Cybersecurity and Privacy

Ex-U.S. Army Soldier Sentenced to Nearly Six Years in Federal Prison for Massive Telecommunications Hacks and Extortion Schemes

A federal judge in Seattle has sentenced a 22-year-old former United States Army soldier to 70 months in federal prison for orchestrating a series of high-profile cyberattacks and extortion schemes targeting major global telecommunications companies, including AT&T and Verizon. Cameron John Wagenius, who operated under the cybercriminal alias "Kiberphant0m" while stationed at a military base in South Korea, was also ordered to pay nearly $300,000 in restitution to his victims. The sentencing brings a temporary close to a complex international cybercrime investigation that exposed critical vulnerabilities in cloud data storage security, involved high-stakes extortion plots, and highlighted the growing threat of insider actors with military-grade security clearances.

The case against Wagenius underscores the evolving nature of modern cyber threats, where young individuals with sophisticated technical capabilities can leverage compromised credentials to infiltrate multinational corporations. Operating from a military installation overseas, Wagenius managed to compromise vast quantities of sensitive metadata affecting more than 100 million AT&T customers. Despite the massive scale of the data breaches, court documents reveal a stark irony: the defendant earned a remarkably meager financial return from his extensive criminal enterprise, highlighting a disconnect between the potential damage of a cyberattack and the actual monetary profit realized by the perpetrators.

The Genesis of the Breaches and the Snowflake Connection

The foundation of Wagenius’s cybercriminal campaign was built upon widespread security lapses exploited across cloud data storage environments, most notably involving the cloud data warehousing service Snowflake. During his deployment in South Korea, Wagenius and a network of international co-conspirators targeted large corporate clients of Snowflake that had inadvertently exposed their login credentials and failed to enforce multi-factor authentication (MFA) on their accounts. Although Snowflake has since mandated multi-factor authentication across all user accounts to prevent similar incidents, the initial lack of stringent access controls allowed threat actors to scrape unprecedented volumes of proprietary corporate and consumer data.

By late 2024, Wagenius had adopted the persona "Kiberphant0m" and began frequenting underground cybercrime forums. In October of that year, he publicly bragged about stealing comprehensive call and text metadata belonging to tens of millions of AT&T customers. This stolen data included highly sensitive transactional details, such as source and destination phone numbers, timestamps, and the exact duration of communications. Furthermore, Wagenius claimed to have successfully penetrated more than a dozen major telecommunications providers worldwide, including Verizon’s specialized Push-to-Talk business. Utilizing these massive datasets as leverage, the criminal group initiated public extortion campaigns, threatening to dump the proprietary records online unless the affected corporations met their ransom demands.

Chronology of the Investigation and Arrest

The unraveling of the "Kiberphant0m" persona began through rigorous investigative journalism and rapid multi-agency law enforcement coordination. In late November 2024, cybersecurity publication KrebsOnSecurity published intelligence suggesting that the hacker operating under the handle Kiberphant0m was likely an active-duty U.S. soldier stationed in South Korea. The revelation triggered an aggressive inter-agency response involving the Defense Criminal Investigative Service (DCIS)—the criminal investigative arm of the U.S. Department of Defense Office of Inspector General—alongside the Federal Bureau of Investigation (FBI), the Army Criminal Investigation Division (CID), and the U.S. Secret Service.

Paul Russell, the resident agent in charge at DCIS, noted the extraordinary nature of the case from its inception. Law enforcement officials rarely encounter active-duty military personnel possessing secret security clearances who simultaneously engage in the creation of bespoke hacking tools and the illicit trafficking of stolen data. The realization that an insider threat existed within the ranks of the U.S. military created immediate urgency among federal partners.

Less than a month after the initial public reporting, federal agents apprehended Wagenius. He was promptly charged in two separate federal indictments in Seattle. Facing overwhelming evidence compiled by federal investigators, Wagenius opted to plead guilty to all counts across both cases, choosing a path of rapid cooperation with prosecutors in exchange for a recommendation of leniency during sentencing.

