/

August 8, 2026

Two Cybercriminals, One Day in Court: The Password Lessons Behind 100 Million Exposed Records

On a single Wednesday this month, the U.S. Department of Justice closed the book on two very different cybercriminals in one announcement — and read together, their two stories tell you almost everything you need to know about how modern cybercrime actually works, and how it actually ends. One was a middleman who never wrote a line of the ransomware he profited from. The other logged into 165 companies without breaking a single lock. Neither fits the hoodie-in-a-basement image most people carry around. Both got caught. And the lessons they leave behind are the two most important habits a small business can adopt.

Let’s take them one at a time, because each is a masterclass in a different truth about this world.

Story one: the man who logged in

Connor Moucka, a 26-year-old from Kitchener, Ontario, pleaded guilty to a hacking conspiracy that compromised more than 165 organizations and exposed records tied to at least 100 million people. These were not small companies. Reporting has tied the same breach campaign to household names — telecoms, ticketing giants, retailers — whose customer data spilled out through a cloud data platform many of them used to store it.

Here is the part that matters, and it is the whole reason we’re telling you this story. Moucka did not defeat that platform’s security. Investigators, including the platform’s own hired forensics team, confirmed there was no flaw in the platform at all. So how did he get into 165 companies?

He used old passwords — and walked through unlocked doors. The login credentials had been quietly harvested years earlier by infostealer malware on various employees’ computers, and then never changed. The accounts they unlocked had multi-factor authentication switched off. So the “hack” was, in the plainest terms: type a username and password that had been valid for years, and that nobody had turned off. No exploit. No genius. Just doors that were never re-locked, in buildings with the second lock left disengaged.

Prosecutors say Moucka personally made at least $495,000 from extorting victims and selling stolen data on criminal forums, and that victim companies suffered around $9.5 million in total losses. In an especially ugly detail, he re-extorted at least one victim who had already paid — going back to the well and threatening to release more, using the personal data of a government official and their family as leverage. He is due to be sentenced on October 27 and faces up to 30 years.

The two lessons in his story are not subtle, and they are free:

  • Old, reused passwords are live ammunition. A password stolen from an employee’s home computer three years ago is still a working key today if nobody ever changed it. Every credential that leaks somewhere, and is reused or never rotated, is a door standing open indefinitely.
  • Multi-factor authentication is the second lock that would have stopped all of it. Every one of those 165 break-ins happened on an account where MFA was off. With it on, a stolen password alone is a key that no longer fits, because the door now also demands a code from a phone the criminal doesn’t have. This is the single highest-value security setting most businesses aren’t fully using.

Story two: the man who never attacked anyone

The second defendant sentenced that day was Maksim Silnikau, a 40-year-old Belarusian national who received 16 years in federal prison as the creator and administrator of the Ransom Cartel ransomware operation. And his story punctures a myth that leaves a lot of small business owners under-prepared.

Silnikau did not, for the most part, carry out attacks himself. Read what he actually did, because it reads more like a job description at a company than anything you’d picture a “hacker” doing:

Silnikau’s actual roleWhat that means in plain terms
Bought network access to victimsPurchased ways in from other criminals who specialize in breaking and entering
Supplied the ransomwareProvided the actual attack software to others to use
Ranked and managed affiliatesRan a team of “customers” who did the attacking, like a manager with staff
Handled victim negotiationsDid the extortion conversations and collected the payments
Moved payments through crypto mixersLaundered the proceeds to hide the money trail

The Justice Department says the operation hit at least 18 companies, including firms in California, New York, and Nebraska. Notice what this describes: not a lone genius, but a business — with suppliers, a product, a sales team, customer service, and an accounting department. That is what “ransomware-as-a-service” means, and it is the actual shape of the modern cybercrime economy.

Why this matters to you: the criminal targeting your business probably isn’t a mastermind who chose you personally. It’s more likely a low-skilled “affiliate” who rented attack tools from someone like Silnikau and is spraying them at every soft target they can find, hoping something sticks. That’s genuinely good news, and here’s why: you don’t have to defend against a criminal genius. You have to be enough of a hard target that the rented-tools crowd bounces off and moves to someone easier. The bar is far lower than the movies suggest — and the two habits from story one clear most of it.

What the two stories say together

Put them side by side and a clear picture forms. Cybercrime is an industry now, with specialists at every stage: people who steal passwords, people who sell access, people who supply the software, people who do the extortion, people who launder the money. Moucka bought stolen credentials that someone else harvested. Silnikau sold attack capability to people who did the attacking. The lone hacker is mostly a fiction; the reality is a supply chain.

But the encouraging half of the picture is just as real. Both men were caught and are facing serious prison time — Moucka arrested barely six months after the breaches began, Silnikau already sentenced to 16 years. The “hackers always get away with it” fatalism isn’t accurate either. Law enforcement is landing real blows against exactly the middlemen who make this economy run, which is the story we’ve been telling in our recent pieces on ransomware takedowns.

And most encouraging of all: the thing that opened 165 companies to a hundred-million-person data disaster was not sophistication. It was old passwords and a disabled safety setting. Which means the fix is not sophistication either. Turn on multi-factor authentication everywhere it’s offered. Stop reusing passwords, and use a password manager so you don’t have to remember them. Change credentials that may have leaked. Those few habits would have stopped the single largest data-theft campaign in this story cold — and they’re available to every business reading this, for free, today.

That’s the whole game for a small business: you’re not trying to be un-hackable by a nation-state. You’re trying to be locked up tighter than the next business over, so the rented-tools crowd gives up and moves on. Our focused, plain-language security training builds exactly those habits into your team — the password-manager reflex, MFA everywhere, and the instincts that make your business the hard target attackers skip. The criminals in these two stories built an entire industry to get in. Don’t hand them the key.

Sources: U.S. Department of Justice announcement (August 5, 2026); The Hacker News; BleepingComputer; The Record; CBC News; Security Affairs; TechNadu, August 2026. The cloud platform at the center of the Moucka case was not named by the DOJ; it was identified by the platform’s vendor and its forensics firm in 2024, which also confirmed no flaw in the platform itself.

From the same category