A 26-year-old Canadian hacker breached 165 companies and exposed data linked to 100 million people, but an investigation eventually led to his guilty plea | World News


A 26-year-old Canadian hacker breached 165 companies and exposed data linked to 100 million people, but an investigation eventually led to his guilty plea

A hacking operation that began in early 2024 reached far beyond the companies directly targeted. A 26-year-old Canadian man, Connor Riley Moucka of Kitchener, Ontario, has admitted taking part in a campaign that compromised data held by at least 165 customers of a US-based software company. The stolen material ran into billions of records and several terabytes of information, according to US court documents. It included financial details, payroll information, identity documents and records relating to calls and text messages. The attackers then demanded money from victims, while some of the stolen data was also offered for sale online. Moucka pleaded guilty in August 2026 and is due to be sentenced in October.

How the hacking operation began and exposed billions of records

The conspiracy operated between February and October 2024, according to prosecutors. Moucka and his associates obtained login credentials that allowed them to get into cloud-hosted information belonging to customers of a US software-as-a-service provider.Once inside, they were able to access the computer systems of individual customer organisations. The scale of the material taken was substantial. Investigators say the group downloaded terabytes of information and obtained billions of sensitive customer records across the affected organisations.The victims were not limited to one particular type of business. The stolen information reflected the different kinds of data held by the companies using the cloud service, which meant that the attackers gained access to records belonging to ordinary customers as well as information used internally by organisations.

What was taken from the companies

Among the information obtained were non-content records showing individuals’ call and text histories. The hackers also accessed banking and other financial information, payroll records and registration numbers associated with the US Drug Enforcement Administration.Personal identity information was part of the haul too. Driver’s licence numbers, passport numbers, Social Security numbers and other personally identifiable information were among the records taken during the breaches.According to The US Department of Justice, the consequences extended to at least 100 million people whose information was held by the affected companies. That figure refers to customers connected to the victim organisations and does not mean that every individual had every type of personal record exposed.

What was taken from the companies<br>

PC: AI Generated

The stolen data became a source of ransom demands

After obtaining the information, the conspirators began putting pressure on victims. They threatened to release stolen data publicly unless money was paid.The operation generated more than $2.5 million in ransom payments, according to prosecutors. Moucka himself received at least $495,000 from the wider scheme, as reported.In one case, the pressure did not stop after an initial extortion attempt. Moucka allegedly used previously stolen information to demand further payment from a victim, threatening another disclosure of data. The information used in that attempt included material belonging to a government officer and members of the immediate family of a former government officer.That second demand showed how stolen information could continue to be used against a victim after the original breach had taken place.

How the stolen data became another source of profit

Extortion was not the only way the group sought to make money from the stolen records.Prosecutors said the conspirators advertised data belonging to victims for sale on several cybercrime forums and through Telegram. The marketplaces named in the case included BreachForums, Exploit.in and XSS.is.The stolen information therefore had a potential value beyond the ransom demands made directly to companies. Data taken during the attacks could be offered to other people involved in cybercrime, creating another route for the information to circulate.According to the US Department of Justice, the financial damage recorded by investigators was considerably larger than Moucka’s personal proceeds. Victim companies suffered more than $9.5 million in actual losses, according to the Justice Department. That calculation does not include the losses experienced by the companies’ customers.

How investigators closed in on the Canadian suspect

The hacking campaign did not continue indefinitely. Moucka was arrested in Canada after the investigation brought international law enforcement agencies into the case.The Justice Department’s Office of International Affairs helped secure his arrest and his extradition to the United States in July 2025. The FBI worked with the Royal Canadian Mounted Police and several other foreign agencies during the investigation.Authorities from Australia, Spain, Ukraine and Turkey also assisted. Their involvement reflected the international nature of an investigation in which a Canadian suspect allegedly targeted organisations and customers in multiple jurisdictions.By the time Moucka entered his guilty plea on August 5, 2026, the case had been under investigation for nearly two years.

What charges does Moucka face after pleading guilty

Moucka pleaded guilty to four counts in the indictment. They include computer fraud, wire fraud, aggravated identity theft and a related conspiracy charge.The aggravated identity theft count carries a mandatory minimum sentence of two years in prison. The other charges carry maximum penalties of up to 30 years, although the final sentence will depend on the court’s assessment of the case, the federal sentencing guidelines and other statutory factors. Moucka is scheduled to be sentenced on October 27.His guilty plea resolves his criminal responsibility for the charges to which he admitted, but the full financial and personal impact of the breaches reaches well beyond the defendant himself. Companies recorded millions of dollars in losses, while information connected to at least 100 million people was caught up in the wider data theft.

The case forms part of a wider FBI operation

The investigation was carried out by the FBI as part of Operation Riptide, an enforcement campaign aimed at cybercriminal networks, their infrastructure and the financial systems used to support cyber-enabled crime and fraud.The Justice Department’s Computer Crime and Intellectual Property Section prosecuted the case alongside the US Attorney’s Office for the Western District of Washington. International agencies played a role in locating and arresting Moucka and bringing him to the United States.The case also sits within a broader increase in reported cybercrime losses in the US. The FBI said Americans reported more than $20 billion in cybercrime losses during the previous year, representing a 26% increase in a single year.For Moucka, the next stage is sentencing. For the organisations caught up in the 2024 breaches, the consequences began much earlier, when credentials were used to gain access to cloud-hosted systems and vast amounts of customer information were taken.



Source link

HTML Snippets Powered By : XYZScripts.com