims. Immediately following Moucka\u2019s arrest, Kiberphant0m posted on hacker forums what he claimed were the AT&#038;T call logs for then President-elect Donald Trump and for then Vice President Kamala Harris, as well schematics allegedly stolen from the U.S. National Security Agency (NSA).<\/p>\n<p>Wagenius is set to be sentenced on September 3, 2026. The government says he faces a maximum penalty of 20 years in prison for conspiracy to commit wire fraud, a maximum penalty of five years in prison for extortion in relation to computer fraud, and a mandatory two-year sentence consecutive to any other prison time for aggravated identity theft.<\/p>\n<p>The third alleged co-conspirator is <strong>John Erin Binns<\/strong>, 26, an elusive American man who fled the United States after being indicted for his admitted role in <a href=\"https:\/\/krebsonsecurity.com\/2021\/08\/t-mobile-investigating-claims-of-massive-data-breach\/\" rel=\"noopener\" target=\"_blank\">a 2021 breach at T-Mobile<\/a> that exposed the personal information of at least 76 million customers.<\/p>\n<p>Sources close to the investigation said Binns, also known as \u201c<strong>IRDev<\/strong>\u201d and \u201c<strong>IntelSecrets<\/strong>,\u201d was until recently incarcerated in a Turkish prison, but that he has since been released and has resurfaced online. Those sources said Binns also recently obtained Turkish citizenship, and under Turkish law a citizen cannot be extradited to a foreign country.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_68097\" style=\"width: 568px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"size-full wp-image-68097\" height=\"399\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2024\/07\/binnspassport.png\" width=\"558\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-68097\">An image of a passport that Binns shared in an email to KrebsOnSecurity in Feb. 2023.<\/p>\n<\/div>\n<p>Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy. He is slated to be sentenced on Oct. 27 and faces a mandatory minimum penalty of two years in prison on the aggravated identity theft count, as well as a maximum penalty of 30 years in prison on the remaining counts. Ultimately, it will be up the federal judge how much time Moucka actually serves for his extensive cybercriminal rap sheet.<\/p>\n<p>For an interview with Moucka prior to his arrest and a deeper look at Binns, see <a href=\"https:\/\/krebsonsecurity.com\/2024\/11\/canadian-man-arrested-in-snowflake-data-extortions\/\" rel=\"noopener\" target=\"_blank\">our original report on Moucka\u2019s arrest<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&#038;T customers.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,32701],"tags":[28477,16740,29556,32765,17600,30064,32743,32752,32720,32338,31554,32702,30119,32739,31556,28752,32753,32754,16695,32759,32721,32258,32722,17774,32103,24608,32766,32767,32768,32769,32744,32745,32708,32709,32746,32710,32711,32713,32723,11740,32714,31558,24613,32747,32724,32725,11638,32726,32740,11869,28567,31016,11863,32755,32715,21409,32716,31561,30434,22313,32104,19277,32105,14947,32770,32717,32106,32760,31895,32056,32748,32718,16888,32761,32703,32704,22255,32749,32712,16696,22836,32750,31157,31158,19013,32727,32771,32772,32728,32756,32705,31162,31163,32729,32741,32719,31164,31030,32706,3765,15227,22691,27009,32730,32731,32732,8223,32751,20501,17220,32733,32734,31492,32762,26016,32735,32736,20502,32737,17061,16936,11884,32763,31636,32742,31564,32707,32757,31911,17006,32764,32773,17091,32738,28020,32758],"class_list":["post-26117","post","type-post","status-publish","format-standard","hentry","category-independent","category-kreb","tag-1password","tag-a-little-sunshine","tag-action1","tag-active-directory-federation-services","tag-adblock","tag-adblock-plus","tag-afd-sys","tag-ai-digital-humans","tag-aikido-security","tag-alfa-bank","tag-andtop-company","tag-atlas-data-privacy","tag-automox","tag-between-digital","tag-bitseller-expert-limited","tag-bitsight","tag-bitsight-trace","tag-blockly","tag-breadcrumbs","tag-bright-data","tag-bulkdmt","tag-cameron-john-wagenius","tag-charlie-eriksen","tag-chris-goettl","tag-connor-riley-moucka","tag-constella-intelligence","tag-cve-2026-48561","tag-cve-2026-50661","tag-cve-2026-56155","tag-cve-2026-56164","tag-cve-2026-62832","tag-cve-2026-68820","tag-cve-2026-69730","tag-cve-2026-69829","tag-cve-2026-72971","tag-cve-2026-81963","tag-cve-2026-85880","tag-cybera","tag-cybercats","tag-data-breaches","tag-decryptads","tag-dmitry-lubarsky","tag-domaintools","tag-ed-skoudis","tag-ellis","tag-epieos","tag-exploit","tag-express","tag-fengwo-group","tag-flashpoint","tag-fortra","tag-gary-norden","tag-github","tag-h96","tag-hertz","tag-huawei","tag-idscan-net","tag-igor-lubarsky","tag-infoblox","tag-intel-471","tag-intelsecrets","tag-internet-of-things-iot","tag-irdev","tag-ivanti","tag-jack-bicer","tag-jillian-kossman","tag-john-erin-binns","tag-john-taylor","tag-judische","tag-justin-sherman","tag-landon-miles","tag-larry-baldwin","tag-latest-warnings","tag-lg-electronics-usa","tag-lifetime-value-company","tag-matt-adkisson","tag-microsoft-corp","tag-microsoft-patch-tuesday-august-2026","tag-microsoft-patch-tuesday-september-2026","tag-neer-do-well-news","tag-nexus","tag-nightmare-eclipse","tag-numberguru","tag-onerep","tag-opera","tag-opsec-express","tag-patch-tuesday-july-2026","tag-pavan-davuluri","tag-pcpcats","tag-pedro-fale","tag-pem-law","tag-peoplelooker","tag-peoplesmart","tag-persy_pcp","tag-pi-hole","tag-planet13","tag-radaris","tag-radaris-com","tag-raj-parikh","tag-ransomware","tag-raspberry-pi","tag-residential-proxies","tag-residential-proxy","tag-ruben-thomson","tag-rubensecurecomputing-au","tag-rubenthomson-com","tag-samsung","tag-sans-technology-institute","tag-satnam-narang","tag-security-tools","tag-sheepstealinggmail-com","tag-shitstickppgmail-com","tag-snowflake","tag-spur","tag-spycloud","tag-surfinup8gmail-com","tag-teampcp","tag-tenable","tag-tensor-industries","tag-the-coming-storm","tag-time-to-patch","tag-tizen","tag-trevor-sutter","tag-tyler-reguly","tag-ublock-origin","tag-val-gurvits","tag-victor-worms","tag-vivo","tag-waifu","tag-web-fraud-2-0","tag-webos","tag-windows-bitlocker","tag-xiaomi","tag-yolosolo17gmail-com","tag-zach-edwards","tag-zhejiang-fengwo-iot-technology-ltd"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26117","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26117"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26117\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26117"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26117"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26117"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}