A Canadian man pleaded guilty to playing a central role in one of the most far-reaching cyberattacks of 2024 — the widespread compromise of more than 165 Snowflake customer environments, resulting in massive data theft for extortion, the Justice Department said Wednesday.
The Extortion Scheme
Connor Moucka earned $495,000 by extorting his victims, offering stolen data for sale online, and in one case re-extorted a victim with stolen data of a government official and members of a then-former government official’s immediate family, authorities said. Moucka and his alleged co-conspirators John Binns and Cameron Wagenius stole billions of sensitive records and received more than $2.5 million in extortion payments combined, according to prosecutors.
Victims of the attack spree included AT&T, Ticketmaster, Advance Auto Parts, and Santander. “Hiding behind a screen is no shield from justice,” Brett Leatherman, assistant director of the FBI’s Cyber Division, said in a statement.
Arrest and Investigation
Authorities arrested Moucka relatively quickly because he caused significant damage, said Allison Nixon, chief research officer at Unit 221B. “His gang went on a spree of maximizing harm, which directly correlated to maximizing the resources devoted to stopping it,” she said.
Moucka, who used several aliases online, including “Waifu,” “Judische,” “Catist,” and “Ellyel8,” was arrested Oct. 30, 2024, in Kitchener, a city in the Canadian province of Ontario, at the behest of U.S. authorities. He was extradited to the United States in March 2025.
The Impact of the Attack
Records of more than 100 million people were exposed by the data theft campaign, including call and text history records, banking and other financial information, payroll records, government ID numbers, and other personally identifiable data.
Officials said victim companies bore more than $9.5 million in losses combined, not including losses attributable to their respective customers. Moucka’s threats and re-extortion tactics were calculated and predatory, and his actions did real harm to his victims, be they companies targeted for theft and extortion or the millions of everyday people who are their customers, said W. Mike Herrington, special agent in charge of the FBI Seattle field office.
The Legacy of the Attack
Researchers said Moucka and his co-conspirators are all associated with The Com, a sprawling cybercriminal network of minors and young adults who engage in violence, extortion, sextortion, and various forms of cybercrime. “His legacy is one of failure. He extorted and then scammed his victims by not deleting the data, casting doubt on all future pay-or-leak extortion gangs,” Nixon said.
Moucka pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy. He is scheduled for sentencing Oct. 27 and faces up to 32 years in prison.
- 165 Snowflake customer environments were compromised
- Billions of sensitive records were stolen
- More than $2.5 million in extortion payments were received
- Over 100 million people had their data exposed
- Victim companies suffered over $9.5 million in losses
The case highlights the importance of cybersecurity and the need for companies to protect their customers' data. It also shows that law enforcement agencies are working to bring cybercriminals to justice, no matter where they are located.
Source: CyberScoop