Cybercrime: A Canadian’s Digital Extortion Gambit
Extortionist Connor Moucka, 26, Helped Breach Over 150 Customer Accounts
In a troubling development for cybersecurity, a Canadian national, Connor Riley Moucka, aged 26, recently pleaded guilty to a series of serious cybercrimes that put the sensitive data of over 150 customers of Snowflake, a leading cloud-based data warehousing platform, at risk. The breach, involving the misuse of stolen login credentials, was characterized by significant extortion tactics where Moucka successfully extorted three victims.
Moucka’s legal troubles can be traced back to an 11-count indictment unsealed in November 2024, which accused him and an accomplice, American national John Binns, of orchestrating a major breach affecting more than 165 organizations. The indictment revealed that the duo had unlawfully accessed terabytes of data from Snowflake’s system, capturing a staggering 50 billion call and text records. In the course of their operation, they extorted victims for no less than 36 bitcoins, equivalent to approximately $3.4 million at the time.
Entering a plea deal, Moucka admitted responsibility for four of the eleven charges laid against him, which included computer fraud, wire fraud, aggravated identity theft, and conspiracy related to the crimes. The timeline of his illicit activities stretched from February to October 2024, during which he reportedly profited to the tune of at least $495,000 from ransom payments—an amount he has agreed to forfeit. The hacker’s aliases were many, blending the names Alexander Moucka, catist, ellyel8, judische, and waifu, under which he executed his malicious schemes.
Moucka is scheduled for sentencing on October 27, and faces a mandatory minimum of two years in prison for the aggravated identity theft charge, with the potential of a maximum of 30 years for the other charges. Additionally, he may be compelled to pay restitution amounting to at least $9.5 million, which reflects the total costs incurred by victims in connection with incident response and ransom payments.
The hack did not only target financially lucrative corporations; it also involved compromising sensitive information from at least nine organizations, resulting in substantial harm. The stolen data spanned a plethora of sensitive information including billions of customer records: telephone call logs, financial and banking information, payroll details, Drug Enforcement Agency registration numbers, and personally identifiable information such as driver’s license, passport, and Social Security numbers.
Victims listed in Moucka’s plea agreement included a diverse array of companies—a major telecommunications provider, a retailer, an entertainment company, a healthcare organization, and a data storage firm, all situated within the United States. Notably, among the victims were well-known entities such as Santander Bank, Advance Auto Parts, Live Nation Entertainment’s Ticketmaster, Neiman Marcus, the Los Angeles Unified School District, and Bausch Health.
Mandiant, the incident response group hired by Snowflake to investigate the breaches, reported that ransom demands ranged between $300,000 to $5 million, with at least ten organizations that had their data exfiltrated facing such extortion attempts. Additionally, it has come to light that at least once Moucka executed a “re-extortion” tactic, threatening to leak data even after receiving payment.
The severity of Moucka’s actions has been described as calculated and predatory, causing real harm to the companies affected and the millions of consumers whose data was put at risk. Assistant Attorney General A. Tysen Duva emphasized the scale of the breaches, underscoring the harsh reality of Moucka’s criminal activity.
Canadian law enforcement, acting on a U.S. arrest warrant, arrested Moucka in Ontario in November 2024. He subsequently agreed to extradition to the United States in March 2025 and was extradited in July 2025, shortly before facing the legal charges against him in Seattle federal court.
Authorities have pointed to “Operation Riptide,” an FBI-led initiative addressing cybercrime and large-scale fraud networks, under which the investigation was conducted. In 2025 alone, Americans reported losses exceeding $20 billion due to various cybercrimes, marking a 26% increase from the previous year.
The investigation received support from foreign law enforcement agencies globally, including organizations from Canada, Australia, Spain, Ukraine, and Turkey. This collaboration emphasizes the international nature of cybercrime, where digital criminals often operate across borders, making enforcement challenging.
While Moucka’s case unfolds, significant questions linger regarding cybersecurity measures in the corporate world. Investigators noted that the breached organizations had failed to utilize multifactor authentication (MFA) effectively, which would have added an additional layer of security and potentially thwarted such attacks. In response to the breach, Snowflake has since taken substantial steps to enhance its security protocols, mandating MFA and establishing stricter password policies to reinforce user account protections.
With the repercussions of Moucka’s actions still reverberating through the affected organizations in the wake of the breaches, individuals and businesses alike remain acutely aware of the ever-evolving landscape of cyber threats in the digital age.
