SEATTLE — Canadian national Connor Riley Moucka has pleaded guilty to federal charges connected to a sweeping campaign that used stolen credentials to access accounts belonging to customers of a U.S.-based software-as-a-service company, steal billions of sensitive records and extort organizations across the United States and abroad.
Moucka, 26, of Kitchener, Ontario, entered the guilty plea Wednesday in the Western District of Washington. He admitted to computer fraud, wire fraud, aggravated identity theft and a related conspiracy.
His sentencing is scheduled for October 27, 2026. Moucka faces a maximum combined penalty of up to 32 years in federal prison, although the sentence will be determined by the court after reviewing federal sentencing guidelines and other statutory factors.
The guilty plea moves Moucka’s case beyond the accusation stage. The conduct he admitted should not be described as alleged, although charges involving any remaining defendant must continue to be treated as allegations unless resolved through a guilty plea or conviction.
Between February and October 2024, Moucka and his co-conspirators used stolen login credentials to gain unauthorized access to cloud-hosted data belonging to customers of the U.S.-based software-as-a-service company. The campaign affected at least 165 organizations and exposed enormous collections of corporate and customer information.
Across the wider campaign, the stolen information included banking records, financial information, payroll records, Drug Enforcement Administration registration numbers, driver’s license numbers, passport numbers, Social Security numbers and other personally identifiable information.
These records carried value beyond the initial extortion demands. Identity information, government registration data and financial records can be packaged for sale, used to support fraud or combined with other stolen information to create more convincing criminal schemes.
Moucka and his co-conspirators threatened to publish stolen data unless the victim organizations paid ransoms. The group received more than $2.5 million through its extortion activity.
Court records also described a re-extortion attempt in which Moucka targeted a victim for a second payment. Prosecutors said he used stolen information belonging to a government officer and members of a former government officer’s immediate family as leverage during that effort.
Re-extortion extends the pressure beyond the original demand. Payment does not guarantee that stolen information was deleted, that additional copies do not exist or that the perpetrators will not return with another threat. The same data can remain useful to the criminals long after the first payment is made.
Moucka also advertised stolen information on cybercriminal forums, including BreachForums and XSS.is. He received at least $495,000 through the sale of data obtained during the campaign.
The combined extortion payments and data sales show that the stolen records were monetized through several channels. Victim organizations were pressured directly while portions of their information were also offered to other criminals through online marketplaces.
Court documents placed losses suffered by the victim companies at more than $9.5 million. That figure reflects the direct financial damage attributed to the breaches but does not fully describe the long-term burden placed upon affected organizations and customers.
Companies confronted incident-response costs, forensic reviews, legal expenses, notification obligations and the operational work required to determine what information had been removed. Customers faced uncertainty over whether their personal, financial or communications records would be sold, published or used in future fraud.
“Connor Moucka’s threats and re-extortion tactics were calculated and predatory, and his actions did real harm to his victims, be they companies targeted for theft and extortion or the millions of everyday people who are their customers,” said FBI Special Agent in Charge W. Mike Herrington.
Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division, First Assistant U.S. Attorney Charles Neil Floyd for the Western District of Washington, Assistant Director Brett Leatherman of the FBI’s Cyber Division and Special Agent in Charge W. Mike Herrington of the FBI Seattle Field Office announced the guilty plea.
Moucka was arrested in Canada in October 2024 and consented to surrender for extradition purposes in March 2025. He was transferred to the United States and made his initial appearance in the Western District of Washington on July 3, 2025.
He initially pleaded not guilty and remained in federal custody while the case proceeded. His new guilty plea eliminates the need for prosecutors to prove the admitted charges against him at trial.
John Erin Binns was charged as Moucka’s co-defendant in the federal case. Prosecutors accused Binns of participating in computer fraud, wire fraud, aggravated identity theft, extortion and related conspiracies.
Those charges remain allegations unless Binns enters a guilty plea or is convicted in court. He is not presently in United States custody, and Moucka’s guilty plea does not establish Binns’ guilt.
The FBI investigated the case. Trial Attorneys Louisa K. Becker and George S. Brown of the Justice Department’s Computer Crime and Intellectual Property Section and Assistant U.S. Attorney Sok Tea Jiang for the Western District of Washington prosecuted the case.
The Justice Department’s Office of International Affairs provided substantial assistance in obtaining Moucka’s arrest and July 2025 extradition from Canada. The Royal Canadian Mounted Police, Australian Federal Police, Spain’s Guardia Civil, Security Service of Ukraine and Turkish National Police also provided substantial assistance.
The campaign exposed the danger created when stolen credentials remain active for extended periods. A password obtained through earlier malware activity, credential theft or another compromised system can continue providing access until the affected organization identifies the exposure and invalidates it.
Valid credentials can also make malicious activity more difficult to distinguish from ordinary account use. The attacker may enter through the same authentication system used by authorized personnel, making strong multifactor authentication, credential rotation, access restrictions and behavioral monitoring critical to detecting unauthorized activity.
Cloud customers remain responsible for protecting the identities, accounts and credentials used to reach their environments. Organizations should enforce multifactor authentication, eliminate dormant accounts, rotate exposed credentials, restrict administrative access and review unusual login activity involving unfamiliar devices, locations or large data transfers.
Moucka’s guilty plea establishes his responsibility for a campaign that reached at least 165 organizations, generated millions of dollars through extortion and data sales, and exposed information belonging to at least 100 million people.
His scheduled October sentencing will determine the punishment imposed for conduct that turned stolen credentials into a pathway for mass data theft, repeated extortion and the criminal sale of sensitive information.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified




“Moucka’s guilty plea establishes his responsibility for a campaign that reached at least 165 organizations, generated millions of dollars through extortion and data sales, and exposed information belonging to at least 100 million people.”
Yikes! It will be interesting to see what kind of sentence this guy gets. I appreciate all who have worked and are working on these cases.
Thank you for this article.
Thank you very much, and you’re very welcome, Chris.
“Yikes” is certainly the right reaction. I will be interested to see the sentence as well. The re-extortion attempt showed that this was calculated, repeated conduct rather than one reckless decision, and I would be surprised if the court treated that lightly.
Thank you again, Chris. I greatly appreciate it, and I hope you have a great day ahead. 😎
A powerful and eye-opening piece on the growing danger of cybercrime. What makes this case particularly disturbing is the sheer scale of the stolen information and the realization that behind every “record” are real people whose privacy, finances, and identity can be put at risk.
The details about re-extortion are especially troubling—it shows how stolen data can continue to threaten victims long after the original breach. The case is also a sobering reminder that digital information has enormous value in the wrong hands.
Thank you very much for reading and commenting.
This case demonstrates why containing unauthorized access is only the beginning of a proper breach response. Organizations must also determine what was taken, invalidate compromised credentials, notify affected individuals, and monitor for later misuse.
A prison sentence provides accountability, but it cannot return exposed information or guarantee that additional copies will not circulate. That lasting loss of control is one of the most serious consequences of a major data breach. Thank you again for sharing your thoughts. It is always greatly appreciated. 😎