One of the most consequential cybercrime campaigns of 2024 has formally ended in a courtroom. Connor Riley Moucka, the 26-year-old Canadian who operated under the aliases “Judische” and “Waifu,” pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy for the extortion spree against customers of the cloud data platform Snowflake, Krebs on Security reported. For identity and cloud security teams, the case remains the cleanest large-scale demonstration on record that credential hygiene — not exotic tooling — decides breach outcomes.
A campaign built on the absence of MFA
Between February and October 2024, Moucka and his conspirators worked through more than 165 organizations that used Snowflake, a victim list that included Ticketmaster, LendingTree, Advance Auto Parts, and Neiman Marcus. The most damaging single theft hit AT&T, where call and text records of more than 100 million customers were exfiltrated. None of it required a vulnerability in Snowflake’s platform. The attackers logged in with credentials harvested by infostealer malware, targeting customer accounts that had no multi-factor authentication and no network allowlisting — then demanded payment to keep the stolen datasets private. Per the U.S. Justice Department, the conspirators extracted roughly $2.5 million in ransom payments.
The accountability ledger
Moucka faces a mandatory minimum of two years on the aggravated identity theft count and up to 30 years on the remaining charges, with sentencing scheduled for October 27, 2026. His plea lands alongside the earlier guilty pleas of Scattered Spider members, part of a broader run of prosecutions against the loosely organized, largely English-speaking cybercrime ecosystem that dominated 2023 and 2024 intrusions. The deterrence value is real but bounded: the infostealer supply chain that produced the credentials is intact, and stolen session cookies and passwords from years-old infections continue to circulate in criminal markets.
What this means
The technical remediation list from the Snowflake wave was published two years ago: enforce MFA on every data-platform account, rotate credentials exposed by infostealers, restrict access by network policy, and monitor for anomalous bulk queries. What the guilty plea adds is a management argument. The gap between “our SaaS platform supports MFA” and “MFA is enforced on every account” cost these companies nine figures in aggregate remediation and reputational damage, and one attacker collected millions before the arrests came. If enforcement of identity controls on third-party data platforms is still tracked as a backlog item rather than a closed control, this case is the budget justification.