Actor Profile

Connor Riley Moucka (aliases "Judische," "Waifu") is a 26-year-old Canadian software engineer from Kitchener, Ontario, who operated as a cybercriminal since at least 2020. Motivated by financial gain, Moucka specialized in credential theft, cloud infrastructure exploitation, and extortion. He worked with co-conspirators including U.S. Army soldier Cameron Wagenius ("Kiberphant0m") and John Erin Binns ("IRDev," "IntelSecrets"). Moucka frequently adopted new online identities and was described as one of the most consequential cybercrime threat actors of 2024. He also engaged in harassment of government officials and security researchers investigating his activities.

TTPs (Tactics, Techniques, Procedures)

Moucka's primary tactics involved credential-based initial access (T1078: Valid Accounts) targeting Snowflake cloud customer accounts lacking multi-factor authentication. The operation leveraged stolen login credentials to gain unauthorized access to cloud-hosted data (T1530: Data from Cloud Storage). The group conducted large-scale data exfiltration, downloading terabytes of sensitive information including call records, financial data, PII, and government documents. Post-compromise, the actors employed extortion (T1486-adjacent extortion tactics) by threatening public disclosure of stolen data. Moucka also engaged in re-extortion of victims and doxing/harassment of investigators and officials. The conspiracy generated over $2.5 million in ransom payments between February and October 2024.

Targets & Patterns

Moucka and co-conspirators targeted at least 165 organizations using Snowflake cloud storage services, focusing on accounts without MFA enforcement. High-profile victims included TicketMaster, Lending Tree, Advance Auto Parts, Neiman Marcus, AT&T (over 100 million customer call/text records stolen), and Verizon. The targeting pattern suggests opportunistic selection based on credential availability and weak authentication controls rather than sector-specific focus. Victims spanned telecommunications, financial services, retail, and entertainment industries. The threat actors sought organizations holding high-value personal data (SSNs, financial records, DEA registration numbers, passport data) suitable for extortion. Post-arrest, co-conspirator Kiberphant0m escalated by allegedly leaking call logs of President-elect Trump, VP Harris, and NSA schematics.

Historical Context

Moucka has been involved in data breaches and voice phishing (vishing) attacks against U.S. companies since at least 2020. His activities were first publicly documented by KrebsOnSecurity in September 2024, which revealed connections between Western cybercriminals and extremist harassment groups targeting minors. Co-conspirator John Erin Binns was previously indicted for the 2021 T-Mobile breach affecting 76 million customers before fleeing to Turkey, where he reportedly obtained citizenship to avoid extradition. Cameron Wagenius pleaded guilty in July 2025 to extorting AT&T and Verizon. The Snowflake campaign (February-October 2024) represents an escalation in scale and impact, prompting Snowflake to enforce MFA and increase password complexity requirements across its platform. Moucka was arrested in Canada in October 2024 on a U.S. provisional warrant.

Defensive Recommendations

  • Enforce multi-factor authentication (MFA) on all cloud service accounts, particularly SaaS and cloud storage platforms like Snowflake, to prevent credential-based access (T1078)
  • Implement credential monitoring and threat intelligence feeds to detect compromised credentials associated with corporate accounts before they are exploited
  • Deploy cloud access security broker (CASB) solutions to monitor for anomalous data exfiltration patterns, including unusual download volumes or access from unexpected geolocations (T1530)
  • Establish baseline activity profiles for cloud storage accounts and alert on deviations such as bulk data downloads, access outside business hours, or connections from anonymization services
  • Maintain offline, immutable backups of critical data to reduce susceptibility to extortion attempts and enable recovery without ransom payment

---

# Geopolitical Context

Geopolitical Context

This case represents a significant example of Western, English-speaking cybercriminal activity operating outside traditional state-sponsored threat frameworks. The prosecution of Connor Riley Moucka, alongside co-conspirators Cameron Wagenius (a U.S. Army soldier) and John Erin Binns (who has reportedly obtained Turkish citizenship to avoid extradition), illustrates the evolving challenge of transnational cybercrime prosecution. The involvement of a serving U.S. military member in extortion operations targeting American telecommunications infrastructure raises questions about insider threat vectors and vetting procedures. The case also highlights jurisdictional friction: while U.S.-Canada law enforcement cooperation resulted in Moucka's arrest, Binns' reported acquisition of Turkish citizenship and subsequent release from Turkish custody demonstrates how citizenship laws can create safe havens for cybercriminals. The targeting of over 165 organizations through credential-based attacks on Snowflake infrastructure—exploiting the absence of multi-factor authentication—underscores persistent gaps in cloud security posture across critical sectors, including telecommunications, financial services, and retail.

State Actor Alignment

This incident appears to be financially motivated cybercrime without apparent state sponsorship. The actors operated as an organized criminal conspiracy rather than on behalf of any government entity. However, the case intersects with state interests in several ways: Wagenius's status as an active-duty U.S. Army soldier stationed in South Korea at the time of offenses represents a significant counterintelligence concern, particularly given his access to military networks and his posting of alleged NSA schematics. Binns' reported acquisition of Turkish citizenship and Turkey's non-extradition policy for its citizens creates a diplomatic friction point between Ankara and Washington. Canadian authorities cooperated with U.S. law enforcement through the Royal Canadian Mounted Police (RCMP), resulting in Moucka's arrest on a provisional U.S. warrant—demonstrating functional Five Eyes intelligence and law enforcement coordination. The theft of DEA registration numbers and targeting of government officials' personal data also elevated this from purely private-sector crime to an issue touching national security equities.

Business Impacty pro region

For North America, this case exposes vulnerabilities in cloud service provider ecosystems that underpin critical infrastructure across telecommunications, healthcare (DEA numbers), and financial sectors. The compromise of AT&T call and text records for over 100 million customers—including alleged records of senior U.S. political figures—demonstrates how credential-based attacks can yield strategic intelligence value even when perpetrated by financially motivated actors. The breach prompted Snowflake to mandate multi-factor authentication, likely influencing security practices across the cloud services industry. For Europe and allied democracies, the case reinforces concerns about the adequacy of authentication controls in software-as-a-service environments and the risk of mass data exfiltration from cloud platforms. Turkey's role as a potential safe haven for U.S.-indicted cybercriminals may complicate NATO coordination on cybercrime matters and bilateral law enforcement cooperation. The involvement of a U.S. military member in cyber extortion operations may prompt allied nations to review insider threat protocols for personnel with access to sensitive systems, particularly those stationed overseas.

Forecast

If Moucka receives a substantial sentence in October 2025, it may serve as a deterrent signal to Western cybercriminals operating in the credential theft and cloud extortion space, particularly given the high-profile nature of the victims. However, if Binns remains beyond U.S. jurisdiction in Turkey, it is likely to encourage other indicted cybercriminals to pursue citizenship in non-extradition jurisdictions, potentially complicating future prosecutions. Wagenius's sentencing in September 2026 will be closely watched as an indicator of how military justice and civilian courts handle insider threats from active-duty personnel engaged in cybercrime. If Turkey continues to shield naturalized citizens from extradition despite NATO partnership, bilateral tensions on cybercrime cooperation may increase. In the near term, organizations using cloud infrastructure are likely to face increased pressure from insurers and regulators to enforce multi-factor authentication and credential monitoring, particularly in sectors handling sensitive personal data. The case may also accelerate legislative efforts in the U.S. and allied countries to strengthen penalties for cloud-based data extortion and to close jurisdictional gaps that enable cybercriminals to evade prosecution.