Cameron John Wagenius, a 22-year-old active-duty U.S. Army soldier stationed in South Korea, has been sentenced to 70 months in federal prison for orchestrating a series of sophisticated cyberattacks against major telecommunications companies, including a massive breach affecting more than 100 million AT&T customers. Operating under the cybercriminal moniker “Kiberphant0m,” Wagenius leveraged his high-level military security clearance and technical acumen to illicitly access, download, and attempt to monetize sensitive customer metadata. In addition to his nearly six-year prison sentence handed down in a Seattle federal court, Wagenius was ordered to pay $294,978 in restitution to his victims.
The sentencing marks a critical milestone in a sweeping international investigation involving multiple federal agencies, including the Federal Bureau of Investigation (FBI), the Army Criminal Investigation Division (CID), the U.S. Secret Service, and the Defense Criminal Investigative Service (DCIS). Despite the monumental scale of the data he compromised—which included call and text message metadata for the vast majority of AT&T subscribers, as well as intrusions into Verizon’s Push-to-Talk business and over a dozen other global telecommunications networks—prosecutors revealed that Wagenius reaped a mere $1,500 in direct financial profit from his illicit exploits.
The Genesis of the Breaches and the Snowflake Vulnerability
The cybercriminal enterprise spearheaded by Wagenius relied heavily on exploiting poorly secured enterprise cloud storage environments, most notably platforms provided by Snowflake. In 2024, Wagenius and a network of co-conspirators targeted large-scale corporate customers of the cloud data storage service that had left administrative credentials exposed and failed to enforce multi-factor authentication (MFA). By exploiting these security lapses, the threat actors gained unauthorized access to proprietary corporate databases, allowing them to extract vast quantities of proprietary records and customer metadata.
Operating from his duty station in South Korea, Wagenius adopted the alias Kiberphant0m and quickly established a notorious reputation within underground cybercrime forums. By October 2024, he publicly boasted about his acquisition of call and text metadata belonging to tens of millions of AT&T customers. This stolen data included highly sensitive transactional details, such as source and destination telephone numbers, timestamps, and call durations. Rather than keeping the data private, Wagenius and his associates engaged in aggressive extortion schemes, directly targeting vulnerable telecommunications giants and demanding substantial payouts in exchange for promises not to publish or auction the purloined data on the dark web.
Chronology of an Investigation and Arrest
The operation to unmask Kiberphant0m unfolded over several months through a combination of cybersecurity intelligence and federal law enforcement tracking. The chronology of the case underscores the rapid escalation of the threat and the coordinated response by global investigators:
- Late November 2024: Cybersecurity publication KrebsOnSecurity published an investigative warning indicating that the threat actor operating as Kiberphant0m was likely an active-duty U.S. soldier stationed in South Korea.
- December 2024: Federal authorities acted on intelligence and arrested Cameron John Wagenius. He was subsequently hit with two separate federal indictments in Washington state, swiftly pleading guilty to all counts.
- August 2026: Conor Riley Moucka, an alleged Canadian co-conspirator known online as “Judische,” formally pleaded guilty to his role in the Snowflake extortion conspiracy following his earlier arrest in 2024.
- September 2025 – September 2026: While incarcerated and awaiting sentencing at a federal facility, Wagenius attempted to exploit Bureau of Prisons (BOP) computer usage policies by engaging in prompt injection techniques against commercial AI tools, seeking unauthorized privilege escalation scripts and prison escape research.
- Present Day: Wagenius is sentenced to 70 months in federal prison and ordered to pay nearly $300,000 in restitution.
An International Network of Co-Conspirators
Wagenius did not operate in a vacuum; federal prosecutors detailed a sprawling network of transnational cybercriminals who collaborated to execute the cloud storage breaches and subsequent extortion campaigns. Among those implicated alongside Wagenius is Kenneth Schuchman, a 28-year-old resident of Vancouver, Washington, with a notorious background in cybercrime. Schuchman previously pleaded guilty in 2019 to operating the Satori botnet, a vast infrastructure of compromised Internet-of-Things (IoT) devices responsible for launching massive distributed denial-of-service (DDoS) attacks against global internet infrastructure.
Another prominent co-conspirator is Conor Riley Moucka of Kitchener, Ontario, who pleaded guilty in August 2026 for his direct involvement in the Snowflake extortions. Meanwhile, American national John Erin Binns remains wanted by U.S. and international law enforcement. Binns, who has been residing in Turkey, is heavily implicated not only in the recent Snowflake-related campaigns but also in the monumental 2021 T-Mobile data breach that exposed the personal identifying information of at least 76 million customers.
