Canadian Man Pleads Responsible in Snowflake Extortions – Krebs on Safety
A 26-year-old Canadian man as soon as described as one of the crucial consequential cybercrime risk actors of 2024 has pleaded responsible to laptop fraud and conspiracy to hack and extort greater than 165 organizations that used the cloud supplier Snowflake. Connor Riley Moucka, of Kitchener, Ontario, additionally admitted to stealing name and textual content historical past information of greater than 100 million AT&T prospects.
A surveillance photograph of Connor Riley Moucka, a.okay.a. “Judische” and “Waifu,” dated Oct 21, 2024, 9 days earlier than Moucka’s arrest. This picture was included in an affidavit filed by an investigator with the Royal Canadian Mounted Police (RCMP).
The U.S. Justice Division mentioned between February and October 2024, Moucka and co-conspirators used stolen login credentials to steal cloud-hosted knowledge belonging to a minimum of 165 prospects of a U.S.-based software-as-a-service firm.
The hackers focused stolen credentials for Snowflake buyer accounts that didn’t implement multi-factor authentication, and extorted or tried to extort a number of well-known corporations, together with TicketMaster, Lending Tree, Advance Auto Elements and Neiman Marcus. Snowflake responded to the information thefts by growing password complexity necessities and implementing multi-factor authentication.
Moucka adopted new nicknames regularly — generally working a number of identities concurrently — however two of his best-known monikers had been “Judische” and “Waifu.” Judische’s admitted function within the Snowflake knowledge thefts was first documented by KrebsOnSecurity in a September 2024 story in regards to the overlap between Western, English-speaking cybercriminals and extremist teams that harass and extort minors into harming themselves or others.
That September 2024 story recognized Judische as a software program engineer from Ontario who has been concerned in quite a few knowledge breaches and voice phishing assaults in opposition to U.S. corporations since a minimum of 2020. Just a little greater than a month later, Canadian authorities arrested Moucka on a provisional warrant from the USA.
The federal government says Moucka and others used their unauthorized entry to steal billions of delicate buyer information and obtain terabytes of knowledge, “together with people’ non-content name and textual content historical past information, banking and different monetary data, payroll information, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, social safety numbers and different personally identifiable data. They then extorted victims by threatening to publish knowledge on-line.”
Moucka additionally threatened and harassed authorities officers and safety researchers who had been serving to to trace him down. The Justice Division mentioned the conspirators revamped $2.5 million in ransom funds, and that in a minimum of one occasion, Moucka re-extorted a sufferer with threats of additional disclosure of the sufferer’s stolen knowledge.
“Moucka used the stolen knowledge of a authorities officer and members of a then-former authorities officer’s rapid household on this re-extortion try,” reads a statement from the Justice Division.
One in all Moucka’s admitted co-conspirators is Cameron “Kiberphant0m” Wagenius, a U.S. Military soldier who pleaded guilty in July 2025 to extorting AT&T and Verizon for his or her buyer account knowledge. Lower than a month earlier than Wagenius’s arrest, KrebsOnSecurity revealed a deep dive into Kiberphant0m’s numerous Telegram and Discord identities through the years, revealing how the proprietor of the accounts advised others they had been within the Military and stationed in South Korea.
One in all a number of selfies on the Fb web page of Cameron Wagenius.
Kiberphant0m additionally re-extorted victims. Instantly following Moucka’s arrest, Kiberphant0m posted on hacker boards what he claimed had been the AT&T name logs for then President-elect Donald Trump and for then Vice President Kamala Harris, as effectively schematics allegedly stolen from the U.S. Nationwide Safety Company (NSA).
Wagenius is ready to be sentenced on September 3, 2026. The federal government says he faces a most penalty of 20 years in jail for conspiracy to commit wire fraud, a most penalty of 5 years in jail for extortion in relation to laptop fraud, and a compulsory two-year sentence consecutive to some other jail time for aggravated identification theft.
The third alleged co-conspirator is John Erin Binns, 26, an elusive American man who fled the USA after being indicted for his admitted function in a 2021 breach at T-Mobile that uncovered the private data of a minimum of 76 million prospects.
Sources near the investigation mentioned Binns, also referred to as “IRDev” and “IntelSecrets,” was till lately incarcerated in a Turkish jail, however that he has since been launched and has resurfaced on-line. These sources mentioned Binns additionally lately obtained Turkish citizenship, and beneath Turkish legislation a citizen can’t be extradited to a international nation.
A picture of a passport that Binns shared in an e mail to KrebsOnSecurity in Feb. 2023.
Moucka pleaded responsible to 4 prison counts, together with laptop fraud, wire fraud, aggravated identification theft, and conspiracy. He’s slated to be sentenced on Oct. 27 and faces a compulsory minimal penalty of two years in jail on the aggravated identification theft depend, in addition to a most penalty of 30 years in jail on the remaining counts. Finally, will probably be up the federal choose how a lot time Moucka truly serves for his intensive cybercriminal rap sheet.
For an interview with Moucka previous to his arrest and a deeper have a look at Binns, see our original report on Moucka’s arrest.
Source link