Connor Riley Moucka, 26, of Kitchener, Ontario, was found guilty on August 5, 2026, for orchestrating a hacking and extortion scheme that compromised at least 165 organizations and exposed billions of sensitive customer records This article explores moucka extorting victim. . Between February and October 2024, Moucka and unnamed accomplices used stolen login credentials to breach cloud-hosted environments belonging to customers of a U.S.-based SaaS provider.

The method employed was credential-based access rather than exploiting software vulnerabilities, allowing the group to exfiltrate terabytes of data, including non-content call and text records, banking details, payroll files, DEA registration numbers, driver’s license and passport numbers, and Social Security numbers. This scale is among the largest credential-stuffing-enabled breaches ever recorded, affecting an estimated 100 million individuals across the victim companies' customer bases.

One notable case involved Moucka re-extorting a victim after leveraging previously obtained data tied to a government official and their immediate family members. Investigative support came from the Royal Canadian Mounted Police, Australian Federal Police, Spain’s Guardia Civil, Ukraine’s Security Service, Turkish National Police, and FBI agents, who led the investigation. Since 2020, the DOJ’s Computer Crime and Intellectual Property Section has secured convictions of over 180 cyber and IP criminals and recovered more than $350 million for victims, demonstrating sustained federal focus on SaaS and cloud-based attack vectors.