‘Hiding behind a screen’: Canadian hacker pleads guilty in data breach affecting 100M people
Aug 5, 2026, 12:44 PM
The Department of Justice building is seen. (Photo: Michael M. Santiago, Getty Images)
(Photo: Michael M. Santiago, Getty Images)
A 26-year-old Canadian man pleaded guilty Wednesday to a widespread computer hacking conspiracy that resulted in the compromise of more than 165 victim organizations, the theft of billions of sensitive customer records and the extortion of several victims.
Between February and October 2024, Connor Riley Moucka of Kitchener, Ontario, and his co-conspirators used stolen login credentials to compromise cloud-hosted data belonging to at least 165 customers of a U.S.-based software-as-a-service company, the U.S. Department of Justice (DOJ) announced.
Moucka and his co-conspirators used unauthorized access to customers’ computer systems to steal billions of sensitive customer records and download terabytes of information, which included individuals’ non-content call and text history records, banking, and other financial information, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, Social Security numbers, and additional personally identifiable information.
“Connor Moucka hacked over 150 companies and organizations, obtained extremely sensitive information, and extorted the victims for millions of dollars,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division. “Moucka was arrested just six months after these breaches began, demonstrating this Department’s firm commitment to investigating and prosecuting sophisticated cybercriminals who cause extensive harm to American businesses and consumers.”
Group raked in more than $2.5 million in ransom payments
Moucka and his co-conspirators then extorted the victims by threatening to publish their personal data online, according to court documents.
The group profited off the scheme, receiving more than $2.5 million in ransom payments. In at least one instance, Moucka “re-extorted” a victim with threats of further disclosure of the victim’s stolen data.
Moucka also used the stolen data of a government officer and members of a then-former government officer’s immediate family in the re-extortion attempt.
While Moucka and his co-conspirators extorted victims, they also advertised victims’ data for sale online by use of cybercrime forums such as BreachForums, Exploit.in, XSS.is, and Telegram.
Moucka’s actions resulted in him personally obtaining at least $495,000. The DOJ noted the harm done to the victims was much greater, with victim companies suffering more than $9.5 million in actual losses. That number does not include losses suffered by the companies’ customers, which totaled at least 100 million individuals.
Moucka pleaded guilty to four counts of the indictment, including computer fraud, wire fraud, aggravated identity theft, and a related conspiracy.
Moucka is scheduled to be sentenced on Oct. 27 and faces a mandatory minimum penalty of two years in prison for the aggravated identity theft count and a maximum penalty of 30 years in prison on the remaining counts.
A federal district court judge will determine any sentence after considering the U.S. Sentencing Guidelines and other statutory factors.
“Hiding behind a screen is no shield from justice,” said Assistant Director Brett Leatherman of the FBI’s Cyber Division. “Connor Moucka learned that when he was arrested just months after he began targeting U.S. companies, stealing sensitive information, and extorting victims for millions of dollars.”



