
Connor Riley Moucka, a 26-year-old Canadian from Kitchener, Ontario, has pleaded guilty to a widespread computer hacking conspiracy that resulted in the compromise of over 165 victim organizations and the theft of billions of sensitive customer records. According to court documents, between February and October 2024, Moucka and his co-conspirators used stolen login credentials to compromise cloud-hosted data belonging to customers of a U.S.-based software-as-a-service company. The conspirators stole terabytes of information including individuals' non-content call and text history records, banking and financial information, payroll records, Drug Enforcement Administration registration numbers, driver's license numbers, passport numbers, social security numbers and other personally identifiable information. Assistant Attorney General A. Tysen Duva of the Justice Department's Criminal Division stated that Moucka hacked over 150 companies and organizations, obtained extremely sensitive information, and extorted the victims for millions of dollars.
The cybercriminals extorted victims by threatening to publish data online, with the conspirators receiving over $2.5 million in ransom payments. In at least one instance, Moucka re-extorted a victim with threats of further disclosure of the victim's stolen data, using the stolen data of a government officer and members of a then-former government officer's immediate family in this re-extortion attempt. Additionally, Moucka and his co-conspirators advertised the victims' data for sale online, including on cybercrime forums BreachForums, Exploit.in and XSS.is, as well as on Telegram. Moucka personally obtained at least $495,000 from these activities, while victim companies suffered over $9.5 million in actual losses - a number that does not include losses suffered by the companies' customers, totaling at least 100 million individuals.
Cybercriminals are increasingly leveraging artificial intelligence to enhance their attack capabilities, with Cisco Talos research documenting how AI systems are being used to develop malicious code, build fraud infrastructure, and accelerate vulnerability research. The study, released during the Black Hat USA conference, found that AI systems guardrails were often ineffective, with threat actors frequently bypassing guardrails by claiming "this is authorized testing" or "I'm asking this as part of a capture the flag exercise" to convince most models to comply. This duped permissiveness wasn't specific to a single model or platform, with analysis of prompt logs related to Claude Code, CodeX, Cursor, and Gemini showing this shortcoming was widespread across AI platforms. CrowdStrike's 2026 Threat Hunting Report reveals how AI is collapsing the window between vulnerability disclosure and active exploitation, with 88% of observed exploitation conducted within 48 hours of public proof-of-concept release.
The case demonstrates significant international cooperation in cybercrime investigation and prosecution. The Justice Department's Office of International Affairs provided substantial assistance in obtaining Moucka's arrest and July 2025 extradition from Canada, while a number of foreign law enforcement agencies provided substantial assistance in the investigation and arrest, including the Royal Canadian Mounted Police, Australian Federal Police, Spain's Guardia Civil, Security Service of Ukraine and Turkish National Police. Assistant Director Brett Leatherman of the FBI's Cyber Division emphasized that "Hiding behind a screen is no shield from justice," while Special Agent in Charge W. Mike Herrington noted that "Today's guilty plea sends a clear message to cybercriminals: you cannot hide from justice, no matter how hard you may try to cover your tracks." Operation Riptide, an FBI campaign targeting criminal actors, infrastructure, and financial networks behind cybercrime, represents the FBI's sustained enforcement response to cybercrime threats, with Americans reporting over $20 billion in losses to cybercrime last year, a 26 percent single-year increase.
According to Securonix, organizations should restrict the execution of untrusted MSI installers using application control technologies such as AppLocker or Windows Defender Application Control. The report recommends maintaining a clear inventory of approved remote management tools and blocking unauthorized software like ScreenConnect. Cisco Talos urges enterprises to improve detection, prioritization, and their own use of AI platforms to handle the growing volume of alerts and vulnerabilities. Security teams should assume AI is already embedded in attacker workflows and focus on detecting malicious behavior rather than proving AI involvement, treating large language models and APIs as privileged, high-risk infrastructure. Oliver Simonnet from CultureAI emphasizes that organizations should strengthen logging, patching, and containment while deploying their own AI-assisted security capabilities to prepare for the coming deluge of additional vulnerabilities and incidents.