The Fall of "Judische": Inside the Massive Snowflake and AT&T Cloud Extortion Ring

Main page Cyber Security & Privacy The Fall of "Judische": Inside…
From ZizzMedia, the free news encyclopedia
The Fall of "Judische": Inside the Massive Snowflake and AT&T Cloud Extortion Ring
The Fall of "Judische": Inside the Massive Snowflake and AT&T Cloud Extortion Ring
Published: 24 August 2026
Author: Suro Senen
Category: Cyber Security & Privacy
Read time: 9 min read
Words: 1,602

Executive Overview

In a landmark case that underscores the staggering vulnerability of modern cloud infrastructure, 26-year-old Canadian national Connor Riley Moucka has pleaded guilty to federal computer fraud, wire fraud, aggravated identity theft, and conspiracy charges. Once flagged by threat intelligence analysts as one of the most consequential and destructive cybercrime actors of 2024, Moucka—operating under various aliases including "Judische" and "Waifu"—admitted to spearheading a massive, multi-pronged hacking campaign.

Between February and October 2024, Moucka and an international cadre of co-conspirators systematically compromised cloud-hosted databases belonging to more than 165 corporate victims. Leveraging stolen login credentials and exploiting organizations that failed to enforce multi-factor authentication (MFA) on the Snowflake cloud platform, the threat group pillaged terabytes of sensitive data. Their victims read like a cross-section of corporate America, featuring household names such as TicketMaster, LendingTree, Advance Auto Parts, and Neiman Marcus.

Beyond the Snowflake breach, Moucka’s digital trail of destruction crossed over into the telecommunications sector. He admitted to participating in the large-scale theft of call and text history records belonging to more than 100 million AT&T customers. The operation utilized fear, extortion, and harassment, resulting in over $2.5 million in extortion payouts, targeted attacks against government officials, and the brazen re-extortion of victims using pilfered personal data.

Moucka’s guilty plea marks a critical milestone in a sprawling transnational investigation involving the U.S. Department of Justice (DOJ), the Royal Canadian Mounted Police (RCMP), and cybersecurity researchers. With his sentencing scheduled for October 27, Moucka faces up to 30 years in federal prison, alongside a mandatory minimum consecutive two-year sentence for aggravated identity theft. His admissions pull back the curtain on an interconnected ecosystem of illicit hackers, insider threats, and cross-border digital extortionists.


Detailed Chronology of the Cyberattacks

The timeline of Moucka’s rise and fall reveals a calculated, aggressive campaign that exploited structural weaknesses in cloud security and corporate credential hygiene.

The Genesis: 2020–2023

Long before he became a household name among cybersecurity incident responders, Moucka was operating in the shadows as a software engineer based in Kitchener, Ontario. Investigators note that since at least 2020, he was actively involved in corporate data breaches and sophisticated voice phishing (vishing) campaigns targeting U.S. companies. During these formative years, he cultivated a sprawling network of digital aliases across encrypted chat platforms like Telegram and Discord, laying the groundwork for the massive operations of 2024.

The Snowflake Campaign: February – October 2024

The cornerstone of Moucka’s criminal enterprise unfolded over an intense eight-month period in 2024. Operating under monikers like "Judische" and "Waifu," Moucka and his co-conspirators targeted the Snowflake cloud storage ecosystem. Rather than exploiting zero-day software vulnerabilities, the threat actors capitalized on human and administrative error: they hunted down valid, stolen corporate login credentials for customer accounts that lacked MFA enforcement.

Once inside the cloud environments, the actors downloaded terabytes of proprietary and personally identifiable information (PII). This treasure trove included:

  • Non-content call and text history records
  • Banking and financial details
  • Internal payroll records
  • Drug Enforcement Administration (DEA) registration numbers
  • State-issued driver’s license numbers, passports, and Social Security numbers (SSNs)

Armed with this data, the group launched a systematic extortion campaign. They contacted victim organizations, threatening to leak or publicly auction their sensitive repositories unless steep cryptocurrency ransoms were paid. When companies balked, the threat actors frequently made good on their threats, publishing samples or entire datasets on dark web forums.

Canadian Man Pleads Guilty in Snowflake Extortions – Krebs on Security

The AT&T Telecommunications Breach

The scope of the threat group’s operations widened dramatically when they pivoted toward major telecommunications providers. In tandem with co-conspirators, Moucka facilitated the catastrophic breach of AT&T customer records, illegally exfiltrating call and text metadata for more than 100 million subscribers. This breach demonstrated the group’s capability to transcend standard SaaS environments and penetrate deeply integrated carrier infrastructure.

The Crackdown and Arrest (Fall 2024)

As the scale of the extortion became clear, private-sector security researchers and law enforcement agencies launched an intensive counter-offensive. Investigative reporting—most notably by KrebsOnSecurity—began mapping the real-world identity of "Judische," linking the Ontario software engineer to the Snowflake attacks and revealing disturbing overlaps between the threat actors and online extremist groups targeting minors.

On October 31, 2024, acting on a provisional arrest warrant issued by the United States, the RCMP apprehended Moucka in Canada. A surveillance photograph taken just nine days prior to his arrest captured the fugitive walking the streets, completely unaware that federal nets were closing in around him.


