An Ontario man has pleaded guilty in U.S. federal court to helping carry out a 2024 cyberattack that exposed the personal information of at least 100 million people and generated more than US$2.5 million in ransom payments.
Connor Riley Moucka, 26, of Kitchener, Ont., entered the guilty plea on Aug. 5 in the U.S. District Court for the Western District of Washington in Seattle, according to an Aug. 5 release by the U.S. Department of Justice (DOJ).
Moucka pleaded guilty to wire fraud, computer fraud, aggravated identity theft, and conspiracy charges pertaining to the hacking campaign that prosecutors say took place between February and October 2024 against at least 165 clients of a U.S.-based cloud storage platform.
The DOJ did not identify the platform, but cybersecurity firm Mandiant has cited the breached accounts as belonging to Snowflake.
“Connor Moucka hacked over 150 companies and organizations, obtained extremely sensitive information, and extorted the victims for millions of dollars,” Assistant Attorney General A. Tysen Duva of the DOJ’s Criminal Division said in the Aug. 5 release.
Moucka was arrested on Oct. 30, 2024, in Kitchener under a provisional arrest warrant that had been requested by American authorities and later consented to being extradited. He was transferred to the United States in July 2025 to face the charges against him.
Hack
According to court documents, Moucka and his co-conspirators used stolen login information to gain access to data hosted on the cloud platform and download terabytes of customer information containing billions of records.
Downloaded data included banking and financial information, payroll information, driver’s license and passport numbers, individual non-content phone call and text history records, Social Security numbers, and registration numbers with the Drug Enforcement Administration (DEA).
Moucka and the co-conspirators threatened to release the sensitive information online unless the companies who were targeted paid out ransoms that the hackers demanded.
Court records did not specify how many companies paid ransom, but said that the threats generated more than US$2.5 million, with Moucka personally pocketing at least US$495,000.
The companies impacted in the hack have experienced more than US$9.5 million in actual losses, although the DOJ notes that this figure does not take into account any other losses suffered by the customers of the companies.
In at least one of the cases, Moucka tried to blackmail a company for a second time saying he would release further information if they didn’t pay more. The data in that case belonged to a government officer and members of the immediate family of an ex-government officer, according to court records.
Those involved in the scheme also put stolen data up for sale on online forums and via the encrypted Telegram messaging app, according to court documents.
“Hiding behind a screen is no shield from justice,” Brett Leatherman, assistant director of the FBI’s Cyber Division, said in the Aug. 5 release.
“His guilty plea highlights the FBI’s commitment to protecting American businesses and consumers from cybercrime and reflects our strong partnership with the Royal Canadian Mounted Police and other international law enforcement agencies.”
The DOJ said that the investigation and arrest of Moucka was assisted by the RCMP, the Australian Federal Police, Spain’s Guardia Civil, the Security Service of Ukraine, and the Turkish National Police.
Moucka is scheduled to face sentencing Oct. 27 and faces a mandatory minimum sentence of two years in prison for his guilty plea on aggravated identity theft, along with up to 30 years in prison on the other charges.
