Notorious cyber-extortionist ‘Waifu’ convicted – lessons from the case
Paul Ducklin
08/14/2026
Share this article:
Celebrating law enforcement success
Ransomware and cyber-extortion news isn’t always about breaches, data theft, and file scrambling crises.
Once in a while, law enforcement gets hold of a cyber-blackmail suspect, brings them to court, and secures a conviction, and that’s what makes the news instead.
It’s worth celebrating these successes, because the perpetrators are often difficult to track and trace, hard to identify, and harder still to bring before a court.
The cryptocoin transactions paid out in ransomware extortions are troublesome to follow, because most cryptocurrencies provide at least pseudo-anonymity.
Attacks are typically conducted via VPNs (virtual private networks) that shield the identity of the real user, hiding their computers behind hard-to-find servers in other countries, or even deliberately redirecting the criminals’ data via unsuspecting and innocent users’ home routers or smart TVs that are infected with traffic-redirecting malware known in the jargon as a residential proxies.
And the “breach announcements” by the criminals, as well as the “negotiations” with their victims, usually happen on the dark web via Tor, a largely anonymous internet-on-top-of-the-internet.
These “announcements” often involving leaking a few records by way of convincing the victims that they really were breached, and thus that it’s worth paying a blackmail demand to have the rest of the stolen data “deleted.”
The dark web gets its name not because it’s inherently evil (though it’s certainly very widely used by cybercriminals and other online ne’er-do-wells), but because it’s effectively unilluminated and unilluminable. Search engines can’t readily index it; clients and servers can communicate with each other without either side being able to trace the connection to the other end; and law enforcement can’t easily work out where dark web servers are located, making them resistant to legal takedowns or other offensive security measures.
Conviction achieved
Sometimes, however, the Mounties, as the saying goes, get their man.
In this case, they got hold of a prolific Canadian cybercriminal called Connor Riley Moucka, known variously in cyber-underground circles by the handles judische, catist, waifu, and ellyel8.
Moucka was located and arrested by the Canadians at the request of the United States, who named him and a co-conspirator called John Erin Binns, also known as irdev and j_irdev1337, in an indictment dating back to late 2024.
The Mounties didn’t get Binns, who was apparently arrested in Turkey in early 2024, but allegedly managed to acquire Turkish citizenship after his arrest, which now shields him from extradition.
Moucka, however, was extradited from Canada to the US, where he recently pleaded guilty to the numerous charges against him, relating to crimes that followed a well-known but odious and manipulative course:
The attackers’ methods extended beyond data theft to extortion, with Moucka and his group demanding payments to prevent the sale or public release of stolen information.
In one high-profile instance, the group is alleged to have stolen 50 billion customer call and text records from a major US telecommunications company, widely believed to be AT&T.
This resulted in AT&T paying $370,000 to secure the deletion of their compromised data.
The group is reported to have successfully extorted a total of $2.5 million across multiple victims, emphasizing the lucrative and dangerous nature of these cybercrimes.
In fact, Moucka’s indictment lists six primary victims, including a “software-as-a-service provider in the US” with servers around the world.
That cloud provider was Snowflake, and this incident became widely known as the Snowflake Attack.
As you can imagine, once the attackers, including Moucka, had access to a worldwide hosting network, they were able to find and identify personal data belonging not just to Snowflake but also to many of its customers.
This added up to 165 additional victims into the fallout of the attack, according to a US court document filed about eight months after the indictment that brought these second-level victims into the matter:
The indictment alleges that they hacked into at least ten victim organizations’ protected computer systems, stole billions of sensitive customer records, threatened to leak the stolen data unless the victims paid ransoms, and offered to sell online the stolen data.
According to the Government, “[t]he investigation to date has further revealed that closer to 165 companies were likely compromised through this series of breaches, spanning major industries, including telecommunications, banking, and healthcare”․․․
As a result, there is a large number of victims in this case.
