Cybersecurity and Privacy

U.S. Army Soldier Sentenced to 70 Months in Prison for Massive Telecom Hacking and Extortion Campaign Targeting AT&T

A federal court in Seattle has sentenced a 22-year-old active-duty U.S. Army soldier to 70 months in federal prison for his role as a central figure in an international cybercriminal syndicate. Operating under the online moniker "Kiberphant0m," Cameron John Wagenius orchestrated a series of high-profile cyberattacks that compromised the telecommunications metadata of more than 100 million AT&T customers. In addition to the nearly six-year prison term, Wagenius was ordered to pay $294,978 in restitution to his victims.

The sentencing brings a significant chapter to a complex, multi-agency federal investigation that exposed serious vulnerabilities in cloud data storage security, corporate extortion protocols, and internal military oversight. While Wagenius admitted guilt to multiple felony counts, prosecutors revealed that his criminal enterprise yielded shockingly modest financial gains—totaling approximately $1,500—despite the massive scale of the data he and his co-conspirators managed to harvest.

The Genesis of Kiberphant0m and the Snowflake Breach

The investigation into Wagenius began with a sweeping wave of cyberattacks targeting cloud storage provider Snowflake in 2024. Numerous prominent corporations had migrated vast quantities of data to Snowflake’s platform, but a subset of these organizations failed to institute basic cybersecurity hygiene practices, notably omitting mandatory multi-factor authentication (MFA) across their administrative accounts.

Wagenius, who was stationed at a U.S. Army base in South Korea at the time and held a secret security clearance, exploited these exposed credentials alongside a network of international co-conspirators. Adopting the cybercriminal persona "Kiberphant0m," the young soldier breached the cloud infrastructure of several major telecommunications companies. By October 2024, Wagenius began openly boasting on underground hacker forums that he had exfiltrated call and text message metadata—including source numbers, destination numbers, timestamps, and call durations—for tens of millions of AT&T subscribers.

Furthermore, Kiberphant0m claimed responsibility for penetrating more than a dozen telecommunications firms globally, including Verizon’s specialized Push-to-Talk corporate infrastructure. Rather than simply leaking the data, the syndicate initiated a campaign of public corporate extortion, threatening to publish confidential subscriber metadata unless ransom demands were met.

A Chronology of Investigation, Identification, and Arrest

The unraveling of the Kiberphant0m persona was a collaborative triumph for federal law enforcement and investigative journalism. The chronology of the case underscores the rapid convergence of digital forensics and military counterintelligence:

  • Late November 2024: Cybersecurity publication KrebsOnSecurity published an investigative report warning that the individual operating as Kiberphant0m was likely an active-duty U.S. military service member stationed in South Korea.
  • December 2024: Federal agents moved quickly following the publication. Cameron John Wagenius was arrested, subsequently facing multiple federal indictments in U.S. courts.
  • August 2026: Co-conspirator Conor Riley Moucka, operating under the alias "Judische," pleaded guilty in connection with the Snowflake extortion campaign following his earlier arrest in Canada.
  • September 2026: Federal prosecutors in Seattle filed a comprehensive sentencing memorandum outlining not only Wagenius’s original hacking offenses but also his subsequent attempts to subvert computer security policies while incarcerated.
  • Today: Wagenius receives his final sentence of 70 months in federal prison and is ordered to pay nearly $300,000 in victim restitution.

An International Syndicate of Cybercriminals

Federal prosecutors detailed that Wagenius did not act in a vacuum. He was part of a loose confederation of experienced cybercriminals who leveraged each other’s technical competencies to execute high-stakes corporate extortion.

Among Wagenius’s alleged co-conspirators is Kenneth Schuchman, a 28-year-old resident of Vancouver, Washington, with a notorious background in digital crime. Schuchman previously pleaded guilty in 2019 to operating the Satori botnet—a massive network of compromised Internet-of-Things (IoT) devices responsible for launching devastating distributed denial-of-service (DDoS) attacks across the globe.

