
A 26-year-old man from Kitchener, Ontario has pleaded guilty to orchestrating one of the largest corporate data breaches in recent memory, admitting he hacked into a U.S.-based cloud storage provider's customer accounts and extorted victims for millions of dollars. Connor Riley Moucka downloaded terabytes of information and stole billions of sensitive customer records after compromising more than 165 victim organizations, according to a U.S. Department of Justice press release announcing the plea.
The unnamed cloud storage provider referenced in the federal press release is Snowflake Inc., according to cybersecurity outlets including SecurityWeek, which reported the victims included Ticketmaster, whose breach exposed 560 million user records, AT&T, whose call and text logs for more than 100 million customers were compromised, along with Santander Bank, Advance Auto Parts and Neiman Marcus. Moucka pleaded guilty to four counts including computer fraud, wire fraud, aggravated identity theft and a related conspiracy charge, according to the Justice Department announcement carried in a post from FBI Seattle. Court documents cited in the press release say Moucka and his co-conspirators used stolen login credentials to break into cloud-hosted data belonging to at least 165 customers of the SaaS company starting around February 2024.
Investigators say the group stole non-content call and text history records, banking information, payroll records, DEA registration numbers, driver's license numbers, passport numbers, Social Security numbers and other personally identifiable information, then advertised the stolen data for sale on BreachForums, Exploit.in, XSS.is and Telegram. Prosecutors say the scheme brought in over $2.5 million in ransom payments, and that Moucka separately obtained at least $495,000 by re-extorting a victim with threats to release more stolen data, in one instance using the stolen information of a government officer and that officer's immediate family. The Justice Department says victim companies suffered more than $9.5 million in actual losses, and that the customers of those companies numbered at least 100 million individuals.
How the Hackers Got In
The breach did not stem from a flaw in Snowflake's own infrastructure. A technical investigation published by Google Cloud's Mandiant unit in June 2024 found that the hackers logged directly into customer accounts using credentials harvested years earlier by infostealer malware such as Lumma and Redline, accounts that lacked multi-factor authentication, according to the Google Cloud Blog. In other words, the intrusion exploited a gap in the shared-responsibility model between cloud vendors and their customers rather than any breach of Snowflake's core systems. Cybersecurity firm Huntress reported in November 2025 that Snowflake has since updated its platform controls, enforcing multi-factor authentication by default and mandating stricter password complexity across customer accounts.
Cybersecurity researchers tracked Moucka's hacking group under the designation UNC5537, while law enforcement identified his primary online aliases as “Judische” and “Waifu” across cybercrime forums, according to KrebsOnSecurity. A cyber threat intelligence report published by Resecurity in January 2026 linked Moucka and his co-conspirators to “The Com,” an informal online network of English-speaking threat actors known for cyber extortion, voice phishing, SIM-swapping and real-world harassment. Court documents unsealed in the U.S. District Court for the Western District of Washington in November 2024 showed Moucka was originally indicted alongside co-conspirator John Erin Binns, a 24-year-old U.S. citizen residing in Turkey who had previously been charged in a 2021 T-Mobile data breach.
A Soldier's Role and a Ransom Paid in Bitcoin
The extortion network reached beyond Kitchener. A Justice Department press release from July 2025 revealed that former active-duty U.S. Army soldier Cameron John Wagenius, operating under the alias “Kiberphant0m,” pleaded guilty to participating in the extortion conspiracy targeting AT&T and Verizon data linked to the Snowflake campaign. Separately, reporting from Security.org in July 2026 noted that AT&T paid approximately $370,000 in Bitcoin to the extortionists in exchange for a video demonstrating the deletion of its stolen customer database.
Moucka was arrested at a home in Kitchener, Ontario in October 2024. CyberScoop reported that shortly before that arrest, Moucka spoke anonymously to journalists, acknowledging he anticipated being apprehended and was actively wiping digital evidence and destroying hardware. CTV News reported that Moucka later appeared in an Ontario court and signed a consent to surrender, voluntarily waiving his right to contest extradition before being transferred to U.S. federal custody in July 2025, with the Justice Department's Office of International Affairs assisting the arrest and extradition process.
An International Manhunt
The FBI led the investigation, which drew assistance from the Security Service of Ukraine, the Australian Federal Police, the Royal Canadian Mounted Police, Spain's Guardia Civil and the Turkish National Police, according to the Justice Department release. The case falls under Operation Riptide, and the department's Computer Crime and Intellectual Property Section says it has secured convictions of more than 180 cyber and IP criminals and court orders for the return of over $350 million in victim funds since 2020.
“Today's guilty plea sends a clear message to cybercriminals: you cannot hide from justice, no matter how hard you may try to cover your tracks,” said W. Mike Herrington, FBI Seattle special agent in charge, adding that “Mr. Moucka's schemes were no match for the tenacity of FBI Seattle and this international investigative team.” Assistant U.S. Attorney A. Tysen Duva said Moucka hacked over 150 companies and organizations, obtained extremely sensitive information, and extorted victims for millions of dollars. FBI official Brett Leatherman said hiding behind a screen does not shield cybercriminals from justice, while Charles Neil Floyd said the Western District of Washington's cybercrimes unit acts quickly and precisely when hacks impact victims in its district and worldwide.
What Comes Next
Moucka is scheduled to be sentenced on October 27, 2026. His aggravated identity theft conviction carries a mandatory minimum of two years in prison, while the remaining counts carry a maximum penalty of 30 years, with the sentencing judge weighing the U.S. Sentencing Guidelines and statutory factors before deciding the final term. The Justice Department release notes that cybercrime losses reported by Americans rose 26 percent in a single year, topping $20 billion last year.
Hoodline previously covered the fallout from the breach, including AT&T's data exposure when it first surfaced on dark web forums in 2024. It is unclear how much of the $9.5 million in victim losses has been recovered, or whether additional unindicted members of The Com or UNC5537 will eventually face charges tied to the sprawling campaign.









