This Feb 23, 2019, photo shows the inside of a computer in Jersey City, N.J. The Biden administration will offer rewards up to $10 million for information leading to the identification of foreign state-sanctioned malicious cyber activity against critical U.S. … This Feb 23, 2019, photo shows … more >

Canadian hacker pleads guilty in scheme that breached 165 companies

by · The Washington Times

Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty to a widespread computer-hacking conspiracy that compromised more than 165 victim organizations and led to the theft of billions of sensitive customer records, according to the Justice Department.

Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division said Moucka hacked more than 150 companies and organizations, stole extremely sensitive information and extorted victims for millions of dollars. Duva said Moucka was arrested just six months after the breaches began, calling the guilty plea a warning to cybercriminals that “they cannot hide behind a wall of anonymity.”

First Assistant U.S. Attorney Charles Neil Floyd for the Western District of Washington credited the FBI and the Justice Department’s Computer Crime and Intellectual Property Section for their teamwork in securing the plea. FBI Cyber Division Assistant Director Brett Leatherman said hiding behind a screen provided no shield from justice and credited international partnerships, including the Royal Canadian Mounted Police. Special Agent in Charge W. Mike Herrington of the FBI’s Seattle field office called Moucka’s threats and re-extortion tactics “calculated and predatory.”

According to court documents, Moucka and his co-conspirators used stolen login credentials between February and October 2024 to compromise cloud-hosted data belonging to at least 165 customers of a U.S.-based software-as-a-service company. The group stole billions of records and terabytes of data, including non-content call and text history records, banking information, payroll records, DEA registration numbers, driver’s license numbers, passport numbers and Social Security numbers. The conspirators then threatened to publish the stolen data unless victims paid ransom.

The scheme generated more than $2.5 million in ransom payments, according to the Justice Department. Moucka and his co-conspirators also advertised victims’ data for sale on the cybercrime forums BreachForums, Exploit.in and XSS.is, as well as on Telegram. Through his participation in the scheme, Moucka personally obtained at least $495,000. Prosecutors said victim companies suffered more than $9.5 million in actual losses, a figure that does not include losses suffered by their customers, who totaled at least 100 million individuals. In one instance, Moucka attempted to re-extort a victim using stolen data associated with a government officer and members of a then-former government officer’s immediate family.

Moucka pleaded guilty to four counts, including computer fraud, wire fraud, aggravated identity theft and a related conspiracy charge. He is scheduled to be sentenced on Oct. 27 and, according to the Justice Department, faces a mandatory minimum of two years in prison on the aggravated identity-theft count and a maximum penalty of 30 years on the remaining counts. A federal district court judge will determine his sentence after considering the U.S. Sentencing Guidelines and other statutory factors.

The FBI investigated the case, with substantial assistance from law enforcement agencies in Canada, Australia, Spain, Ukraine and Turkey. The case is part of Operation Riptide, an FBI initiative targeting the criminal actors, infrastructure and financial networks behind cybercrime, cyber-enabled crime and fraud. According to the FBI, Americans reported more than $20 billion in cybercrime losses last year, a 26% increase from the previous year.

This article was constructed with the assistance of artificial intelligence and published by a member of The Washington Times' AI News Desk team. The contents of this report are based solely on The Washington Times' original reporting, wire services, and/or other sources cited within the report. For more information, please read our AI policy or contact Steve Fink, Director of Artificial Intelligence, at sfink@washingtontimes.com

The Washington Times AI Ethics Newsroom Committee can be reached at aispotlight@washingtontimes.com.