Ontario man pleads guilty to multi-million-dollar U.S. data theft and ransom demands
- A Canadian man, Connor Riley Moucka, pleaded guilty in the U.S. to computer hacking conspiracy involving over 165 companies, stealing more than 50 billion consumer records, and extorting millions of dollars.
- Moucka admitted to using stolen login credentials to hack Snowflake's cloud platform between February and October 2024, exploiting previously stolen passwords that lacked multi-factor authentication.
- He faces up to 30 years in prison, a mandatory minimum of two years for aggravated identity theft, and possible restitution payments exceeding $9.5 million for ransom and incident response costs.
- Moucka was arrested in Canada in November 2024, extradited to the U.S. in July 2025, and remains in custody; his American co-conspirator, John Binns, is in custody in Turkey facing separate charges.
A Canadian man has pleaded guilty in the U.S. to a computer hacking conspiracy that affected more than 165 companies, involved the theft of over 50 billion consumer records and resulted in the extortion of millions of dollars, sometimes involving more than one ransom demand from the same victim.
The U.S. Department of Justice yesterday announced that 26-year-old Connor Riley Moucka of Kitchener, Ont., had pleaded guilty to four charges including computer fraud, wire fraud, use of stolen credentials and aggravated identity theft.
He is due to be sentenced on Oct. 27 and faces a mandatory minimum sentence of two years in prison on the aggravated identity theft count, and a possible 30 years on the remaining counts. He could also be ordered to pay restitution to victims for their incident response and ransom costs, which totalled at least US$9.5 million.
According to court documents, between February and October of 2024 Moucka and an American co-conspirator, John Binns, used stolen login credentials to hack into and steal information from Snowflake, a cloud-based platform.
According to the website thehackernews, the credentials had actually been stolen years earlier — as far back as November 2020 — but the passwords had largely not been changed, and the accounts had multi-factor authentication switched off, making the hack easier.
The stolen data included call and text history records, banking and other financial information, payroll records, Drug Enforcement Administration registration numbers, driver’s license numbers, passport numbers, social security numbers and other personally identifiable information.
At least 10 organizations whose data was stolen received ransom demands ranging from $300,000 to $5 million in return for promises to not leak the stolen data. The suspects also advertised victims’ data for sale online on cybercrime forums.
The Department of Justice said the conspirators received more than $2.5 million in ransom payments. In at least one case, Moucka is alleged to have re-extorted a government officer and members of that person’s family with threats of further disclosure of the victim’s stolen data.
“Connor Moucka’s threats and re-extortion tactics were calculated and predatory, and his actions did real harm to his victims, be they companies targeted for theft and extortion or the millions of everyday people who are their customers,” said Special Agent in Charge W. Mike Herrington of the FBI Seattle field office in a statement.
Moucka admitted that he personally received at least $495,000 from ransom payments (which he has also agreed to forfeit) and that he hacked under a variety of aliases, including Alexander Moucka, catist, ellyel8, judische and waifu.
The Justice Department noted that Canadian law enforcement, acting on a U.S. arrest warrant, arrested Moucka in Ontario in November 2024. He agreed to be extradited in March 2025, and this took place in July 2025. He remains in custody.
Binns, who was also indicted by the U.S. in 2022 for a separate hacking attack, is said to be in custody in Turkey on separate hacking and privacy violation charges and could face extradition.
“Today’s guilty plea serves as a reminder to all cybercriminals, regardless of where they live, that they cannot hide behind a wall of anonymity,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division. “You will be found and brought to justice.”