Supporting Context, Metrics, and Co-Conspirators

Moucka did not operate in a vacuum. His indictment and subsequent guilty plea have exposed a tight-knit triad of cybercriminals, each with unique military, technical, or geopolitical advantages that shielded them—temporarily—from traditional law enforcement reach.

Cameron "Kiberphant0m" Wagenius

One of Moucka’s primary admitted co-conspirators is 20-something U.S. Army soldier Cameron Wagenius, widely known in hacker circles by the handle "Kiberphant0m." Operating from military installations—including a deployment in South Korea—Wagenius leveraged his digital operational security knowledge to participate in the extortions of telecommunications giants like AT&T and Verizon.

Wagenius pleaded guilty in July 2025 to related hacking and extortion charges. His brazenness matched Moucka’s: immediately following Moucka’s arrest in October 2024, Wagenius posted what he claimed were the AT&T call logs of then President-elect Donald Trump and then Vice President Kamala Harris on hacker forums, alongside classified-looking schematics allegedly pilfered from the U.S. National Security Agency (NSA). Wagenius is scheduled to be sentenced on September 3, 2026, and faces a maximum penalty of 20 years for wire fraud conspiracy, five years for computer fraud extortion, and a mandatory consecutive two-year term for aggravated identity theft.

John Erin Binns ("IRDev")

The third pillar of the alleged conspiracy is John Erin Binns, a 26-year-old American citizen who fled the United States following federal indictments for his role in the monumental 2021 T-Mobile data breach, which exposed records for at least 76 million customers.

Known online as "IRDev" and "IntelSecrets," Binns managed to evade U.S. extradition by relocating abroad. According to sources close to the investigation, Binns recently acquired Turkish citizenship. Under Turkish constitutional law, citizens cannot be extradited to foreign jurisdictions. Although Binns spent time incarcerated in a Turkish prison on unrelated matters, he has since been released and has begun resurfacing across digital channels, highlighting the complex geopolitical hurdles facing international cybercrime investigators.

The Human Toll: Re-Extortion and Harassment

What distinguished Moucka and his associates from traditional financially motivated ransomware gangs was their aggressive, personal style of psychological warfare. The Justice Department revealed that the conspirators made more than $2.5 million in extortion payments. However, they frequently crossed ethical and legal boundaries by re-extorting victims after ransoms had already been paid.

Canadian Man Pleads Guilty in Snowflake Extortions – Krebs on Security

In a particularly egregious abuse of power, Moucka utilized the stolen data of a government officer—as well as the personal information of that official’s immediate family members—to launch a secondary re-extortion campaign. Furthermore, the group actively harassed and threatened government officials and independent security researchers who were aiding law enforcement in tracking them down.


Official Statements and Industry Impact

The fallout from the Snowflake and AT&T breaches has forced a radical re-evaluation of cloud security postures across the global software industry.

The U.S. Department of Justice issued scathing remarks regarding the defendants’ conduct, emphasizing the profound invasion of privacy suffered by millions of citizens. In official press releases, prosecutors highlighted that the defendants’ willingness to weaponize sensitive PII—ranging from social security numbers and DEA registration codes to intimate communication logs—posed an unprecedented threat to national security and public trust.

For Snowflake, the fallout was an acute corporate crisis. The company faced intense scrutiny over how threat actors were able to access customer instances using credential-stuffing and stolen credentials. In response, Snowflake initiated a sweeping security overhaul. The cloud provider instituted mandatory password complexity requirements and forced all corporate and customer accounts to implement robust multi-factor authentication (MFA), effectively slamming the door on the primary vector used by Moucka and his accomplices.

Similarly, telecom giants AT&T and Verizon faced severe regulatory and congressional pressure following the disclosure that call and text metadata for virtually the entire AT&T subscriber base had been exfiltrated. The breaches prompted renewed legislative calls for mandatory federal cybersecurity standards governing telecommunications carriers and cloud-hosted data repositories.


Future Outlook

As the legal proceedings against Connor Riley Moucka draw to a close with his upcoming sentencing on October 27, the broader war against cloud-native extortion syndicates is entering a new phase.

Moucka faces a formidable reality: while the plea agreement spares him a full trial, he looks toward a potential prison sentence of up to 30 years, alongside a mandatory minimum two-year stacking sentence for aggravated identity theft. His co-conspirator, Cameron Wagenius, faces a similarly bleak judicial horizon when he stands for sentencing in September 2026.

However, the case of John Erin Binns serves as a stark reminder of the persistent structural roadblocks in international cyber law enforcement. As long as safe-haven nations continue to offer citizenship or refuse extradition to fugitive hackers, masterminds operating from abroad will retain the ability to taunt Western law enforcement from afar.

For the enterprise sector, the "Judische" case stands as a permanent watershed moment. It has effectively killed the era of lax cloud hygiene. Organizations can no longer treat multi-factor authentication as an optional feature or rely solely on perimeter defenses. As cloud providers enforce rigid security baselines and international law enforcement agencies close ranks through coordinated cross-border takedowns, the golden age of easy cloud extortion is rapidly coming to an end.

Related News

Leave a Reply / Join Discussion

Your email address will not be published. Required fields are marked with *