Canadian Hacker Pleads Guilty in Cloud Data Extortion Case
- OpusDatum

- Aug 5
- 2 min read

Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty on 5 August 2026 to a computer hacking conspiracy that compromised more than 165 victim organisations and resulted in the theft of billions of sensitive customer records. According to court documents, Moucka and his co-conspirators used stolen login credentials between February and October 2024 to access cloud-hosted data belonging to customers of a US-based software-as-a-service company, exfiltrating terabytes of information including non-content call and text history records, banking and financial information, payroll records, Drug Enforcement Administration (DEA) registration numbers, driving licence numbers, passport numbers and social security numbers. Victims were then extorted under threat of publication.
The conspirators received over $2.5 million in ransom payments, with Moucka personally obtaining at least $495,000. Victim companies reported more than $9.5 million in actual losses, excluding harm to their own customers, who numbered at least 100 million individuals. Stolen data was also advertised for sale on the cybercrime forums BreachForums, Exploit.in and XSS.is, and on Telegram. Moucka pleaded guilty to four counts including computer fraud, wire fraud, aggravated identity theft and a related conspiracy, and is scheduled for sentencing on 27 October. The Federal Bureau of Investigation (FBI) investigated, with substantial assistance from the Royal Canadian Mounted Police (RCMP), the Australian Federal Police (AFP), Spain's Guardia Civil, the Security Service of Ukraine (SBU) and the Turkish National Police.
Three features of the case warrant close attention from UK compliance and financial crime teams. The first is the intrusion method: the compromise relied on stolen credentials rather than on any exotic exploitation, and it propagated across a single provider's customer base. Firms carrying material data holdings in third-party cloud environments should be able to evidence, at tenant level, that multi-factor authentication is enforced, that credential rotation follows staff and contractor departures, and that anomalous bulk-export activity is monitored rather than merely logged. Concentration risk of this kind falls squarely within existing operational resilience and outsourcing expectations.
The second is the downstream fraud exposure. Datasets combining call records, banking details, payroll data and identity documents supply precisely the material used to construct convincing impersonation attacks. Institutions whose customers appear in such breaches should anticipate elevated account takeover attempts and authorised push payment fraud, and should consider whether detection thresholds and step-up authentication triggers remain calibrated for counterparties operating with accurate personal data.
The third concerns the handling of extortion demands. In at least one instance, Moucka re-extorted a victim with threats of further disclosure, using stolen data belonging to a government officer and to members of a then-former government officer's immediate family. Payment did not extinguish the exposure. For UK firms, any decision to pay engages sanctions screening obligations, potential principal money laundering offences under the Proceeds of Crime Act 2002, and reporting considerations under the Financial Conduct Authority (FCA) rules and to the Information Commissioner's Office (ICO). Those pathways are best resolved in advance of an incident rather than during one.
Read the press release here.
%20-%20C.png)