Connor Riley Moucka, a 26-year-old resident of Kitchener, Ontario, has pleaded guilty in the United States for his role in a major computer hacking and extortion conspiracy.
Prosecutors said the campaign compromised more than 165 organizations, exposed billions of sensitive customer records, and generated millions of dollars in ransom payments.
According to court documents, Moucka and his co-conspirators operated between February and October 2024. The group allegedly used stolen login credentials to gain unauthorized access to cloud-hosted data managed by a U.S.-based software-as-a-service provider. The intrusions affected at least 165 of the company’s customers.
After entering victim environments, the conspirators downloaded terabytes of data containing highly sensitive personal and business information.
The stolen material included non-content call and text history records, banking details, payroll information, DEA registration numbers, driver’s license and passport data, Social Security numbers, and other personally identifiable information.
Authorities said the group used the stolen data to pressure organizations into paying ransoms. Victims were threatened with public exposure of their information if they refused to pay.
The operation received more than $2.5 million in ransom payments. In one case, Moucka allegedly re-extorted a victim by threatening additional disclosure of previously stolen data. Prosecutors said that effort involved data belonging to a government officer and relatives of a former government officer.
The stolen datasets were also advertised for sale on cybercrime channels, including BreachForums, Exploit, XSS.is, and Telegram. Moucka personally received at least $495,000 from the scheme, according to the Justice Department.
Businesses targeted in the campaign suffered more than $9.5 million in known losses, excluding harm to their customers. The breaches affected at least 100 million individuals.
Moucka pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy. He is scheduled to be sentenced on October 27.
The aggravated identity theft conviction carries a mandatory minimum prison term of two years, while the other charges can carry a maximum sentence of 30 years. A federal judge will set the final sentence after reviewing sentencing guidelines and statutory factors.
The FBI led the investigation with support from the Justice Department, the Royal Canadian Mounted Police, and law enforcement agencies in Australia, Spain, Ukraine, and Türkiye. Moucka was arrested six months after the breaches began and was extradited from Canada in July 2025.
The case forms part of the FBI’s Operation Riptide, an enforcement effort focused on cybercrime, fraud, criminal infrastructure, and financial networks.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…