U.S. Army Soldier Sentenced to Nearly Six Years in Federal Prison for Massive Telecommunications Hacks and Extortion Schemes

Cameron John Wagenius, a 22-year-old active-duty U.S. Army soldier stationed in South Korea, has been sentenced in a Seattle federal court to 70 months in prison followed by three years of supervised release. Operating under the cybercriminal moniker “Kiberphant0m,” Wagenius admitted to infiltrating multiple high-profile cloud data storage and telecommunications companies. His illicit operations resulted in the exposure of sensitive call and text metadata belonging to more than 100 million AT&T customers, alongside attacks on Verizon’s Push-to-Talk infrastructure and other global providers. In addition to his nearly six-year prison sentence, U.S. District Judge ordered Wagenius to pay $294,978 in restitution to his victims.
The sentencing marks a critical milestone in a multi-agency international investigation involving the Federal Bureau of Investigation (FBI), the Defense Criminal Investigative Service (DCIS), the Army Criminal Investigation Division (CID), and the U.S. Secret Service. Prosecutors revealed that despite orchestrating massive breaches that compromised the privacy of tens of millions of citizens, Wagenius netted a remarkably meager financial return of roughly $1,500 from direct sales of stolen data—highlighting a stark disconnect between the catastrophic scale of the cyberattacks and the minimal monetary reward realized by the perpetrator.
Chronology of the Cyberattacks and Extortion Campaign
The origins of the breach trace back to systemic vulnerabilities within cloud data storage platforms, most notably Snowflake. During his deployment in South Korea, Wagenius and a ring of international co-conspirators exploited accounts that had exposed credentials and lacked multi-factor authentication (MFA) protections. By leveraging these oversight gaps, the actors gained unauthorized entry into corporate data environments, harvesting massive repositories of internal and customer records.
By October 2024, operating under the alias Kiberphant0m, Wagenius began openly boasting on underground cybercrime forums about his acquisition of call and text metadata—including source numbers, destination numbers, timestamps, and call durations—belonging to over 100 million AT&T accounts. The group expanded their targets to include more than a dozen telecommunications companies worldwide, executing public extortion campaigns and threatening to leak sensitive corporate assets unless cryptocurrency ransoms were paid.
The investigative breakthrough occurred in late November 2024, when cybersecurity journalist Brian Krebs published findings indicating that the individual behind the Kiberphant0m persona was likely a U.S. service member stationed in South Korea. The publication of these details accelerated law enforcement efforts. Within weeks, federal agents arrested Wagenius. He was subsequently hit with multiple federal indictments, prompting him to plead guilty to all counts across his cases.
Co-Conspirators and Global Extortion Ring
Federal prosecutors detailed that Wagenius did not act alone. He collaborated with an international network of cybercriminals, several of whom have faced or are currently facing severe legal consequences in multiple jurisdictions.
Among the key co-conspirators is 28-year-old Kenneth Schuchman of Vancouver, Washington. Schuchman possesses a notorious history in the cybercrime underground; in 2019, he pleaded guilty to operating the Satori botnet, a sprawling collection of compromised Internet-of-Things (IoT) devices responsible for large-scale distributed denial-of-service (DDoS) attacks that temporarily disrupted critical internet infrastructure.
Another prominent figure in the Snowflake-related data heists is Conor Riley Moucka (also known as “Judische”) of Kitchener, Ontario. Moucka was arrested in Canada in 2024 and subsequently entered a guilty plea in August 2026. Meanwhile, American national John Erin Binns—currently residing in Turkey—remains wanted by U.S. authorities. Binns is linked not only to the Snowflake extortion conspiracies but also to a massive 2021 data breach at T-Mobile that exposed the personal data of at least 76 million customers.
The extortion tactics employed by the group were aggressive and multifaceted. Following the arrest of Moucka, and even after AT&T reportedly paid a $370,000 Bitcoin ransom to satisfy the demands, Kiberphant0m engaged in re-extortion. In a brazen move to punish victims or increase leverage, the hacker leaked what he claimed were call logs for then-President-elect Donald Trump and then-Vice President Kamala Harris, alongside technical schematics allegedly stolen from the U.S. National Security Agency (NSA).
