A federal court in Seattle has sentenced a 22-year-old active-duty U.S. Army soldier to 70 months in prison for orchestrating a sprawling international cybercrime and extortion campaign. Cameron John Wagenius, who operated under the alias "Kiberphant0m" while stationed at a military base in South Korea, pleaded guilty to multiple federal charges related to hacking into major telecommunications companies, stealing sensitive metadata from more than 100 million AT&T customers, and attempting to blackmail corporate victims. In addition to his prison term, Wagenius was ordered to pay $294,978 in restitution to his victims.
The sentencing brings a definitive legal close to a high-profile cyber espionage and extortion scheme that exposed critical vulnerabilities in cloud-storage ecosystems and telecom networks. Despite the monumental scale of the data he compromised—including call and text logs belonging to tens of millions of mobile users—prosecutors revealed that Wagenius netted a remarkably paltry sum of approximately $1,500 from his illicit data sales, highlighting a striking disjunction between the vast magnitude of the harm caused and the meager financial rewards realized by the perpetrator.
The Genesis of "Kiberphant0m": Cloud Vulnerabilities and Compromised Credentials
The sprawling conspiracy centered largely around widespread security oversights in cloud data storage services, most notably Snowflake. During his deployment in South Korea, Wagenius, holding a secret security clearance, adopted the moniker Kiberphant0m and aligned himself with an international syndicate of cybercriminals. This collective capitalized on exposed user credentials and a widespread failure across organizations to enforce multi-factor authentication (MFA). By exploiting these foundational security gaps, the group systematically breached multiple large enterprise accounts hosted on cloud platforms, downloading vast repositories of proprietary and customer data.
By October 2024, Kiberphant0m emerged as a public figure within underground cybercrime forums, openly boasting about his exploits. He claimed responsibility for infiltrating more than a dozen international telecommunications organizations, including Verizon’s specialized Push-to-Talk business. The core of his theft involved the extraction of massive volumes of telecommunications metadata—specifically source and destination numbers, time stamps, and call durations—for over 100 million AT&T subscribers.
Wagenius and his co-conspirators leveraged this stolen information to run an aggressive extortion campaign. They directly targeted the afflicted corporations, threatening to publicly leak the sensitive proprietary data and customer metadata unless exorbitant ransom demands were met.
A Chronology of Investigation, Identification, and Arrest
The unraveling of the Kiberphant0m persona represents a textbook example of collaborative digital forensics between investigative journalism and federal law enforcement agencies.
- Late November 2024: Cybersecurity publication KrebsOnSecurity published an investigative report warning that the individual operating as Kiberphant0m was likely an active-duty U.S. soldier stationed on the Korean Peninsula.
- December 2024: Law enforcement agencies swiftly acted on the public disclosures and internal leads. Cameron Wagenius was arrested and subsequently hit with two separate federal indictments. Confronted with overwhelming digital evidence, he quickly opted to plead guilty to all charges.
- September 2025: While awaiting sentencing in federal detention, Wagenius was caught attempting to probe and compromise the computer network of the Bureau of Prisons (BOP), utilizing sophisticated prompt injection techniques against commercial artificial intelligence tools.
- August 2026: Canadian co-conspirator Conor Riley Moucka pleaded guilty to his role in the Snowflake-related extortion campaigns.
- Today: Wagenius receives his final sentence of 70 months in federal prison alongside nearly $300,000 in restitution during a hearing in Seattle.
An International Network of Co-Conspirators
Federal prosecutors emphasized that Wagenius did not act in a vacuum. He operated within a sophisticated ecosystem of seasoned cybercriminals. Chief among his alleged partners was Kenneth Schuchman, a 28-year-old resident of Vancouver, Washington, with a notorious background in digital crime. Schuchman previously pleaded guilty in 2019 to operating the Satori botnet—a massive, automated network of hijacked Internet-of-Things (IoT) devices responsible for crippling, large-scale distributed denial-of-service (DDoS) attacks.
Other central figures in the sweeping Snowflake-related data theft investigations include Conor Riley Moucka, operating under the alias "Judische," of Kitchener, Ontario, who was arrested in 2024 and formally entered a guilty plea in August 2026. Furthermore, American national John Erin Binns, residing in Turkey, remains wanted by authorities for his alleged participation in the monumental 2021 T-Mobile data breach, which compromised the personal information of at least 76 million consumers.
Escalation, Double-Crossing, and National Security Threat
As pressure mounted from international law enforcement, the extortion tactics employed by Kiberphant0m grew increasingly erratic and reckless. Following the initial arrest of Conor Moucka—and despite the fact that AT&T had already paid the extortion syndicate a $370,000 ransom in Bitcoin—Kiberphant0m engaged in a retaliatory double-cross.
