Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty today to a widespread computer hacking conspiracy that resulted in the compromise of over 165 victim organizations, the theft of billions of sensitive customer records and the extortion of numerous victims.
“Connor Moucka hacked over 150 companies and organizations, obtained extremely sensitive information, and extorted the victims for millions of dollars,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division. “Moucka was arrested just six months after these breaches began, demonstrating this Department’s firm commitment to investigating and prosecuting sophisticated cybercriminals who cause extensive harm to American businesses and consumers. Today’s guilty plea serves as a reminder to all cybercriminals, regardless of where they live, that they cannot hide behind a wall of anonymity. You will be found and brought to justice.”
“As this case demonstrates, the cybercrimes unit in the Western District of Washington acts quickly and with precision when these hacks and intrusions impact victims in our district and around the world,” said First Assistant U.S. Attorney Charles Neil Floyd for the Western District of Washington. “I commend the work of the FBI and our counterparts in the Computer Crime and Intellectual Property Section in DC for the teamwork that resulted in Mr. Moucka taking responsibility today for his actions.”
“Hiding behind a screen is no shield from justice,” said Assistant Director Brett Leatherman of the FBI’s Cyber Division. “Connor Moucka learned that when he was arrested just months after he began targeting U.S. companies, stealing sensitive information, and extorting victims for millions of dollars. His guilty plea highlights the FBI’s commitment to protecting American businesses and consumers from cybercrime and reflects our strong partnership with the Royal Canadian Mounted Police and other international law enforcement agencies. The FBI will continue to identify, locate, and hold cybercriminals accountable, wherever they operate.”
“Today’s guilty plea sends a clear message to cybercriminals: you cannot hide from justice, no matter how hard you may try to cover your tracks,” said Special Agent in Charge W. Mike Herrington of the FBI Seattle field office. “Connor Moucka’s threats and re-extortion tactics were calculated and predatory, and his actions did real harm to his victims, be they companies targeted for theft and extortion or the millions of everyday people who are their customers. Ultimately, though, Mr. Moucka’s schemes were no match for the tenacity of FBI Seattle and this international investigative team. I am incredibly proud of their work. Let this outcome serve as a reminder: actions have consequences, and the FBI will continue to relentlessly pursue those who target American businesses and individuals in cyberspace, wherever they may be.”
According to court documents, between February and October 2024, Moucka and his co-conspirators used stolen login credentials to compromise cloud-hosted data belonging to at least 165 customers of a U.S.-based software-as-a-service company. Moucka and others used their unauthorized access to these customers’ computer systems to steal billions of sensitive customer records and download terabytes of information, including individuals’ non-content call and text history records, banking and other financial information, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, social security numbers and other personally identifiable information. They then extorted victims by threatening to publish data online.
The conspirators profited from the scheme, receiving over $2.5 million in ransom payments. In at least one instance, Moucka re-extorted a victim with threats of further disclosure of the victim’s stolen data. Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt.
In addition to extorting victims, Moucka and his co-conspirators advertised the victims’ data for sale online, including on the cybercrime forums BreachForums , Exploit.in and XSS.is, as well as on Telegram. Through these actions, Moucka personally obtained at least $495,000. The harm to the conspirators’ victims was much greater, with victim companies suffering over $9.5 million in actual losses – a number that does not include losses suffered by the companies’ customers, totaling at least 100 million individuals.
Moucka pleaded guilty to four counts of the indictment, including computer fraud, wire fraud, aggravated identity theft, and a related conspiracy. He is scheduled to be sentenced on Oct. 27 and faces a mandatory minimum penalty of two years in prison on the aggravated identity theft count and a maximum penalty of 30 years in prison on the remaining counts. A federal district court judge will determine any sentence after considering the U.S. Sentencing Guidelines and other statutory factors.
The FBI investigated the case.
Trial Attorneys Louisa K. Becker and George S. Brown of the Justice Department’s Computer Crime and Intellectual Property Section and Assistant U.S. Attorney Sok Tea Jiang for the Western District of Washington prosecuted the case. The Justice Department’s Office of International Affairs provided substantial assistance in obtaining the arrest and July 2025 extradition of Moucka from Canada.
A number of foreign law enforcement agencies provided substantial assistance in the investigation and arrest of Moucka, including the Royal Canadian Mounted Police, the Australian Federal Police, Spain’s Guardia Civil, the Security Service of Ukraine and the Turkish National Police.
CCIPS investigates and prosecutes cybercrime and intellectual property (IP) crime in coordination with domestic and international law enforcement agencies, often with assistance from the private sector. Since 2020, CCIPS has secured the conviction of over 180 cyber and IP criminals, and court orders for the return of over $350 million in victim funds.
This action is part of Operation Riptide, an FBI campaign targeting the criminal actors, infrastructure, and financial networks behind cybercrime, cyber-enabled crime, and fraud against the American people. Last year, Americans reported over $20 billion in losses to cybercrime, a 26 percent single-year increase. Operation Riptide is the FBI’s sustained enforcement response to that threat.