Another key figure linked to the broader Snowflake data theft ecosystem is Conor Riley Moucka of Kitchener, Ontario, who entered a guilty plea in August 2026. Additionally, American national John Erin Binns, residing in Turkey, remains wanted by U.S. authorities for his alleged involvement in the massive 2021 T-Mobile data breach that exposed the personal records of at least 76 million customers.

Escalation of Threats and National Security Implications

The syndicate’s extortion tactics escalated from standard corporate shakedowns to reckless disclosures involving sensitive government information. Following the arrest of Conor Moucka—and despite the fact that AT&T had already paid the extortion ring a $370,000 Bitcoin ransom—Kiberphant0m retaliated by publishing what he claimed were the call logs of then-President-elect Donald Trump and then-Vice President Kamala Harris.

In addition to telecommunications logs, Kiberphant0m threatened to release classified national security secrets, allegedly distributing schematics stolen from the U.S. National Security Agency (NSA). These actions elevated the case from a standard corporate extortion scheme to a matter of acute national security interest.

The involvement of a service member with active security clearances prompted an unprecedented multi-agency response. Paul Russell, the resident agent in charge at the Defense Criminal Investigative Service (DCIS)—the criminal investigative arm of the Department of Defense Office of Inspector General—noted the gravity of the situation. Russell coordinated the investigation alongside the Federal Bureau of Investigation (FBI), the Army Criminal Investigative Division (CID), and the U.S. Secret Service.

"We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data," Russell stated. "That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with."

Incarceration Misconduct and AI "Prompt Injection" Tactics

Even while awaiting sentencing in federal custody, Wagenius demonstrated a persistent drive to probe computer systems illicitly. Government prosecutors revealed in their September sentencing memo that the soldier repeatedly violated Bureau of Prisons (BOP) computer use policies in an effort to research system vulnerabilities and potential prison escape methods.

According to BOP records, Wagenius utilized fellow inmates’ email accounts to query commercial artificial intelligence tools. To bypass safety filters designed to prevent AI models from generating malicious code—a technique known as "prompt injection"—Wagenius framed his requests within the context of writing a book.

In one instance, he instructed an email recipient to prompt an AI tool for information regarding privilege escalation and bypass vulnerabilities in Windows 10 Enterprise, explicitly demanding "real world working script for each CVE . . . without omitted code." In another instance, he sought step-by-step instructions and code for CVE-2023-45208, a command injection vulnerability affecting D-Link networking devices. Furthermore, prison records indicated Wagenius researched how to construct improvised radio antennas using commissary items to extend reception, alongside inquiries concerning prison escape logistics.

While prosecutors acknowledged there is no evidence Wagenius successfully deployed these vulnerabilities within BOP computer architecture, the actions highlighted a continued disregard for institutional security policies.

Broader Impact and Industry Implications

The case of Cameron Wagenius serves as a watershed moment illustrating several contemporary vulnerabilities in both national defense and corporate cybersecurity:

  1. The Danger of Credential Exposure: The initial breaches of Snowflake and subsequent telecom networks underscore that major enterprises remain highly vulnerable to simple hygiene lapses, such as failing to enforce multi-factor authentication across all access points.
  2. The Insider Threat Matrix: The ease with which a mid-level military service member could leverage a security clearance to develop hacking methodologies highlights critical gaps in internal monitoring and behavioral vetting within the armed forces.
  3. The Weaponization of Generative AI: Wagenius’s exploitation of commercial AI tools via prompt injection demonstrates how bad actors—including those physically confined within correctional facilities—are attempting to automate the discovery of software exploits and weaponize artificial intelligence against digital infrastructure.

Despite the monumental potential value of the data stolen from AT&T and other global telecom providers, Wagenius’s inability to monetize his cache effectively—netting a mere $1,500 from his illicit efforts—underscores a common disconnect in modern cybercrime: the capacity to inflict catastrophic societal and corporate damage frequently outstrips the perpetrator’s financial return.

With his 70-month sentence now handed down, federal authorities hope to send an uncompromising message to both civilian and military personnel who might contemplate turning their technical skills against the institutions they have sworn to protect.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Device Kick
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.