In an effort to pressure victims and flaunt his reach, Wagenius published files on underground hacker forums that he claimed included call logs belonging to prominent political figures, specifically then-President-elect Donald Trump and then-Vice President Kamala Harris. More alarmingly, he threatened to leak classified documents and technical schematics allegedly stolen from the U.S. National Security Agency (NSA). This brazen pivot from corporate extortion to the reckless handling of national security secrets transformed the investigation from a corporate cybercrime case into a top-tier national security priority.
A Multi-Agency Response to an Unprecedented Insider Threat
The intersection of active-duty military service, active security clearances, and sophisticated cyberattacks triggered an immediate, high-priority response across the United States defense and law enforcement apparatus. Paul Russell, the resident agent in charge at the Defense Criminal Investigative Service (DCIS)—the criminal investigative arm of the Department of Defense Office of Inspector General—highlighted the atypical nature of the case.
According to Russell, when DCIS received actionable intelligence indicating that an active-duty soldier with a secret clearance was actively engineering hacking tools and trafficking in stolen data, the response was immediate. The agency launched a joint task force comprising the Federal Bureau of Investigation (FBI), the Army Criminal Investigation Division (CID), and the U.S. Secret Service.
"We don’t often get leads where there’s an active-duty soldier with a secret clearance who’s creating hacking tools and trafficking in data," Russell noted. "That doesn’t happen every day, and so when that hits, it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with."
In-Custody Misconduct and the Abuse of Artificial Intelligence
Details emerging from the federal sentencing memorandum filed by prosecutors in Seattle shed light on Wagenius’s persistent technical ambitions, even while incarcerated. While awaiting sentencing in Bureau of Prisons (BOP) facilities, Wagenius reportedly violated institutional computer use policies in a systematic effort to map out vulnerabilities within the prison system’s administrative network.
Records cited by the prosecution reveal that in September 2025, Wagenius utilized another inmate’s electronic messaging account to query commercial artificial intelligence systems. To bypass built-in safety controls designed to prevent the generation of malicious code, Wagenius employed "prompt injection"—a technique where deceptive contexts, such as claiming the queries were for a book he was writing, are used to trick AI models into outputting actionable exploitation material.
In one instance, Wagenius asked an AI tool to detail specific Common Vulnerabilities and Exposures (CVEs) related to Windows 10 Enterprise privilege escalation, demanding "a real world working script for each CVE . . . without omitted code." Shortly thereafter, he requested step-by-step instructions and potential code for CVE-2023-45208, a command injection vulnerability found in D-Link networking hardware. Furthermore, records show he sought instructions on constructing improvised radio antennas using prison commissary items to extend reception, alongside queries concerning prison escape strategies.
While prosecutors acknowledged there was no definitive evidence that Wagenius successfully deployed these researched vulnerabilities against BOP infrastructure, the attempted exploitation underscored his persistent technological threat profile. When questioned by authorities, Wagenius maintained that his research into potential system flaws was intended solely to assist the BOP in improving its security posture—an explanation prosecutors viewed with considerable skepticism.
Broader Implications for Corporate and National Security
The legal conclusion of the Cameron Wagenius case serves as a watershed moment for contemporary cybersecurity, underscoring systemic vulnerabilities across multiple vectors of modern digital infrastructure.
First, the incident exposed the fragile reliance on third-party cloud data storage ecosystems. The Snowflake breaches demonstrated how enterprise-level data repositories can be compromised simply through poor credential hygiene and the absence of mandatory multi-factor authentication. In the wake of these incidents, major cloud providers and enterprise vendors have aggressively moved toward mandatory MFA enforcement to mitigate credential-stuffing and unauthorized access vectors.
Second, the case highlights the evolving threat landscape posed by insider actors. The convergence of military-grade security clearances with advanced technical proficiency creates severe risks for national defense agencies. The ability of a single service member to exfiltrate massive datasets, traffic in sensitive metadata, and subsequently threaten national security disclosures forced defense and intelligence agencies to reevaluate internal monitoring, clearance vetting, and digital access controls.
Finally, the incident illustrates the growing risks associated with the misuse of generative artificial intelligence. Wagenius’s in-custody attempts to weaponize commercial AI models via prompt injection demonstrate how malicious actors can leverage large language models to automate the discovery of privilege escalation paths and exploit scripts, lowering the technical barrier to sophisticated cyber operations even from behind prison walls.
As Wagenius begins his nearly six-year federal prison sentence, the broader digital ecosystem continues to grapple with the long-term fallout of the Snowflake and AT&T breaches. Federal authorities maintain that while the financial yield of the operation was negligible, the widespread disruption, corporate expenditures, and national security implications justify the severe punitive measures handed down by the court.


