-
A Canadian man pleaded guilty to hacking a U.S. cloud service provider and accessing data belonging to at least 165 organizations.
-
According to U.S. court documents, the attackers stole billions of records and collected more than $2.5 million in ransom payments.
-
The suspect now faces multiple federal charges and is scheduled for sentencing on Oct. 27.
A Canadian man has admitted to taking part in a large hacking and extortion scheme that affected organizations across the United States and beyond.
According to the U.S. Department of Justice, Connor Riley Moucka, 26, pleaded guilty to several federal charges after investigators linked him to attacks that exposed sensitive data belonging to more than 165 organizations.
Court documents show the attacks took place between February and October 2024. During that time, Moucka and his co-conspirators broke into cloud-hosted systems owned by customers of a U.S.-based software-as-a-service company. The group allegedly used stolen login details to enter the systems without permission.
According to the court filings, the attackers downloaded terabytes of information containing billions of sensitive customer records.
The stolen data included banking details, payroll records, passport numbers, driver’s license numbers, Social Security numbers, Drug Enforcement Administration registration numbers, call and text history records, and other personal information.
The group later demanded ransom payments and threatened to publish the stolen data online if victims refused to pay.
Officials say the attacks caused widespread harm
According to the Department of Justice, Assistant Attorney General A. Tysen Duva said Moucka targeted more than 150 companies and organizations, stole highly sensitive information, and demanded millions of dollars from victims.
Duva added that investigators arrested the suspect only six months after the attacks began, showing the department’s determination to pursue cybercriminals who cause major damage to businesses and consumers.
He also warned that people involved in cybercrime should not expect anonymity to protect them because authorities will continue working to identify and prosecute them.
First Assistant U.S. Attorney Charles Neil Floyd for the Western District of Washington also praised the investigation. According to Floyd, the case shows how quickly the district’s cybercrime team responds when attacks affect victims locally and internationally.
He credited the FBI and the Justice Department’s Computer Crime and Intellectual Property Section for working together to bring the case forward and secure Moucka’s guilty plea.
Assistant Director Brett Leatherman of the FBI’s Cyber Division said hiding behind a computer does not protect criminals from facing justice. According to Leatherman, authorities arrested Moucka just months after he allegedly targeted U.S. companies, stole sensitive information, and demanded ransom payments.
He added that the guilty plea reflects the FBI’s commitment to protecting businesses and consumers while working closely with the Royal Canadian Mounted Police and other international law enforcement partners.
Special Agent in Charge W. Mike Herrington of the FBI Seattle Field Office also described the attacks as carefully planned and harmful. According to Herrington, the threats and repeated extortion attempts affected the targeted organizations as well as millions of individuals whose information those companies stored.
He added that the outcome demonstrates the determination of investigators and serves as a reminder that cybercriminals will continue to be pursued wherever they operate.
Investigators say the group earned millions from the scheme
According to court documents published by the Department of Justice, the conspiracy collected more than $2.5 million through ransom payments. Investigators also said Moucka personally received at least $495,000 from the operation.
The court filings state that the group did more than demand ransom. They also advertised stolen information for sale on cybercrime platforms, including BreachForums, Exploit.in, XSS.is, and Telegram.
The same platform has become a vector for malware distribution. Cambodian authorities recently warned citizens about a Telegram malware campaign where compromised accounts send fake file attachments disguised as business plans, confidential documents, or urgent notices.
In one case, Moucka allegedly tried to extort the same victim again by threatening to release additional stolen information. Investigators said he also used data belonging to a government officer and members of a former government official’s immediate family during that attempt.
Authorities estimate the affected organizations suffered more than $9.5 million in direct losses. That figure excludes customers whose personal information was exposed. According to the court documents, at least 100 million individuals were affected by the stolen records.
Guilty plea brings the case closer to sentencing
Moucka pleaded guilty to four charges. They include computer fraud, wire fraud, aggravated identity theft, and conspiracy related to those offenses, according to the Department of Justice. He is scheduled to be sentenced on Oct. 27.
The aggravated identity theft charge carries a mandatory minimum prison term of two years. The remaining charges each carry a maximum sentence of up to 30 years. A federal judge will decide the final sentence after evaluating the United States Sentencing Guidelines as well as other legal criteria.
The FBI investigated the case with help from several international agencies. According to the Department of Justice, support came from the Royal Canadian Mounted Police, the Federal Police of Australia, the Guardia Civil of Spain, Ukraine’s Security Service, and the National Police of Turkey.
The Justice Department’s Office of International Affairs also assisted with Moucka’s arrest in Canada and his extradition to the United States in July 2025.
The case forms part of Operation Riptide, an FBI campaign focused on disrupting cybercriminals, their infrastructure, and the financial networks that support cyber-enabled crime and fraud targeting the American public, according to the U.S. Department of Justice.