A federal court in Seattle has sentenced a 22-year-old active-duty U.S. Army soldier to 70 months in federal prison for orchestrating a sweeping international cybercrime and extortion campaign. Operating under the pseudonym “Kiberphant0m,” Cameron John Wagenius exploited unsecure cloud infrastructure to steal sensitive call and text metadata belonging to more than 100 million AT&T customers. In addition to his nearly six-year prison sentence, Wagenius was ordered to pay $294,978 in restitution to his victims, concluding a high-profile prosecution that exposed critical vulnerabilities in corporate data storage and highlighted the growing threat of insider actors within military ranks.
Wagenius, who was stationed at a U.S. Army base in South Korea at the time of the offenses, utilized his secret security clearance and technical acumen to coordinate cyberattacks against major telecommunications and data storage entities worldwide. Federal prosecutors detailed that Wagenius, alongside a network of international co-conspirators, weaponized compromised credentials from cloud data storage provider Snowflake to siphon proprietary corporate data. Despite the massive scale of the data breaches—which impacted dozens of global telecom providers, including Verizon’s Push-to-Talk division—investigators revealed that Wagenius profited remarkably little from his illicit operations, netting approximately $1,500 in direct sales of stolen information before federal law enforcement intervened.
The Chronology of an International Cyber Investigation
The unraveling of the Kiberphant0m persona represents a collaborative triumph for multi-agency federal law enforcement. The investigative timeline illustrates the rapid escalation of a complex digital threat that transitioned from an anonymous forum boast to an active national security investigation.
In October 2024, the cybercriminal operating as Kiberphant0m took to public dark-web and surface-web hacker forums to openly brag about infiltrating cloud environments and extracting call and text metadata—including source numbers, destination numbers, timestamps, and call durations—for tens of millions of AT&T subscribers. During this period, the extortion group engaged in aggressive public shaming and corporate extortion, threatening to leak sensitive internal archives unless corporate targets met substantial cryptocurrency ransom demands.
By late November 2024, cybersecurity journalism outlet KrebsOnSecurity published intelligence suggesting that the actor behind the Kiberphant0m moniker was likely an American military service member stationed in South Korea. This public revelation accelerated pressure on defense and federal investigators.
Less than a month after the initial public reporting, in December 2024, federal authorities arrested Wagenius. He was formally charged in dual federal indictments, moving swiftly through the judicial process to plead guilty to all counts. Throughout the proceedings, prosecutors noted that Wagenius cooperated extensively with investigators, though subsequent behavior while incarcerated would complicate his pre-sentencing assessment.
By August 2026, international co-conspirators faced similar judicial reckoning. Conor Riley Moucka, a Canadian national known online as “Judische,” pleaded guilty to his role in the Snowflake extortion scheme. Meanwhile, co-conspirator Kenneth Schuchman—a 28-year-old Washington resident with a prior federal conviction for operating the Satori Internet-of-Things botnet in 2019—faced separate federal charges for assisting in the extortion campaigns. Another co-conspirator, American national John Erin Binns, remained wanted internationally, linked to historical major data breaches including a 2021 T-Mobile network intrusion that exposed the records of 76 million customers.
The Mechanics of the Snowflake Breaches and Telecom Extortion
The backbone of the Kiberphant0m enterprise relied on exploiting third-party cloud data repositories rather than breaching corporate perimeters directly. Companies utilizing Snowflake’s cloud storage services frequently fell victim to credential-stuffing attacks and account takeovers due to a widespread failure among corporate clients to mandate multi-factor authentication (MFA) across all administrative and user accounts.
Once inside these vulnerable cloud environments, Wagenius and his associates harvested massive repositories of structured telecommunications data. AT&T bore the brunt of the exposure, with the metadata of over 100 million customers compromised. In an escalation of pressure tactics after AT&T reportedly paid a $370,000 Bitcoin ransom to the broader extortion collective, Kiberphant0m engaged in re-extortion efforts.
