A Canadian man has pleaded guilty in the United States to his role in a cybercrime operation that breached at least 165 organisations, stole billions of sensitive customer records and extorted companies for millions of dollars, according to the US Department of Justice.
Get breaking news anytime, anywhere. Download the TOI app now!
Connor Riley Moucka, 26, of Kitchener, Ontario, admitted to computer fraud, wire fraud, aggravated identity theft and conspiracy charges. Prosecutors said the hacking campaign ran between February and October 2024 and targeted customers of a US-based software-as-a-service company.
According to court documents, Moucka and his co-conspirators used stolen login credentials to gain unauthorised access to cloud-hosted systems before downloading terabytes of confidential information. The stolen data included banking and financial records, payroll information, passport and driver's licence details, Social Security numbers, DEA registration numbers, and call and text history records.
Investigators said the group later demanded ransom payments by threatening to publish the stolen data online.
Millions earned through extortion
The Justice Department said the conspiracy generated more than $2.5 million in ransom payments, while Moucka personally received at least $495,000.
In one case, prosecutors said he attempted to re-extort a victim by threatening to release additional stolen information, including data belonging to a government official and members of a former government official's immediate family.
Authorities estimated that affected companies suffered more than $9.5 million in direct losses. The breaches also exposed the personal information of at least 100 million individuals, although customer losses were not included in that figure.
The stolen data was also advertised for sale on online cybercrime platforms, including BreachForums, Exploit.in, XSS.is, and Telegram, according to prosecutors.
Officials highlight international investigation
Assistant Attorney General A. Tysen Duva said the case demonstrated the department's commitment to pursuing cybercriminals operating across borders.
"Connor Moucka hacked over 150 companies and organizations, obtained extremely sensitive information, and extorted the victims for millions of dollars," Duva said.
He added: "Today’s guilty plea serves as a reminder to all cybercriminals, regardless of where they live, that they cannot hide behind a wall of anonymity. You will be found and brought to justice."
The FBI said Moucka was arrested within six months of the cyberattacks beginning.
Assistant Director Brett Leatherman said: "Hiding behind a screen is no shield from justice."
He added that the guilty plea reflected cooperation between the FBI, the Royal Canadian Mounted Police, and several international law enforcement agencies.
Sentencing scheduled for October
Moucka is scheduled to be sentenced on October 27. He faces a mandatory minimum sentence of two years for aggravated identity theft and up to 30 years in prison on the remaining charges, although the final sentence will be determined by a federal judge.
The investigation was led by the FBI, with assistance from law enforcement agencies in Canada, Australia, Spain, Ukraine and Türkiye. The Justice Department said Moucka was extradited from Canada to the United States in July 2025 as part of the case.
The prosecution forms part of Operation Riptide, an FBI initiative targeting cybercrime, cyber-enabled fraud and the financial networks behind such offences.