Insider Threat and Law Enforcement Response
The involvement of an active-duty soldier holding a secret security clearance elevated the case from a standard corporate cybercrime investigation to a high-priority national security concern. Paul Russell, resident agent in charge at the Defense Criminal Investigative Service (DCIS)—the criminal investigative arm of the Department of Defense Office of Inspector General—emphasized the alarming nature of the insider threat.
“We don’t often get leads where there’s an active-duty soldier with a secret clearance who’s creating hacking tools and trafficking in data,” Russell stated. “That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with.”
The convergence of military clearance, classified-adjacent exposure, and illicit cyber operations triggered an immediate, coordinated response across defense and civilian law enforcement agencies, demonstrating the federal government’s zero-tolerance policy for service members who compromise digital infrastructure.
Post-Arrest Misconduct and Exploitation of Artificial Intelligence
Court documents unsealed ahead of the sentencing hearing revealed that Wagenius’s penchant for probing digital defenses did not cease upon his incarceration. A sentencing memo filed by federal prosecutors in September detailed how Wagenius violated Bureau of Prisons (BOP) computer use policies while awaiting trial, attempting to research system vulnerabilities and prison escape strategies from behind bars.
According to BOP records cited in the memo, Wagenius utilized another inmate’s email system in September 2025 to prompt commercial artificial intelligence tools for detailed exploitation scripts. Disguising his queries as research for an upcoming book—a classic form of "prompt injection" designed to bypass AI safety guardrails—Wagenius asked for command-injection CVE details, privilege escalation techniques for Windows 10 Enterprise, and step-by-step instructions for exploiting CVE-2023-45208, a vulnerability affecting D-Link networking devices. Furthermore, he solicited advice on constructing improvised antennas using commissary items to extend radio reception and researched methods for escaping a correctional facility.
While federal prosecutors noted there is no evidence that Wagenius successfully deployed these vulnerabilities within BOP systems—with the defendant claiming his research was intended to assist prison administrators—the behavior underscored a persistent and compulsive drive toward unauthorized digital system exploration.
Broader Implications for Cybersecurity and Corporate Resilience
The case of Cameron Wagenius serves as a watershed moment illustrating several contemporary vulnerabilities in both corporate and governmental security frameworks:
- The Danger of Credential Hygiene: The foundational breach of Snowflake and subsequent corporate repositories underscores how easily threat actors can bypass perimeter defenses simply by locating exposed credentials and exploiting accounts lacking multi-factor authentication. In the wake of these incidents, cloud providers and enterprise organizations have increasingly moved to make MFA a mandatory baseline requirement.
- The Insider Threat Matrix: Military personnel and corporate employees with elevated access represent a unique risk vector. When technical proficiency meets authorized or adjacent clearance levels, traditional security controls can be circumvented, prompting defense agencies to re-evaluate internal monitoring and vetting protocols.
- The Weaponization of Generative AI: Wagenius’s attempts to use AI tools for malware generation and vulnerability research via prompt injection highlight the growing challenge facing developers of commercial language models. As bad actors attempt to subvert safety filters, regulatory bodies and AI developers face mounting pressure to refine safeguards against malicious utility.
- Disproportionate Impact Versus Profit: Despite causing millions of dollars in damages, operational disruption, and widespread privacy violations for over 100 million citizens, Wagenius earned a negligible financial return. This dynamic demonstrates that modern cybercrime is frequently driven by status, notoriety, and ideological or chaotic motivations within underground forums, rather than purely rational economic calculations.
As Wagenius begins serving his 70-month federal sentence, federal authorities continue to pursue remaining co-conspirators in an ongoing effort to dismantle the remnants of the international hacking collective that leveraged cloud misconfigurations to hold global telecommunications infrastructure hostage.







