Quick Facts

  • Connor Moucka, 26, pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy after stealing data from more than 165 organizations.
  • The breaches exposed records belonging to at least 100 million people, including AT&T customers, with victim companies reporting over $9.5 million in direct losses.
  • Moucka faces up to 32 years in prison and is scheduled to be sentenced October 27.

A 26-year-old Canadian hacker pleaded guilty Wednesday to one of the largest data theft campaigns in recent history. Connor Riley Moucka, also known online as “Waifu” and “Judische,” of Kitchener, Ontario, admitted in federal court in Washington state to hacking more than 165 companies, stealing billions of records, and extorting victims for millions of dollars.

The U.S. Department of Justice announced the plea as part of Operation Riptide, the FBI’s enforcement campaign targeting cybercriminal networks, announced in June 2026. Moucka was extradited from Canada to the United States in July 2025.

The breach reached at least 165 organizations and exposed records belonging to at least 100 million people. Stolen data included telephone call records, banking and financial information, payroll details, Drug Enforcement Agency registration numbers, and driver’s license, passport, and Social Security numbers.

AT&T was among the hardest-hit organizations. Moucka stole call and texting records from more than 100 million AT&T customers, along with banking information, driver’s license numbers, and Social Security numbers from other breaches. Other publicly named victims include Ticketmaster, Santander, Advance Auto Parts, LendingTree, Neiman Marcus, Pure Storage, and Bausch Health.

Moucka and his co-conspirators extorted 36 bitcoin, worth roughly $2.5 million at the time, from at least three victims. Moucka personally collected at least $495,000 from ransoms and data sales. The group advertised stolen data on BreachForums, Exploit.in, XSS.is, and Telegram.

The attacks did not exploit any flaw in Snowflake’s platform. Moucka and co-conspirators John Erin Binns and Cameron Wagenius used credentials stolen from infostealer malware logs to log directly into cloud accounts. Snowflake did not require customers to enable multi-factor authentication, meaning a valid username and password was sufficient to access terabytes of enterprise data.

Once inside, the group deployed custom software tracked by Google’s Mandiant as “Frostbite,” which automated the identification of high-value targets within each breached account, scanning for organization names, user roles, IP addresses, and banking details. Mandiant noted in its June 2024 investigation report that the campaign was “not the result of any particularly novel or sophisticated tool, technique, or procedure.”

“Hiding behind a screen is no shield from justice,” said FBI Cyber Division Assistant Director Brett Leatherman. “Connor Moucka learned that when he was arrested just months after he began targeting U.S. companies, stealing sensitive information, and extorting victims for millions of dollars.”

Assistant Attorney General A. Tysen Duva added that Moucka “was arrested just six months after these breaches began, demonstrating this Department’s firm commitment to investigating and prosecuting sophisticated cybercriminals.”

The case triggered significant legal and regulatory fallout. The Judicial Panel on Multidistrict Litigation consolidated 32 lawsuits against Snowflake in October 2024. Plaintiffs alleged negligent security practices, including failure to mandate MFA and delayed breach notification. The FTC opened an investigation into Snowflake’s compliance with the Safeguards Rule. Advance Auto Parts faces a $28 million fine from the Vermont Attorney General for improper credential storage.

In one particularly alarming instance, Moucka attempted to extort a victim a second time by threatening to release additional stolen data that included personal information belonging to a government official and members of a former government official’s immediate family.

An 11-count indictment unsealed in November 2024 charged Moucka alongside American co-conspirator John Binns. The stolen data in that indictment included roughly 50 billion call and text records. Austin Larsen, a senior researcher at Mandiant, called Moucka “one of the most consequential” hackers of 2024 at the time of his arrest.

Read more: Hacker pleads guilty to stealing data from more than 165 Snowflake customers

This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.