Skip to content

Canadian Hacker Pleads Guilty in Cloud Breach Spree Affecting More Than 165 Organizations

A Canadian man has pleaded guilty to participating in a widespread cloud hacking and extortion campaign that compromised more than 165 organizations and exposed information belonging to at least 100 million people.

Connor Riley Moucka, 26, of Kitchener, Ontario, entered guilty pleas to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy. The Justice Department announced the plea on August 5, 2026.

Stolen Credentials Used to Access Cloud Data

Between February and October 2024, Moucka and his co-conspirators used stolen login credentials to access cloud-hosted information belonging to customers of a U.S.-based software-as-a-service provider.

The attackers compromised accounts belonging to at least 165 customer organizations and downloaded terabytes of information containing billions of sensitive records.

The stolen information included:

  • Non-content call and text history records
  • Banking and other financial information
  • Payroll records
  • Driver’s license and passport numbers
  • Social Security numbers
  • Drug Enforcement Administration registration numbers
  • Other personally identifiable information

The provider is not identified in the Justice Department’s plea announcement. The campaign has been widely linked to compromises involving customers of cloud data platform Snowflake.

Victims Paid More Than $2.5 Million

After stealing the information, Moucka and other members of the operation threatened to publish it unless the affected organizations paid ransoms.

The conspirators received more than $2.5 million in ransom payments. Prosecutors say Moucka personally obtained at least $495,000 through the scheme.

In at least one case, Moucka attempted to extort a victim again after an earlier payment. He used stolen information involving a government officer and members of a former government officer’s immediate family while threatening further disclosure.

The stolen datasets were also advertised for sale through BreachForums, Exploit.in, XSS.is, and Telegram.

At Least 100 Million People Affected

The affected companies suffered more than $9.5 million in documented losses, according to prosecutors. That figure does not include losses suffered by the organizations’ customers.

DOJ estimates that the compromised records involved at least 100 million individuals.

The scale of the stolen information substantially increased the potential harm. Financial information and government identification numbers can support identity theft and fraud, while call and text history records can reveal sensitive personal and professional relationships.

Extradited From Canada

Moucka was arrested in Canada in October 2024 and later agreed to surrender for extradition to the United States.

He arrived in the Western District of Washington and made his first U.S. court appearance on July 3, 2025. The Justice Department’s case information page lists aliases associated with Moucka including “Alexander Antonin Moucka,” “judische,” “catist,” “waifu,” and “ellye18.”

Several international agencies assisted with the investigation and arrest, including the Royal Canadian Mounted Police, Australian Federal Police, Spain’s Guardia Civil, the Security Service of Ukraine, and the Turkish National Police.

Co-defendant John Erin Binns, also known online as “irdev” and “j_irdev1337,” is not presently in U.S. custody.

Sentencing Scheduled for October

Moucka is scheduled to be sentenced on October 27, 2026.

The aggravated identity theft conviction carries a mandatory minimum sentence of two years in prison. He also faces maximum penalties totaling up to 30 years on the remaining counts, although the final sentence will be determined by a federal judge after considering statutory factors and the U.S. Sentencing Guidelines.

The case forms part of Operation Riptide, an FBI campaign targeting the people, infrastructure, and financial networks supporting cybercrime and online fraud.

The guilty plea highlights a recurring weakness in cloud environments. Attackers do not always need to compromise the cloud provider itself. Stolen credentials, accounts without strong multifactor authentication, excessive access privileges, and poor monitoring can provide a direct route into large collections of centralized customer data.

Latest