An International Conspiracy Involving Notorious Hackers

Federal prosecutors revealed that Wagenius did not act in isolation. He was supported by a network of seasoned cybercriminals with extensive histories in illicit digital operations. Chief among his alleged co-conspirators was Kenneth Schuchman, a 28-year-old resident of Vancouver, Washington. Schuchman is no stranger to federal law enforcement; in 2019, he pleaded guilty to operating the notorious Satori botnet, a massive collection of compromised Internet-of-Things (IoT) devices responsible for large-scale distributed denial-of-service (DDoS) attacks that crippled major web infrastructure.

Other key figures linked to the Snowflake-related data thefts include Conor Riley Moucka, also known as "Judische," a Canadian national from Kitchener, Ontario. Moucka was arrested in 2024 and subsequently pleaded guilty in August 2026. Additionally, the conspiracy involved John Erin Binns, an American citizen currently residing in Turkey, who remains wanted by U.S. authorities for his alleged role in a massive 2021 data breach at T-Mobile that compromised the personal identifying information of at least 76 million customers.

The scope of the extortion schemes expanded dramatically as the pressure mounted on the cybercriminal network. Following the arrest of Conor Moucka—and despite AT&T having already paid an extortion group a reported $370,000 Bitcoin ransom—Kiberphant0m engaged in a desperate attempt at re-extortion. In an unprecedented escalation, the hacker posted datasets on underground forums purporting to contain the AT&T call logs of then-President-elect Donald Trump and then-Vice President Kamala Harris, alongside technical schematics allegedly stolen from the U.S. National Security Agency (NSA).

In-Prison Misconduct and AI Prompt Injection Attempts

Even while incarcerated and awaiting sentencing at a federal facility, Wagenius continued to demonstrate his technical fixation, managing to violate Bureau of Prisons (BOP) computer use policies in an attempt to probe federal detention networks for vulnerabilities. According to a government sentencing memo filed in September 2025 by federal prosecutors in Seattle, Wagenius exploited another inmate’s email account to interact with commercial artificial intelligence tools.

Using sophisticated prompt-injection techniques designed to bypass safety filters built into commercial AI models, Wagenius framed his queries as research for a book he claimed to be writing. In reality, he sought specific technical instructions for Windows 10 Enterprise privilege escalation, real-world working scripts for CVE-2023-45208 (a command injection vulnerability affecting D-Link networking devices), and instructions on how to construct improvised radio antennas using prison commissary items to extend reception. Furthermore, investigators discovered queries relating to prison escape tactics.

Federal prosecutors acknowledged during the sentencing hearing that there was no definitive evidence indicating Wagenius successfully deployed these vulnerabilities within the BOP’s internal computer infrastructure. When confronted by authorities regarding the suspicious AI prompts, Wagenius claimed he was merely researching potential system weaknesses to provide constructive vulnerability reports to prison officials. Nonetheless, the incident heavily influenced the government’s sentencing posture, illustrating the persistent risk posed by technically proficient offenders even while behind bars.

Financial Realities and Broader Industry Implications

Despite the immense intrinsic value of the proprietary data exfiltrated from AT&T and other global telecommunications giants, financial forensic analyses detailed in the government’s sentencing memo revealed a startling economic inefficiency in Wagenius’s criminal enterprise. Investigators calculated that despite compromising data belonging to over 100 million individuals and attempting large-scale extortion operations, Wagenius personally netted a meager total of approximately $1,500 from the direct sale of stolen information.

Federal prosecutors emphasized this disparity in their final legal arguments, noting that while the defendant’s financial yield was remarkably low, the actual and intended harm inflicted upon individual consumers, private corporations, and federal agencies was profound. The case serves as a watershed moment for corporate cloud security, forcing enterprises to re-evaluate their reliance on single-factor authentication, tighten access management policies across third-party cloud data warehouses, and adopt rigorous zero-trust architectures.

Furthermore, the prosecution of an active-duty soldier with a secret security clearance has prompted a comprehensive review within the Department of Defense regarding the internal monitoring of service members with specialized technical proficiencies. As cybercrime increasingly intersects with national security and insider threats, federal agencies have signaled that cross-jurisdictional task forces will remain vigilant in identifying and neutralizing rogue actors before they can compromise critical civilian and military infrastructure.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Device Kick
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.