Canadian Man Pleads Guilty to Hacking US Cloud Storage Provider
Key Takeaways A Canadian man, Connor Riley Moucka, has pleaded guilty to charges related to a large-scale hacking and extortion scheme targeting a U.S. cloud storage provider. The operation...
Key Takeaways
- A Canadian man, Connor Riley Moucka, has pleaded guilty to charges related to a large-scale hacking and extortion scheme targeting a U.S. cloud storage provider.
- The operation compromised data from over 165 organizations, exposing billions of sensitive customer records and leading to millions in ransom payments.
- Moucka faces significant prison time, with sentencing scheduled for October 27, following his extradition from Canada.
Connor Riley Moucka, a 26-year-old from Kitchener, Ontario, has admitted guilt in a U.S. court for his involvement in an extensive computer hacking and extortion conspiracy. The criminal enterprise, which operated between February and October 2024, is accused of breaching a U.S.-based software-as-a-service (SaaS) provider, impacting at least 165 of its clients.
Table Of Content
Prosecutors detailed that the campaign led to the exposure of billions of sensitive customer records and generated millions of dollars in illicit ransom payments. The perpetrators allegedly leveraged stolen login credentials to gain unauthorized access to cloud-hosted data managed by the provider.
The Scope of the Cybercrime and Extortion
Once inside the victim networks, Moucka and his co-conspirators exfiltrated terabytes of highly sensitive personal and business information. This stolen data encompassed a wide array of confidential details, including non-content call and text histories, banking information, payroll records, DEA registration numbers, driver’s license and passport data, Social Security numbers, and other forms of personally identifiable information (PII).
Authorities revealed that the stolen data was then used as leverage to coerce organizations into paying ransoms. Victims faced threats that their sensitive information would be publicly disclosed if they failed to comply with the demands. The scheme successfully extorted over $2.5 million in ransom payments.
In one particularly egregious instance, Moucka reportedly re-extorted a victim by threatening to release additional previously stolen data. This specific threat involved sensitive information pertaining to a government officer and relatives of a former government officer. Beyond direct extortion, the pilfered datasets were also advertised for sale on prominent cybercrime forums such as BreachForums, Exploit, XSS.is, and Telegram. Moucka personally profited by at least $495,000 from the illicit operation, according to the Justice Department.
The financial impact on the targeted businesses exceeded $9.5 million in known losses, not including the significant harm inflicted upon their customers. The breaches collectively affected a minimum of 100 million individuals.
Legal Ramifications and Enforcement
Moucka pleaded guilty to multiple federal charges, including computer fraud, wire fraud, aggravated identity theft, and conspiracy. His sentencing is scheduled for October 27. The aggravated identity theft conviction alone carries a mandatory minimum prison sentence of two years, while the other charges could result in a maximum sentence of 30 years. The final sentence will be determined by a federal judge, who will consider sentencing guidelines and statutory factors.
The investigation into this widespread cybercrime was spearheaded by the FBI, with critical support from the Justice Department, the Royal Canadian Mounted Police, and law enforcement agencies from Australia, Spain, Ukraine, and Türkiye. Moucka was apprehended six months after the breaches commenced and was subsequently extradited from Canada in July 2025. This case forms a component of the FBI’s broader Operation Riptide, an initiative focused on combating cybercrime, fraud, and dismantling criminal infrastructure and financial networks.
What You Should Do
- Implement Multi-Factor Authentication (MFA): Mandate MFA for all user accounts, especially for access to cloud services and sensitive data.
- Regularly Update and Patch Systems: Ensure all software, operating systems, and cloud environments are kept up-to-date with the latest security patches.
- Strengthen Credential Management: Enforce strong, unique passwords and consider passwordless authentication where feasible. Regularly audit and rotate credentials.
- Monitor for Unauthorized Access: Implement robust logging and monitoring solutions to detect unusual login attempts, data access patterns, or suspicious activities within cloud environments.
- Conduct Employee Security Training: Educate staff on phishing, social engineering tactics, and the importance of secure password practices to prevent credential theft.
- Backup Data Securely: Maintain isolated, encrypted backups of critical data to facilitate recovery in the event of a breach or ransomware attack.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.