Connor Riley Moucka, a 26-year-old from Kitchener, Ontario, has admitted to his involvement in a significant hacking and extortion operation that compromised over 165 organizations and exposed billions of sensitive records. This campaign, which ran from February to October 2024, resulted in millions of dollars in ransom payments.
Operating with co-conspirators, Moucka utilized stolen login credentials to infiltrate cloud-hosted data managed by a U.S.-based software-as-a-service provider. This unauthorized access affected at least 165 of the company’s clients. Once inside, the group downloaded terabytes of data, including non-content call and text histories, banking details, payroll information, DEA registration numbers, driver’s license and passport data, Social Security numbers, and other personally identifiable information.
The stolen data was leveraged to pressure organizations into paying ransoms, with threats of public exposure if they refused. The operation amassed over $2.5 million in ransom payments. In one instance, Moucka re-extorted a victim by threatening further disclosure of previously stolen data, which included information belonging to a government officer and relatives of a former government official. Additionally, the stolen datasets were advertised for sale on cybercrime platforms such as BreachForums, Exploit, XSS.is, and Telegram. Moucka personally received at least $495,000 from these activities.
The targeted businesses suffered more than $9.5 million in known losses, excluding the impact on their customers. The breaches affected at least 100 million individuals. Moucka has pleaded guilty to charges including computer fraud, wire fraud, aggravated identity theft, and conspiracy. His sentencing is scheduled for October 27. The aggravated identity theft charge carries a mandatory minimum prison term of two years, while the other charges could result in a maximum sentence of 30 years. The final sentence will be determined by a federal judge after reviewing sentencing guidelines and statutory factors.
The FBI led the investigation, with support from the Justice Department, the Royal Canadian Mounted Police, and law enforcement agencies in Australia, Spain, Ukraine, and Türkiye. Moucka was arrested six months after the breaches began and was extradited from Canada in July 2025. This case is part of the FBI’s Operation Riptide, an enforcement effort focused on cybercrime, fraud, criminal infrastructure, and financial networks.
This case underscores the escalating threat posed by cybercriminals who exploit cloud services to access vast amounts of sensitive data. Organizations must prioritize robust cybersecurity measures, including stringent access controls and continuous monitoring, to safeguard against such sophisticated attacks. The collaboration between international law enforcement agencies highlights the global commitment to combating cybercrime and holding perpetrators accountable.