DTWdailytechwire
Tech Intelligence, Wired Daily
Policy

Canadian Hacker Faces Decades Behind Bars After $12 Million Cloud Data Raid

A 26-year-old's guilty plea closes the book on one of 2024's most damaging breach campaigns, exposing how credential stuffing turned cloud infrastructure into a wide-open vault.

DR
Daniel R. Whitfield
Markets & Venture Reporter · Hong Kong
Aug 7, 2026
4 min read
Canadian Hacker Faces Decades Behind Bars After $12 Million Cloud Data Raid
Canadian Hacker Faces Decades Behind Bars After $12 Million Cloud Data RaidCredit: Joan Cros / Getty Images

The Guilty Plea That Ended a Ransomware Spree

A 26-year-old Canadian national has admitted to orchestrating one of the most financially damaging breach campaigns in recent memory. Connor Moucka entered a guilty plea this week in U.S. federal court, acknowledging responsibility for compromising more than 165 companies, exfiltrating billions of customer records, and extracting millions in ransom payments.

The U.S. Department of Justice disclosed the plea agreement on Wednesday, marking the conclusion of an investigation that began when security researchers first detected anomalous access patterns in Snowflake customer environments during mid-2024. Moucka, who operated under the online aliases Waifu and Judische, leveraged compromised credentials to penetrate the cloud data platform and pivot into dozens of corporate tenants.

His targets included household names: AT&T lost call and text metadata for over 100 million subscribers, Ticketmaster suffered a breach exposing event-goer details, and LendingTree saw banking credentials and Social Security numbers siphoned from its systems. Across the campaign, Moucka and his collaborators collected more than $2.5 million in extortion payments and an additional $500,000 from selling stolen datasets on underground forums, including BreachForums.

How Credential Stuffing Became a Skeleton Key

The Snowflake intrusions did not rely on novel zero-day exploits or supply-chain implants. Instead, Moucka and his team used credential stuffing, recycling username-password pairs harvested from previous breaches and testing them against corporate Snowflake accounts that lacked multi-factor authentication.

Once inside a single customer environment, attackers enjoyed broad visibility into data warehouses that companies had centralized for analytics and business intelligence. The architecture of modern cloud data platforms means a single compromised account can unlock terabytes of sensitive information, from transaction logs to personally identifiable records.

At DailyTechWire, we've tracked the steady drumbeat of credential-based cloud breaches over the past eighteen months. What distinguishes Moucka's campaign is scale: rather than focusing on a handful of high-value targets, he systematically enumerated Snowflake customers, testing credentials in bulk and monetizing access through parallel extortion and data-sale channels.

The Human and Financial Toll

Victims reported cumulative losses of $9.5 million, according to the Department of Justice. That figure captures direct costs such as incident response, forensic analysis, legal fees, and regulatory fines, but it excludes harder-to-quantify damage like customer churn and reputational harm.

For AT&T customers, the breach exposed call and text metadata that, while not containing message content, revealed patterns of communication over months. Financial services victims saw driver's license numbers, Social Security numbers, and bank account details flow onto dark-web marketplaces, fueling identity fraud and account takeover attacks.

FBI Special Agent W. Mike Herrington, who led the investigation, described Moucka's tactics as "calculated and predatory," noting that the hacker employed re-extortion strategies, returning to victims who had already paid to demand additional sums or threaten wider data publication.

Arrest and Attribution

Canadian authorities arrested Moucka in late 2024, months after the Snowflake breaches first came to light. At the time, Austin Larsen, a senior researcher at Mandiant (Google's threat intelligence arm), characterized Moucka as "one of the most consequential" hackers of the year, pointing to the breadth of affected organizations and the volume of exfiltrated records.

The investigation benefited from cooperation between U.S. and Canadian law enforcement, as well as telemetry shared by Snowflake and affected customers. Digital forensics linked Moucka's online personas to cryptocurrency wallets that received ransom payments, and chat logs recovered from seized devices detailed negotiations with victims and coordination with co-conspirators.

Moucka is scheduled for sentencing on October 27. Federal prosecutors have indicated they will seek a lengthy prison term, citing the scope of the scheme, the financial harm inflicted, and the defendant's role in operating a for-profit extortion enterprise. Under U.S. sentencing guidelines for computer fraud and aggravated identity theft, he faces the possibility of decades behind bars.

What the Case Reveals About Cloud Security Posture

The Snowflake incident underscores a persistent gap between cloud platform capabilities and customer implementation. Snowflake offered multi-factor authentication as a feature, but enforcement was left to individual organizations. Many enterprises treated cloud data warehouses as internal systems, applying weaker access controls than they would to internet-facing applications.

In the wake of the breaches, Snowflake introduced mandatory MFA for all administrative accounts and published updated security baselines. The company also launched a customer notification program to flag accounts with suspicious login patterns, drawing on machine learning models trained to detect credential stuffing and anomalous data export activity.

The broader lesson for Asia-Pacific enterprises, which are rapidly adopting cloud analytics platforms, is that shared-responsibility models require active security hygiene. Cloud providers secure the infrastructure; customers must secure identities, enforce least-privilege access, and monitor for anomalous behavior.

Looking Ahead: Enforcement and Deterrence

Moucka's guilty plea represents a rare prosecutorial win in a domain where attackers often operate across jurisdictions with impunity. The collaboration between U.S. and Canadian authorities, combined with private-sector threat intelligence, demonstrates that sustained investigation can pierce the anonymity that cybercriminals rely on.

Yet the economics of data extortion remain attractive. The $3 million Moucka netted from his campaign is modest compared to the billions held in corporate data warehouses, and the technical barriers to entry are low for actors willing to invest in credential databases and automation tooling.

As sentencing approaches, the case will serve as a bellwether for how courts weigh the systemic harm of mass data theft against the relatively young age of many defendants in this space. For now, the plea closes one chapter in a story that continues to unfold across cloud platforms, where the tension between accessibility and security remains unresolved.

Read next
Policy

FCC Scraps National Broadcast Cap in 2-1 Vote, Setting Stage for Legal Fight

Marcus Halloran · 4 min
Policy

Safari's Private Relay Leaks IP Addresses Through Passkey Authentication

Daniel R. Whitfield · 4 min
Policy

Beijing Opens Cybersecurity Review of Palo Alto Networks Products

Wei Zhang · 4 min
Spot something wrong? Email corrections@dailytechwire.com. We log every correction publicly.