Skip to main content

Canadian Man Pleads Guilty in Snowflake Extortions

0
Low
Published: 08/06/2026 (08/06/2026, 17:00:56 UTC)
Source: Krebs on Security

Description

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud provider Snowflake . Connor Riley Moucka , of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers. A surveillance photo of Connor Riley Moucka, a.k.a. “Judische” and “Waifu,” dated Oct 21, 2024, 9 days before Moucka’s arrest. This image was included in an affidavit filed by an investigator with the Royal Canadian Mounted Police (RCMP). The U.S. Justice Department said between February and October 2024, Moucka and co-conspirators used stolen login credentials to steal cloud-hosted data belonging to at least 165 customers of a U.S.-based software-as-a-service company. The hackers targeted stolen credentials for Snowflake customer accounts that did not enforce multi-factor authentication, and extorted or attempted to extort a host of well-known companies, including TicketMaster, Lending Tree, Advance Auto Parts and Neiman Marcus. Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication. Moucka adopted new nicknames frequently — sometimes operating multiple identities concurrently — but two of his best-known monikers were “ Judische ” and “ Waifu .” Judische’s admitted role in the Snowflake data thefts was first documented by KrebsOnSecurity in a September 2024 story about the overlap between Western, English-speaking cybercriminals and extremist groups that harass and extort minors into harming themselves or others. That September 2024 story identified Judische as a software engineer from Ontario who has been involved in numerous data breaches and voice phishing attacks against U.S. companies since at least 2020. A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States. The government says Moucka and others used their unauthorized access to steal billions of sensitive customer records and download terabytes of information, “including individuals’ non-content call and text history records, banking and other financial information, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, social security numbers and other personally identifiable information. They then extorted victims by threatening to publish data online.” Moucka also threatened and harassed government officials and security researchers who were helping to track him down. The Justice Department said the conspirators made over $2.5 million in ransom payments, and that in at least one instance, Moucka re-extorted a victim with threats of further disclosure of the victim’s stolen data. “Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” reads a statement from the Justice Department. One of Moucka’s admitted co-conspirators is Cameron “Kiberphant0m” Wagenius , a U.S. Army soldier who pleaded guilty in July 2025 to extorting AT&T and Verizon for their customer account data. Less than a month before Wagenius’s arrest, KrebsOnSecurity published a deep dive into Kiberphant0m’s various Telegram and Discord identities over the years, revealing how the owner of the accounts told others they were in the Army and stationed in South Korea. One of several selfies on the Facebook page of Cameron Wagenius. Kiberphant0m also re-extorted victims. Immediately following Moucka’s arrest, Kiberphant0m posted on hacker forums what he claimed were the AT&T call logs for then President-elect Donald Trump and for then Vice President Kamala Harris, as well schematics allegedly stolen from the U.S. National Security Agency (NSA). Wagenius is set to be sentenced on September 3, 2026. The government says he faces a maxim…

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 20:38:55 UTC

Technical Analysis

Between February and October 2024, Connor Riley Moucka and co-conspirators exploited stolen login credentials to access and steal data from at least 165 Snowflake customer accounts that did not enforce multi-factor authentication. The stolen data included billions of sensitive records such as call and text histories, financial and government identifiers, and personally identifiable information. The group extorted victims by threatening to publish stolen data, generating over $2.5 million in ransom payments. Snowflake mitigated the threat by increasing password complexity requirements and enforcing multi-factor authentication. Moucka operated under multiple aliases and was arrested in late 2024. His activities also involved harassment of government officials and security researchers. A co-conspirator, Cameron Wagenius, a U.S. Army soldier, pleaded guilty to similar extortion crimes.

Potential Impact

The threat actors compromised sensitive data of over 165 organizations using Snowflake cloud services, including personal, financial, and government-related information of millions of individuals. The extortion caused financial losses exceeding $2.5 million in ransom payments. The exposure of sensitive data posed risks to privacy and security of affected individuals and organizations. The attacks exploited weak security controls such as lack of multi-factor authentication on cloud accounts. The harassment of officials and researchers further complicated incident response efforts.

Defensive Guidance

Snowflake has responded by enforcing multi-factor authentication and increasing password complexity requirements for customer accounts, effectively mitigating the vulnerability exploited in these attacks. Organizations using Snowflake should ensure multi-factor authentication is enabled and follow Snowflake's updated security policies. No additional immediate actions are indicated beyond adherence to these enforced security controls.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.67,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/","fetched":true,"fetchedAt":"2026-08-06T17:09:10.587Z","wordCount":977}

Threat ID: 6a74bfb6bf8831d53903c87f

Added to database: 08/06/2026, 17:09:10 UTC

Last enriched: 08/13/2026, 20:38:55 UTC

Last updated: 09/18/2026, 16:11:07 UTC

Views: 86

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses