“Hiding behind a screen is no shield from justice,” Brett Leatherman, assistant director of the FBI’s Cyber Division, said as prosecutors disclosed a guilty plea in one of the most expansive data-theft-and-extortion campaigns of 2024.
Connor Moucka’s plea, charges, and custody timeline
Connor Moucka, a Canadian national, pleaded guilty to computer fraud, wire fraud, aggravated identity theft and a related conspiracy for his central role in the 2024 attacks that compromised Snowflake customer environments. Moucka was arrested on Oct. 30, 2024, in Kitchener, Ontario, at the behest of U.S. authorities and was extradited to the United States in March 2025. He is scheduled for sentencing on Oct. 27, 2026, and faces up to 32 years in prison. Authorities also tied multiple online aliases to him, including “Waifu,” “Judische,” “Catist” and “Ellyel8.”
How the Snowflake compromises unfolded
Prosecutors say Moucka and his co-conspirators used stolen credentials to access the cloud data-storage platform’s customers’ accounts en masse, compromising more than 165 Snowflake customer environments. The campaign exposed records for more than 100 million people and stole billions of sensitive records. The types of information taken included call and text history, banking and other financial information, payroll records, government ID numbers and other personally identifiable data.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleScale of theft, extortion proceeds, and named victims
Authorities say Moucka earned $495,000 by extorting victims, offering stolen data for sale online, and, in at least one case, re-extorting a victim with stolen data of a government official and members of a then-former government official’s immediate family. Together with alleged co-conspirators John Binns and Cameron Wagenius, prosecutors say the group received more than $2.5 million in extortion payments. The attacks touched high-profile corporate customers; listed victims include AT&T, Ticketmaster, Advance Auto Parts and Santander. Officials calculated that victim companies bore more than $9.5 million in losses combined, a total that does not include losses attributable to their respective customers.
Co-conspirators and The Com network
Prosecutors linked Moucka and his alleged partners to The Com, which federal authorities describe as a sprawling cybercriminal network of minors and young adults that engages in violence, extortion, sextortion and various forms of cybercrime. John Binns and Cameron Wagenius are named as Moucka’s co-conspirators in the indictment and were described in the Justice Department’s account of the scheme.
What this means for technologists, affected enterprises, and end users
- Technologists and security teams: The attackers’ use of stolen credentials to gain bulk access to customer accounts highlights the consequence of credential-based intrusions and mass account compromise; teams will be watching how credential theft and account access vectors are identified and remediated in post-incident work.
- Affected enterprises and procurement leaders: Companies that were victims — including AT&T, Ticketmaster, Advance Auto Parts and Santander — already face quantified costs: more than $9.5 million in losses borne by victim companies, plus unknown additional losses to customers and downstream parties.
- End users and the general public: More than 100 million people had personal information exposed in the campaign. The stolen material included sensitive categories such as call and text histories, financial data, payroll records and government identification numbers, raising specific privacy and fraud risks for those individuals.
Federal officials framed the case as both a criminal victory and a caution about predatory extortion tactics. “Moucka’s threats and re-extortion tactics were calculated and predatory, and his actions did real harm to his victims, be they companies targeted for theft and extortion or the millions of everyday people who are their customers,” W. Mike Herrington, special agent in charge of the FBI Seattle field office, said in a statement. With sentencing set for Oct. 27, the case will resolve one chapter in a campaign that combined credential theft, bulk access to cloud-stored data, and targeted extortion of both corporations and private individuals.