Seeking to maximize leverage, the hacker posted datasets online that allegedly included call logs belonging to prominent political figures, including then-President-elect Donald Trump and then-Vice President Kamala Harris. Furthermore, Kiberphant0m threatened to release classified or sensitive schematics allegedly sourced from the U.S. National Security Agency (NSA), crossing the threshold from corporate cybercrime into potential national security espionage.
The Insider Threat Dimension and Multi-Agency Response
The involvement of an active-duty U.S. Army soldier with a secret security clearance alarmed federal defense and intelligence agencies. Paul Russell, the resident agent in charge at the Defense Criminal Investigative Service (DCIS)—the criminal investigative arm of the Department of Defense Office of Inspector General—emphasized the atypical nature of the case.
“We don’t often get leads where there’s an active-duty soldier with a secret clearance who’s creating hacking tools and trafficking in data,” Russell stated. “That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with.”
The investigation required a coordinated, cross-jurisdictional task force comprising DCIS, the Federal Bureau of Investigation (FBI), the Army Criminal Investigation Division (CID), and the U.S. Secret Service. The convergence of military counterintelligence and civilian federal cybercrime divisions underscored the federal government’s zero-tolerance stance on service members leveraging classified access or military infrastructure to engage in transnational cybercrime.
Post-Arrest Misconduct and Bureau of Prisons Security Concerns
While Wagenius earned some leniency in prosecutorial sentencing memos for his immediate guilty plea and subsequent cooperation, his conduct while detained awaiting sentencing introduced fresh legal complications. Court documents filed in September by federal prosecutors in Seattle revealed that Wagenius attempted to probe the computer network security of the Bureau of Prisons (BOP) from inside a federal detention facility.
According to BOP records cited in the government’s sentencing memorandum, Wagenius utilized unauthorized access to other inmates’ email accounts in September 2025. Through these proxies, he prompted commercial artificial intelligence tools to bypass standard safety guardrails via prompt injection techniques. Wagenius explicitly requested specific Common Vulnerabilities and Exposures (CVEs) related to Windows 10 Enterprise privilege escalation, step-by-step instructions for exploiting CVE-2023-45208 (a command injection vulnerability in D-Link networking hardware), and methods for constructing makeshift antennas using commissary items to extend radio reception within a correctional facility. He also researched instructions pertaining to prison escape methodologies.
When confronted by authorities regarding these queries, Wagenius claimed he was merely researching system vulnerabilities to provide defensive intelligence back to the BOP. Prosecutors maintained there was no evidence that Wagenius successfully deployed or executed any exploits against BOP digital infrastructure, but the attempts demonstrated a persistent compulsion toward technical exploitation even while incarcerated.
Broader Implications for Corporate Cybersecurity and Cloud Hygiene
The sentencing of Cameron Wagenius closes a significant chapter in one of the most disruptive cyber extortion sprees in recent corporate history, yet the broader implications for cybersecurity architecture remain profound. The Snowflake-related extortions served as a watershed moment for cloud security, prompting enterprise vendors to universally enforce multi-factor authentication and re-evaluate third-party access controls.
Security analysts point out that the case underscores the severe vulnerabilities introduced by supply-chain dependencies. Major telecommunications providers often outsource data analytics and storage to third-party cloud ecosystems, creating centralized honeypots that, if left inadequately protected, expose millions of consumer records through a single point of failure.
Furthermore, the integration of generative AI tools by incarcerated hackers highlights an emerging frontier in digital security. The ease with which technical exploits and vulnerability bypass instructions can be extracted from commercial AI models through prompt engineering presents ongoing challenges for correctional authorities and software developers alike.
As Wagenius begins his 70-month federal prison term, federal agencies continue to pursue remaining co-conspirators across international borders. The case stands as a stark reminder of the convergence between modern cloud vulnerabilities, transnational extortion syndicates, and the complex challenges of managing insider threats within the United States military.
















