Connor Moucka, a 26-year-old Canadian citizen, pleaded guilty in August 2026 to hacking more than 165 companies, stealing billions of records, and extorting victims for millions of dollars. The U.S. Department of Justice announced the guilty plea on Wednesday.
Moucka, known online as Waifu and Judische, exploited cloud data provider Snowflake to gain access to dozens of its customers, including AT&T, LendingTree, and Ticketmaster. The breach of AT&T alone exposed data belonging to more than 100 million customers, including call and text records. Other breaches yielded banking information, driver’s license numbers, and Social Security numbers.
Moucka and his co-conspirators collected more than $2.5 million in ransom payments over the course of the scheme. He also earned approximately $500,000 selling stolen data on hacking forums, including BreachForums. The DOJ estimates that victims suffered a combined $9.5 million in losses.
Moucka was arrested in Canada in late 2024, shortly after the Snowflake breaches came to light. Austin Larsen, a senior researcher at Google’s cybersecurity firm Mandiant, who had investigated the hacks, described Moucka at the time as “one of the most consequential” hackers of 2024.
“Connor Moucka’s threats and re-extortion tactics were calculated and predatory, and his actions did real harm to his victims, be they companies targeted for theft and extortion or the millions of everyday people who are their customers,” said W. Mike Herrington, an FBI special agent involved in the case.
Moucka is scheduled to be sentenced on October 27 and faces decades in prison. The case underscores the scale of harm that can follow a single breach of a widely used cloud platform, with millions of ordinary consumers among those affected.
Source: TechCrunch