Connor Moucka, a 26-year-old Canadian national, pleaded guilty on Wednesday to hacking more than 165 corporate databases, stealing billions of sensitive records, and extorting numerous high-profile organisations and individuals.
The US Department of Justice announced the guilty plea in an official statement, marking a major breakthrough in one of the most significant cybercrime investigations of recent years.
How the Snowflake Cloud Exploits Unfolded
Moucka targeted the cloud storage provider Snowflake, exploiting security gaps to infiltrate the databases of dozens of major corporate clients. Among the high-profile victims of the campaign were telecommunications giant AT&T, financial platform LendingTree, and entertainment firm Ticketmaster.
During these breaches, Moucka compromised the personal data of more than 100 million AT&T customers, obtaining call logs and text message records. From other targeted systems, the hacker exfiltrated highly sensitive personally identifiable information, including banking details, driver’s licence numbers, and Social Security numbers.
Millions Extorted and Sold on the Dark Web
The cybercriminal operation yielded massive financial payouts for Moucka and his co-conspirators, who successfully extorted over $2.5 million in ransom payments from victim companies. Additionally, Moucka generated approximately $500,000 by selling stolen consumer databases on notorious cybercrime marketplaces, including BreachForums.
According to the Department of Justice, the total losses suffered by the victimised companies amounted to at least $9.5 million. FBI Special Agent W. Mike Herrington, who worked on the investigation, condemned the hacker’s actions, stating that Moucka’s “threats and re-extortion tactics were calculated and predatory, and his actions did real harm to his victims, be they companies targeted for theft and extortion or the millions of everyday people who are their customers.”
The Arrest of ‘Waifu’ and ‘Judische’
Moucka, who operated online under the pseudonyms “Waifu” and “Judische”, was arrested by Canadian authorities in late 2024, just months after the devastating Snowflake breaches came to light.
At the time of his arrest, cybersecurity experts highlighted the immense scale of his operations. Austin Larsen, a senior researcher at Google’s cybersecurity firm Mandiant, described Moucka as “one of the most consequential” threat actors of 2024 due to the sheer volume of data compromised under his campaigns.
Sentencing and Potential Prison Time
Following his formal guilty plea, Moucka is scheduled to face a federal judge for sentencing on 27 October. Given the severity of the cyber espionage and extortion charges, the 26-year-old Canadian faces a potential sentence spanning several decades in a US federal prison.
