Notorious 'Judische' Hacker Pleads Guilty to Snowflake Extortion and AT&T Data Theft
A 26-year-old Canadian man, **Connor Riley Moucka** (also known as **Judische** and **Waifu**), has pleaded guilty to orchestrating a massive hacking and extortion scheme targeting over 165 organizations utilizing the cloud provider **Snowflake**. Moucka also admitted to stealing the call and text history records of more than 100 million **AT&T** customers, highlighting a significant breach of privacy and data security.
# Notorious 'Judische' Hacker Pleads Guilty to Snowflake Extortion and AT&T Data Theft
**Connor Riley Moucka**, a 26-year-old Canadian man from Kitchener, Ontario, has entered a guilty plea to charges of computer fraud and conspiracy. Moucka, identified by monikers such as **Judische** and **Waifu**, was implicated in a widespread hacking and extortion campaign that impacted over 165 organizations leveraging the cloud platform **Snowflake**.
His admissions also include the theft of call and text history records belonging to more than 100 million **AT&T** customers, underscoring the vast scale of his cybercriminal activities.

## The Snowflake Breach and Extortion Scheme
Between February and October 2024, Moucka and his co-conspirators exploited stolen login credentials to access cloud-hosted data of at least 165 **Snowflake** customers. The hackers specifically targeted accounts that lacked multi-factor authentication (MFA), demonstrating a common vulnerability exploited in such attacks.
Victims of the extortion attempts included prominent companies like **TicketMaster**, **Lending Tree**, **Advance Auto Parts**, and **Neiman Marcus**. In response to these incidents, **Snowflake** has since implemented stricter password complexity requirements and enforced multi-factor authentication across its platform.
## A History of Cybercrime and Harassment
Moucka, operating under various aliases, has been a significant figure in cybercrime since at least 2020, involved in numerous data breaches and voice phishing attacks. His role in the **Snowflake** thefts was initially brought to light by KrebsOnSecurity in September 2024, which detailed connections between Western cybercriminals and extremist groups.
Canadian authorities arrested Moucka in October 2024, following a provisional warrant from the United States. The **U.S. Justice Department** revealed that Moucka and his associates stole billions of sensitive customer records and terabytes of information. This data included non-content call and text history, financial details, payroll records, **Drug Enforcement Administration (DEA)** registration numbers, driver's license numbers, passport numbers, and Social Security numbers.
The group then extorted victims by threatening to publish this stolen data online. Moucka also engaged in harassment and threats against government officials and security researchers involved in tracking him. The conspirators reportedly received over $2.5 million in ransom payments, with Moucka even re-extorting a victim using stolen data of a government officer and their family.
## Co-Conspirators: A U.S. Soldier and an Elusive Hacker
One of Moucka's admitted co-conspirators is **Cameron βKiberphant0mβ Wagenius**, a former U.S. Army soldier who pleaded guilty in July 2025 to an extortion scheme involving **AT&T** and **Verizon** customer data.

Kiberphant0m also re-extorted victims and, after Moucka's arrest, allegedly posted what he claimed were **AT&T** call logs for then President-elect Donald Trump and Vice President Kamala Harris, alongside alleged schematics from the **U.S. National Security Agency (NSA)**.
Wagenius faces a maximum penalty of 20 years for conspiracy to commit wire fraud, five years for extortion in relation to computer fraud, and a mandatory two-year consecutive sentence for aggravated identity theft. His sentencing is scheduled for September 3, 2026.
The third alleged co-conspirator is **John Erin Binns**, 26, an American national who fled the U.S. after being indicted for his involvement in a 2021 breach at **T-Mobile** that exposed the personal information of at least 76 million customers.

Binns, known as **IRDev** and **IntelSecrets**, was reportedly incarcerated in a Turkish prison but has since been released and resurfaced online. Sources indicate he recently obtained Turkish citizenship, which could prevent his extradition to the U.S. under Turkish law.
## Sentencing and Legal Ramifications
Moucka pleaded guilty to four criminal counts: computer fraud, wire fraud, aggravated identity theft, and conspiracy. He faces a mandatory minimum of two years in prison for aggravated identity theft and a maximum of 30 years for the remaining counts. His sentencing is set for October 27, where a federal judge will determine the final extent of his prison term.