Canadian Hacker Who Advertised Stolen Data on BreachForums Pleads Guilty

Canadian Hacker “Waifu” Pleads Guilty to Stealing Data from Over 165 Organizations

Connor Riley Moucka, aka Waifu, admits breaching over 165 organizations, stealing billions of records and advertising the data on BreachForums, XSS.is and Exploit.in.

Listen to this article

0:00

Press play to start listening

A 26-year-old Canadian man has pleaded guilty to participating in a cyberattack campaign that compromised cloud-hosted data belonging to at least 165 organizations. Connor Riley Moucka (also known as Judische and Waifu) of Kitchener, Ontario, and his co-conspirators stole billions of sensitive customer records and extorted numerous victims, according to US prosecutors.

The campaign ran between February and October 2024 and targeted customers of a US-based software-as-a-service company. In its press release, the US Department of Justice said the group used stolen login credentials to access cloud-hosted databases.

Stolen Credentials and Extortion Tactics

Once inside the accounts, the conspirators downloaded terabytes of data containing sensitive personally identifiable information. The stolen information included banking and financial records, payroll data, Social Security numbers, passport and driver’s licence numbers, DEA registration numbers, and non-content call and text history records.

The conspirators then extorted victims by threatening to publish the stolen data online. They also advertised information for sale on Telegram and cybercrime forums including BreachForums, Exploit.in and XSS.is.

Canadian Hacker Who Advertised Stolen Data on BreachForums Pleads Guilty
Waifu hacker on Breach Forums (Screenshot: Hackread.com)

Prosecutors said the operation received more than $2.5 million in ransom payments, of which Moucka personally obtained at least $495,000. During one re-extortion attempt, he used stolen data belonging to a government officer and relatives of a former government officer to demand another payment.

Victim companies suffered more than $9.5 million in actual losses. The DOJ said this figure did not include harm suffered by the companies’ customers, who total at least 100 million people.

Guilty Plea Follows International Investigation

Canadian authorities arrested Moucka roughly six months after the breaches began. He was extradited to the United States in July 2025 following assistance from the Justice Department’s Office of International Affairs.

The FBI investigated the case, while the Royal Canadian Mounted Police, Australian Federal Police, Spain’s Guardia Civil, Security Service of Ukraine and Turkish National Police assisted.

Moucka pleaded guilty to four counts, including computer fraud, wire fraud, aggravated identity theft and a related conspiracy. Sentencing is scheduled for October 27, 2026. He faces a mandatory minimum penalty of two years for aggravated identity theft and a maximum penalty of 30 years on the remaining counts.

“Connor Moucka hacked over 150 companies and organizations, obtained extremely sensitive information, and extorted the victims for millions of dollars,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division.

Case Forms Part of Operation Riptide

The case forms part of Operation Riptide, an FBI campaign targeting cybercriminals, supporting infrastructure and financial networks involved in cybercrime, online fraud and related offences.

As Hackread.com previously reported, other cases announced under the operation include the arrest in Spain of an alleged Cyber Army of Russia Reborn member and the guilty plea of a Ukrainian national linked to Conti ransomware.

Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage.
Related Posts