Connor Riley Moucka, a 26-year-old resident of Kitchener, Ontario, has officially entered a guilty plea regarding his role in a prolific cybercrime campaign targeting the cloud storage firm Snowflake. According to Krebs on Security, the defendant faced charges related to conspiracy and computer fraud, admitting to the compromise of 165 organizations that relied on the cloud platform for data management. In addition to the Snowflake breaches, Moucka confessed to the exfiltration of sensitive call and text history logs belonging to more than 100 million AT&T customers.
Incident Statistics and Data Scope
The U.S. Department of Justice investigation determined that the criminal activity occurred between February and October 2024. Moucka, known in various digital circles by the monikers "Judische" and "Waifu," utilized stolen credentials to bypass systems that failed to implement multi-factor authentication. The scope of the stolen data was extensive, including banking details, payroll records, DEA registration numbers, government-issued IDs, and passport documentation. The conspirators successfully extorted over $2.5 million in ransom payments.
| Metric | Figure |
|---|---|
| Organizations Targeted (Snowflake) | 165 |
| AT&T Customers Affected | 100,000,000+ |
| Ransoms Paid | $2,500,000+ |
| Operational Period | Feb 2024 - Oct 2024 |
Official Context
Law enforcement interest in the suspect accelerated following reports from Krebs on Security in September 2024, which linked "Judische" to a history of data breaches and phishing attacks against U.S. entities dating back to 2020. The Royal Canadian Mounted Police (RCMP) arrested Moucka shortly thereafter, acting on a provisional warrant issued by the United States. Following the breaches, Snowflake took technical measures to harden customer accounts by enforcing stricter password policies and mandatory multi-factor authentication protocols.
Why It Matters
This case underscores a fundamental vulnerability in the shared responsibility model of cloud computing. While providers like Snowflake offer infrastructure, the failure of client-side entities to enforce basic identity hygiene—specifically multi-factor authentication—remains the primary vector for mass-scale exfiltration. The diversification of extortion tactics, which included re-extortion and the targeting of researchers, signals a shift toward more aggressive, psychological warfare within the cybercrime ecosystem. Organizations must move beyond static security perimeters and prioritize granular credential monitoring to mitigate the threat of automated credential stuffing operations.

Reader Discussion & Insights