
Connor Moucka, a 26-year-old national of Canada, has admitted to hacking over 165 businesses, pilfering billions of records, and extorting numerous organizations and individuals.
The U.S. Department of Justice revealed the guilty plea in a press announcement on Wednesday.
Moucka was alleged to have hacked into cloud service provider Snowflake, which enabled him and his associates to gain access to many of the company’s clients, including AT&T, LendingTree, and Ticketmaster. He absconded with data from more than 100 million AT&T users, encompassing call and text logs, along with banking details, driver’s license identifiers, and Social Security numbers from various breaches.
Throughout the years, Moucka and his partners collected over $2.5 million in ransom payments. The hacker also garnered approximately $500,000 from selling victims’ data on hacking platforms like the infamous BreachForums. According to the DOJ, victims of the hacks perpetrated by Moucka and his collaborators incurred losses totaling $9.5 million.
“Connor Moucka’s threats and re-extortion strategies were deliberate and predatory, causing real damage to his victims, whether they were companies targeted for theft and extortion or the millions of ordinary individuals who are their customers,” stated W. Mike Herrington, an FBI special agent involved in the investigation.
Moucka, who went by the online aliases Waifu and Judische, was apprehended in Canada towards the end of 2024, shortly after the Snowflake breaches occurred.
At that time, Austin Larsen, a senior researcher at Google’s cybersecurity firm Mandiant who had been probing the Snowflake hacks, remarked that Moucka was “one of the most impactful” hackers of 2024.
Moucka’s sentencing is set for October 27, where he could face decades behind bars.

