Connor Riley Moucka, 26, of Kitchener, Ontario — known online as "Waifu" and "Judische" — pleaded guilty on August 5, 2026 to federal charges stemming from one of the most consequential cloud data-theft campaigns ever documented. The attacks leveraged stolen credentials to breach Snowflake customer accounts at 165 organizations, exposing billions of sensitive records and netting millions in extortion payments.
How the Attack Worked
Between February and October 2024, Moucka and his co-conspirator, American John Erin Binns, executed a methodical campaign against Snowflake customer accounts that lacked multi-factor authentication (MFA). The attack chain was straightforward but devastatingly effective:
- Credential harvesting: Credentials were obtained via infostealer malware that had previously compromised employee devices
- Account access: MFA-absent Snowflake accounts were accessed using the stolen credentials
- Data identification: Custom tooling identified and extracted high-value datasets
- Extortion: At least 10 organizations received ransom demands ranging from $300,000 to $5 million
In at least one case, Moucka re-extorted a victim who had already paid, leveraging personal data belonging to a government official's family as additional pressure.
Scale of the Breach
The numbers are staggering:
| Metric | Volume |
|---|---|
| Victim organizations | 165 |
| Call and text records stolen | ~50 billion |
| Individuals affected | 100+ million |
| Documented victim losses | $9.5 million+ |
| Bitcoin extorted |
High-profile victims included AT&T, Ticketmaster, Santander, Pure Storage, Advance Auto Parts, Los Angeles Unified School District, QuoteWizard/LendingTree, and Neiman Marcus.
Arrest, Extradition, and Guilty Plea
Moucka was arrested in October 2024 through a collaborative operation involving Canadian, Australian, Spanish, Ukrainian, and Turkish law enforcement. He was extradited to the United States in July 2025.
His guilty plea covers multiple charges. Sentencing is scheduled for October 27, 2026. The aggravated identity theft count alone carries a mandatory minimum of two years; Moucka faces up to 32 years in total.
Co-conspirator John Erin Binns was separately indicted but has not yet pleaded.
The MFA Problem
The Snowflake campaign is a textbook example of what happens when cloud platforms and their customers treat MFA as optional. Snowflake itself was not breached — the platform's infrastructure remained intact. The attacks succeeded entirely because legitimate credentials, harvested through third-party infostealer infections, were used to log into accounts without any secondary verification.
In the aftermath, Snowflake introduced mandatory MFA enforcement policies and worked with customers to identify and remediate exposed accounts.
Key Takeaways
- Infostealer malware feeding into cloud credential abuse remains one of the most effective attack vectors of 2024–2026
- MFA on cloud data platforms is non-negotiable — its absence was the single enabling condition for all 165 breaches
- Re-extortion of already-paid victims is an emerging tactic among ransomware and data extortion actors
- Multi-country law enforcement coordination successfully tracked and apprehended actors operating across borders
- Sentencing in October 2026 could result in one of the longest sentences handed down for cloud-focused cybercrime