The extortion tactics employed by this network reached unprecedented levels of audacity. Following the arrest of Conor Moucka—and even after AT&T had reportedly paid a $370,000 Bitcoin ransom to the extortion collective—Kiberphant0m engaged in a campaign of re-extortion. In an aggressive bid to pressure corporate and government entities, Wagenius posted what he alleged were call logs belonging to then-President-elect Donald Trump and then-Vice President Kamala Harris. Furthermore, he threatened to leak classified schematics allegedly stolen from the U.S. National Security Agency (NSA).
Inside the Federal Investigation: A Unique Insider Threat
The involvement of an active-duty U.S. service member possessing a secret security clearance presented an extraordinary challenge to federal law enforcement agencies. Paul Russell, the resident agent in charge at the Defense Criminal Investigative Service (DCIS)—the criminal investigative arm of the Department of Defense Office of Inspector General—emphasized the unprecedented nature of the case.
"We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data," Russell stated. "That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with."
The realization that a military insider was actively weaponizing his technical skills to compromise national telecommunications infrastructure triggered an immediate, multi-agency task force. The FBI, Army CID, U.S. Secret Service, and DCIS pooled their resources to track digital footprints, trace cryptocurrency transactions, and ultimately apprehend Wagenius before further classified or proprietary data could be disseminated to foreign actors.
Incarceration Misconduct and AI Prompt Injection Tactics
Even while stripped of his freedom and awaiting sentencing in a federal detention facility, Wagenius demonstrated a persistent inclination toward cyber reconnaissance and system exploitation. According to a sentencing memorandum filed by federal prosecutors in Seattle, Wagenius violated Bureau of Prisons computer use policies in late 2025 by orchestrating a series of indirect attempts to probe BOP network security.
Utilizing the email accounts of fellow inmates, Wagenius directed third parties to query commercial artificial intelligence tools. His prompts were carefully constructed to bypass safety filters designed to prevent AI models from generating malicious exploit code—a cybersecurity evasion technique known as "prompt injection." In one instance, Wagenius framed his queries within the context of researching a book he claimed to be writing, asking the AI tool to provide Common Vulnerabilities and Exposures (CVEs) related to Windows 10 Enterprise privilege escalation and bypasses, complete with unedited, real-world working scripts.
Weeks later, Wagenius utilized another inmate’s account to solicit step-by-step instructions and exploitation code for CVE-2023-45208, a command injection vulnerability affecting D-Link networking hardware. Alongside these cyber reconnaissance efforts, records indicate that Wagenius instructed the same proxy recipients to research methods for constructing contraband radio antennae using prison commissary items to enhance reception, as well as investigating strategies for escaping confinement.
When confronted by federal investigators regarding these prison-era digital inquiries, Wagenius claimed he was merely researching potential vulnerabilities to provide corrective feedback to the Bureau of Prisons. Prosecutors noted that while there was no concrete evidence indicating Wagenius successfully deployed these exploits within BOP networks, the behavioral pattern underscored his persistent malicious intent and technical fixation.
Broader Implications for Corporate Cybersecurity and National Security
The conviction and sentencing of Cameron John Wagenius serve as a watershed moment for both corporate accountability and the defense of critical national infrastructure. The incidents highlight critical vulnerabilities in how major enterprises manage cloud-based data storage and third-party vendor integrations. The ease with which cybercriminals accessed proprietary Snowflake environments due to neglected multi-factor authentication protocols prompted a widespread reckoning across the technology sector, forcing cloud providers and corporate clients alike to mandate strict, uncompromised MFA enforcement across all user tiers.
Furthermore, the case underscores the severe risks posed by insider threats within military and defense apparatuses. The convergence of military-grade security clearances, access to sensitive communications networks, and malicious cyber operations represents a complex threat matrix that traditional defense protocols are continually forced to adapt to. While Wagenius’s financial gains from his sprawling criminal enterprise were remarkably meager—totaling approximately $1,500—the collateral damage inflicted upon corporate trust, individual privacy, and national security institutions was immeasurable.
As federal authorities continue to pursue remaining co-conshrators such as John Erin Binns, the legal outcome for Kiberphant0m sends an unmistakable message to the global cybercrime underground: the cooperative enforcement machinery of the United States military and federal law enforcement agencies possesses the capability to pierce through pseudo-anonymous personas, dismantle transnational extortion rings, and bring malicious insiders to swift justice.
