# Canadian Threat Actor Pleads Guilty in Snowflake Extortions

> Connor Riley Moucka pleaded guilty to computer fraud and extortion involving 165 Snowflake client organizations and AT&T customer records.

- Published: 2026-08-07T02:10:26.000Z
- Severity: high
- Category: Threat Intel
- Tags: Credential Theft, Ransomware, Data Breach, Snowflake
- Author: Runtime Rebel Intel
- Primary source: https://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/
- Canonical: https://runtimerebel.com/blog/canadian-threat-actor-pleads-guilty-in-snowflake-extortions

## Key points

- Immediate impact: Over 165 organizations suffered major data thefts and subsequent extortions following cloud credential compromise.
- Affected systems: Snowflake cloud customer accounts lacking mandatory multi-factor authentication and AT&T customer records.
- Remediation: Enforce robust multi-factor authentication across all cloud accounts and eliminate reliance on single-factor authentication.

## Overview of the Snowflake Extortion Case

A 26-year-old Canadian national has entered a guilty plea to federal charges stemming from a massive campaign targeting cloud-hosted environments. According to [KrebsOnSecurity](https://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/), Connor Riley Moucka—previously known online by monikers such as "Judische" and "Waifu"—admitted to computer fraud, wire fraud, aggravated identity theft, and conspiracy. The campaign compromised data belonging to more than 165 organizations utilizing the cloud provider [Snowflake](https://www.snowflake.com/).

The admissions outline a multi-month operation spanning from February to October 2024. During this timeframe, the threat actors leveraged stolen login credentials to access cloud storage environments, exfiltrating terabytes of sensitive files and subsequently demanding ransom payments under threat of public data exposure.

## Technical Details and Attack Methodology

The primary [attack vector](/glossary#attack-vector) relied on harvesting valid user credentials rather than exploiting complex software zero-days. Attackers specifically hunted for enterprise accounts belonging to Snowflake customers that failed to enforce multi-factor authentication. By utilizing these exposed credentials, the conspirators accessed environments belonging to prominent brand names, including Ticketmaster, Advance Auto Parts, LendingTree, and Neiman Marcus.

### Scope of Stolen Data

The operation resulted in the theft of billions of sensitive records containing:

* Non-content call and text history records impacting over 100 million AT&T customers
* Banking and financial account details
* Personally identifiable information including passport numbers, driver's licenses, and social security numbers
* Drug Enforcement Administration (DEA) registration numbers

The Department of Justice noted that the conspirators amassed over $2.5 million in ransom payments. In certain instances, the threat actors engaged in re-extortion, leveraging stolen data belonging to government officials and their family members to pressure victims further.

## Co-Conspirators and Global Reach

Investigators identified multiple individuals operating alongside Moucka:

* **Cameron Wagenius**, operating as "Kiberphant0m," a U.S. Army soldier who admitted to extorting telecommunication providers and leaking high-profile call logs. Wagenius is scheduled for sentencing in September 2026.
* **John Erin Binns**, known as "IRDev" and "IntelSecrets," an American fugitive indicted for a prior breach at T-Mobile. Sources indicate Binns acquired Turkish citizenship to evade foreign extradition.

Moucka's sentencing is scheduled for October 27, where he faces mandatory minimum penalties for aggravated identity theft alongside potential decades-long imprisonment for remaining counts.

## Actionable Recommendations

Security teams managing cloud environments must prioritize foundational hygiene controls to prevent credential-based intrusions:

* **Mandate Multi-Factor Authentication:** Enforce [phishing](/glossary#phishing)-resistant multi-factor authentication across all administrative and user accounts without exception.
* **Credential Monitoring:** Implement continuous monitoring for exposed corporate credentials on [dark web](/glossary#dark-web) forums and underground messaging channels.
* **Access Governance:** Apply the principle of [least privilege](/glossary#least-privilege) to cloud data storage, ensuring that downstream systems only retain access to necessary operational data.

**Related:** [Snowflake Hacker Pleads Guilty: Analyzing the UNC5537 Data Breach](/blog/snowflake-hacker-pleads-guilty-analyzing-the-unc5537-data-breach), [Smoke#Screen RMM Takeover Campaign Targets Enterprise Networks](/blog/smoke-screen-rmm-takeover-campaign-targets-enterprise-networks)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/canadian-threat-actor-pleads-guilty-in-snowflake-extortions