Apparently, the attackers focused on accounts without 2FA (two-factor authentication), thereby making usernames and traditional stolen passwords enough on their own to initiate an intrusion.
They seem to have acquired these initial passwords by a range of methods, including simply “buying them up” from so-called IABs (initial access brokers) operating on cybercrime forums.
Of course, this doesn’t mean that 2FA is a silver bullet against intrusions based on already-known passwords.
There are numerous convincing phishing tricks to lure victims into giving away their one-time 2FA codes, and a range of open-source tools (often available publicly on GitHub, pitched as “research projects” or “red-team tools”) to automate these lures.
One approach involves luring victims into giving away a current 2FA code by making up fake password reset or account compromise warnings, and asking for the 2FA code as a legitimate-sounding “proof of identity.”
Another attack technique aims to wear down users via so-called 2FA fatigue or approval bombing attacks, where unwanted login approvals pester the user until they either give in to make the pop-ups stop, or press the wrong button in haste and irritation.
What happens if you pay up?
We’ve asked before, “How far can you trust a ransomware criminal?”
This sounds like a rhetorical question that assumes the answer, “Not very far at all,” but it’s useful to have real-world examples that remind everyone why paying the blackmail money comes with no guarantees at all.
The US Department of Justice (DOJ) provides just such an example in its own write-up of the case:
In at least one instance, Moucka re-extorted a victim with threats of further disclosure of the victim’s stolen data.
Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt.
Presumably, Moucka squeezed money out of an organization by saying he’d delete the data he’d stolen, but deliberately kept back some or all of it so he could then target individuals with the same blackmail scheme.
Moucka pleaded guilty to the charges against him, and now faces a minimum of two years in prison on one of the charges, and an additional maximum of 30 years for the others, meaning that he could get up to 32 years for his crimes.
He’s already in custody, but he’ll find out how much longer he’ll be there when he’s sentenced in October 2026.
What to do?
Cybersecurity prevention is always better than cure, not least because stolen data can never be considered safe from disclosure. As this and other cases prove, some cyber-blackmailers quite deliberately keep hold of data they’ve already “promised” to erase. And even if your attackers genuinely intend to delete your data after getting their payoff, many of them have shown that they have very poor operational security themselves, so who knows who else has got your data already?
Many cyber-extortionists are active in multiple cybergangs at the same time. Victim details, and presumably stolen data dumps, are sometimes shuttled between multiple, competing criminal groups, making promises to suppress stolen files in return for a blackmail payment emptier than ever.
Multi-factor or two-factor authentication (MFA, 2FA) adds extra protection against rogue logins. 2FA is far from perfect, but this case is a good reminder of just how much easier it is for cyberattackers if you don’t use it.
Prepare for the worst no matter how strongly you think you’ve protected your data. If you do get breached, you need to react quickly and decisively. It’s not enough just to kick the crooks out, because you also need to figure out what they did while they were in, given that they may have opened up holes for themselves to use in the future, or to sell on to other attackers. You may also need to front up to the regulators, your customers, and the media, so decide in advance how you will divide up those important human-facing tasks.
Remember that you don’t have to do it all yourself. Stay on top of cyberthreats without distracting staff from your core business. Sign up with SolCyber to do it for you, human style.
Listen to this TALES FROM THE SOC podcast: Will we ever conquer the scourge of ransomware? Can rules and regulations help? Should we be allowed to pay off cybercriminals at all?
If the media player above doesn’t work in your browser, try clicking here to listen in a new browser tab.
Why not ask how SolCyber can help you do cybersecurity in the most human-friendly way? Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit your IT team, your colleagues, or your customers!
More About Duck
Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!
We start with identity and end with transparency — protecting where attacks begin and keeping you informed, with as much visibility as you want. No black boxes, just clear, expert-driven security.
I am interested in SolCyber Foundational Coverage™
I am interested in a Free Demo
14674
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it. Privacy policy