Man living in Kitchener, Ont. alleged to be involved in massive data breach
A man accused in a massive data breach, impacting several large international companies, has been located in Kitchener, Ont.
Connor Moucka, also known as Alexander Moucka, was until recently living at a home in the city’s Stanley Park neighbourhood.
The 25-year-old was arrested in October and is now facing an U.S. extradition request.
Court documents detailed the allegations made against Moucka and his co-accused, John Erin Binns, who is believed to be living in Türkiye.
The U.S. court indictment stated Moucka and Binns "devised and executed international computer hacking and wire fraud schemes to hack into at least 10 victim organizations’ protected computer networks, steal sensitive information, threaten to leak the stolen data unless the victims paid ransoms, and offer to sell online, and sell, the stolen data."
It also alleged they successfully extorted about $2.5 million from at least three of the victims who paid the ransoms and then posted offers online to sell the stolen data for millions of dollars.
Moucka is facing charges of conspiracy, computer fraud and abuse, extortion in relation to computer fraud, wire fraud and aggravated identity theft.
While no companies were named in the court documents, experts agree the details match a hack that happened earlier this year involving customers of Snowflake, a cloud-based data storage company based in the U.S.
“One of the third parties that companies pay to manage their data on Snowflake was compromised,” explained David Jao, chief cryptographer at evolutionQ, a University of Waterloo professor and a member of the Cybersecurity and Privacy Institute. “Through them, the hackers got a bunch of usernames and, in some cases passwords, and they used those usernames and passwords to get into the main accounts of these bigger companies.”
AT&T, Live Nation, Ticketmaster and Advance Auto Parts were among the companies that admitted they were affected by the data breach.
“It is certainly one of the biggest cybersecurity breaches that we’ve had in history,” Jao told CTV News.
The court documents identified one victim as a major telecommunications company in the U.S., which had about 50 billion customer call and text records stolen.
Other victims are described as a major retailer, a major entertainment company and a major healthcare company.
Documents prepared by the RCMP ahead of Moucka’s arrest outlined the seriousness of the allegations and their concerns he was a serious flight risk. They also noted that as of October 2024, Moucka continued to hack and had attempted to re-extort one of the victims.
The RCMP affidavit described Moucka as a danger to the public, to police and to himself, quoting online messages from one of his accounts that said: “I think I’d make a really good serial killer,” “I think I want to do suicide by cop,” and “I need guns to kill Canadians.”
According to the Department of Justice Canada, Moucka was arrested on Oct. 30 and appeared in court later that same day. He had another court appearance in November, where he indicated he was still waiting for a decision on legal aid.
Moucka is scheduled to be back in court on Nov. 29.
The case remains before the courts and nothing has been proven at this time.
Jao said that, while it appears the two alleged masterminds have been identified, the work continues for investigators.
“The case is not over, there are still other criminals that are out there that have not been caught yet.”
CTVNews.ca Top Stories
War monitor says Assad has fled Syria after rebels enter capital
The head of a Syrian opposition war monitor said early Sunday that Syria’s President Bashar Assad left the country for an undisclosed location.
Canada Post strike: Union 'extremely disappointed' in latest offer, negotiator says
A negotiator for the Canadian Union of Postal Workers (CUPW) says the latest offer from Canada Post to end the ongoing strike shows the carrier is moving in the "opposite direction."
Search for UnitedHealthcare CEO's killer yields evidence, but few answers
As the search for UnitedHealthcare CEO Brian Thompson’s killer goes on, investigators are reckoning with a tantalizing dichotomy: They have troves of evidence, but the shooter remains an enigma.
Digging themselves out: With Santa Claus parade cancelled, Londoners make best of snowy situation
Londoners continue to dig themselves out from this week’s massive snowstorm.
Trump is welcomed by Macron to Paris with presidential pomp and joined by Zelenskyy for their talks
French President Emmanuel Macron welcomed Donald Trump to Paris with a full dose of presidential pomp for the reopening of the Notre Dame Cathedral.
Groups launch legal challenge against Alberta's new gender-affirming treatment law
A pair of LGBTQ2S+ advocate organizations say they've followed through with their plan to challenge Alberta's three transgender bills in court, starting with one that bars doctors from providing gender-affirming treatment such as puberty blockers and hormone therapy for those under 16.
Canada's air force took video of object shot down over Yukon, updated image released
The Canadian military has released more details and an updated image of the unidentified object shot down over Canada's Yukon territory in February 2023.
U.S. announces nearly US$1 billion more in longer-term weapons support for Ukraine
The United States will provide nearly US$1 billion more in longer-term weapons support to Ukraine, Defense Secretary Lloyd Austin said Saturday.
New plan made to refloat cargo ship stuck in St. Lawrence River for two weeks
Officials say they have come up with a new plan to refloat a large cargo ship that ran aground in the St. Lawrence River two weeks ago after previous efforts to move the vessel were unsuccessful.