More than 100 million AT&T customers had their call and text history records stolen, U.S. prosecutors say — one fact among many that underpins the scale of a cross-border hacking and extortion scheme for which a 26‑year‑old Canadian man has now pleaded guilty.
Connor Riley Moucka: guilty pleas, aliases, and possible penalties
Connor Riley Moucka of Kitchener, Ontario pleaded guilty to four federal counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy, the U.S. Justice Department said. He is slated to be sentenced on Oct. 27 and faces a mandatory minimum of two years in prison on the aggravated identity theft count, alongside a combined maximum of 30 years on the remaining counts; how much time he will actually serve will be up to the sentencing judge.
Moucka operated under multiple monikers, frequently changing identities and sometimes running concurrent accounts. Two of his best‑known nicknames were “Judische” and “Waifu.” A surveillance photograph dated Oct. 21, 2024 — nine days before Moucka’s arrest — was included in an affidavit filed by an investigator with the Royal Canadian Mounted Police (RCMP), the Justice Department said. The department also reported that Moucka threatened and harassed government officials and security researchers who were helping to track him down.
Scale and scope: Snowflake customers, AT&T records, and terabytes of data
Between February and October 2024, Moucka and co‑conspirators used stolen credentials to access cloud‑hosted data belonging to at least 165 customers of a U.S.‑based software‑as‑a‑service company, the Justice Department said. That activity included theft of “billions of sensitive customer records” and the downloading of terabytes of information.
The government described the range of stolen materials as including “individuals’ non‑content call and text history records, banking and other financial information, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, social security numbers and other personally identifiable information.” In addition to the AT&T call and text records, the conspirators extorted or attempted to extort well‑known commercial victims such as TicketMaster, LendingTree, Advance Auto Parts and Neiman Marcus.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadTactics: stolen Snowflake credentials, lack of multi‑factor authentication, and extortion
Prosecutors say the hackers targeted stolen login credentials for Snowflake customer accounts that did not enforce multi‑factor authentication (MFA). Using those credentials, they accessed and exfiltrated data, and then threatened publication unless victims paid ransoms. The Justice Department reported the conspirators received more than $2.5 million in ransom payments and detailed at least one re‑extortion in which Moucka threatened additional disclosure of already stolen data.
In one particularly sensitive re‑extortion, prosecutors said Moucka “used the stolen data of a government officer and members of a then‑former government officer’s immediate family” to pressure a victim into paying. The pattern — credential abuse, large data exfiltration, and extortion — was central to the conspiracy outlined in court papers.
Co‑conspirators: Cameron “Kiberphant0m” Wagenius and John Erin Binns
One admitted co‑conspirator is Cameron “Kiberphant0m” Wagenius, a U.S. Army soldier who pleaded guilty in July 2025 to extorting AT&T and Verizon for customer account data. Less than a month before Wagenius’s arrest, KrebsOnSecurity published reporting on his multiple Telegram and Discord identities and noted claims he made about military service and stationing. Wagenius publicly posted alleged AT&T call logs for “then President‑elect Donald Trump and for then Vice President Kamala Harris,” and reportedly posted schematics allegedly stolen from the U.S. National Security Agency immediately after Moucka’s arrest. Wagenius is set to be sentenced on Sept. 3, 2026, and faces statutory maximums described by prosecutors for conspiracy, extortion tied to computer fraud, and aggravated identity theft.
The third named alleged co‑conspirator is John Erin Binns, 26, an American who fled the United States after indictment for his admitted role in a 2021 breach of T‑Mobile that exposed the data of at least 76 million customers. Sources close to the investigation said Binns was until recently incarcerated in a Turkish prison, has since been released, and “has resurfaced online.” Those sources added that Binns obtained Turkish citizenship and that, under Turkish law, a citizen cannot be extradited to a foreign country.
Snowflake and law enforcement responses
Snowflake responded to the thefts by increasing password complexity requirements and enforcing multi‑factor authentication for customer accounts, according to the Justice Department. The RCMP filed an affidavit that included the Oct. 21, 2024 surveillance photograph of Moucka as part of cross‑border investigative cooperation. U.S. prosecutors have framed the case as an international conspiracy that exploited cloud‑hosted misconfigurations and weak authentication to harvest and monetize sensitive records.
What this means for technologists, affected enterprises, and the public
- Technologists and security teams: The case underscores the operational impact of accounts that do not enforce MFA. Teams will watch authentication policies, credential exposure, and monitoring for large‑scale data exfiltration from cloud platforms.
- Affected enterprises and procurement leaders: Organizations that used the cloud provider Snowflake and other SaaS platforms may reassess default security settings, password complexity requirements, and contractual expectations around breach notification and access controls.
- End users and the general public: The thefts included highly sensitive personal identifiers and non‑content telephony records; individuals affected by breaches cited in court filings should look for breach notices tied to the companies named and monitor communications from service providers.
The plea by Connor Riley Moucka closes one chapter in a wide‑ranging extortion campaign that, prosecutors say, combined credential theft, sprawling data collection, and repeated attempts to monetize victims’ most sensitive records. Sentencing on Oct. 27 will quantify the legal consequence for Moucka; related proceedings for co‑conspirators and the practical aftermath for companies and millions of affected individuals will play out in the months ahead.
Source: KrebsOnSecurity: Canadian Man Pleads Guilty in Snowflake Extortions




