Home Cybersecurity & Hacking U.S. Army Soldier Sentenced to Nearly Six Years in Federal Prison Over Massive Telecom Hacking and Extortion Scheme

U.S. Army Soldier Sentenced to Nearly Six Years in Federal Prison Over Massive Telecom Hacking and Extortion Scheme

by admin

A federal judge in Seattle has sentenced 22-year-old U.S. Army soldier Cameron John Wagenius to 70 months in federal prison, concluding a high-profile cybercrime case that exposed the vulnerabilities of cloud data storage providers and major global telecommunications infrastructure. Operating under the online persona “Kiberphant0m” while stationed at a U.S. military base in South Korea, Wagenius pleaded guilty to multiple charges stemming from a wide-ranging campaign of data theft, extortion, and the exposure of sensitive metadata belonging to over 100 million AT&T customers. In addition to his prison term, Wagenius was ordered to pay $294,978 in restitution to his victims.

The sentencing marks a critical milestone for federal law enforcement agencies, including the Federal Bureau of Investigation (FBI), the Army Criminal Investigation Division (CID), the U.S. Secret Service, and the Defense Criminal Investigative Service (DCIS). Prosecutors detailed a sprawling criminal conspiracy that involved multiple international co-conspirators, corporate extortion, high-stakes data breaches, and an insider threat involving an active-duty soldier with a secret security clearance. Despite the massive scale of the data compromised, the case also highlighted the sometimes meager financial returns of modern cybercrime, with investigators revealing that Wagenius netted a paltry $1,500 from his direct sales of stolen proprietary information.

The Anatomy of the Snowflake and AT&T Breaches

The foundation of the hacking campaign orchestrated by Wagenius and his associates relied heavily on unsecured enterprise credentials and a lack of baseline security controls at major corporations. The attackers targeted cloud data storage service Snowflake, exploiting accounts that lacked mandatory multi-factor authentication (MFA). By leveraging exposed credentials, the threat actors gained unauthorized access to databases hosted by several large enterprise customers, allowing them to siphon vast troves of proprietary data.

In October 2024, operating as Kiberphant0m, Wagenius made waves across underground cybercrime forums by publicly boasting about a massive cache of stolen call and text metadata. This data included critical communication logs for tens of millions of AT&T customers, detailing source and destination phone numbers, call timestamps, and exact durations. Furthermore, the threat actor claimed to have infiltrated more than a dozen telecommunications companies worldwide, including Verizon’s specialized Push-to-Talk business.

Rather than merely selling the data on illicit forums, Wagenius and his co-conspirators turned to public extortion. The group threatened to publish the confidential logs unless the corporate victims paid substantial ransoms in cryptocurrency. In total, the extortion ring managed to extract a $370,000 Bitcoin ransom from AT&T. However, internal friction, rapid law enforcement intervention, and subsequent arrests quickly unraveled the criminal enterprise.

A Global Cast of Co-Conspirators and Cybercriminal Veterans

Federal prosecutors emphasized that Wagenius did not operate in a vacuum. He was aided by a network of seasoned cybercriminals with deep roots in the digital underground. Among them was Kenneth Schuchman, a 28-year-old resident of Vancouver, Washington, whose criminal history includes a 2019 guilty plea for operating the notorious Satori Internet-of-Things (IoT) botnet—a massive network of compromised smart devices used to launch devastating distributed denial-of-service (DDoS) attacks against global internet infrastructure.

Other key figures in the Snowflake data theft operations included Conor Riley Moucka, a Canadian national from Kitchener, Ontario, who operated under the alias “Judische.” Moucka was arrested in 2024 and subsequently pleaded guilty in August 2026. Additionally, the conspiracy involved John Erin Binns, an American citizen currently residing in Turkey, who has long been wanted by federal authorities in connection with a massive 2019 data breach at T-Mobile that compromised the personal details of at least 76 million customers.

The escalation of Kiberphant0m’s extortion tactics ultimately triggered a reckless downward spiral. Following Moucka’s arrest—and even after AT&T had already paid out the $370,000 Bitcoin ransom—Kiberphant0m retaliated by dumping additional sensitive data onto hacker forums. This included call logs allegedly belonging to then-President-elect Donald Trump and then-Vice President Kamala Harris, alongside engineering schematics purportedly stolen from the U.S. National Security Agency (NSA). This brazen inclusion of national security secrets transformed the investigation from a corporate extortion probe into an urgent counterintelligence priority.

Chronology of an Insider Threat Investigation

The investigation into Kiberphant0m accelerated rapidly in late 2024, driven by digital forensics and open-source intelligence work. In November 2024, independent cybersecurity journalist Brian Krebs published an analysis warning that the threat actor behind the Kiberphant0m persona was likely an active-duty U.S. soldier stationed in South Korea.

Less than a month after that public warning, federal agents apprehended Wagenius. He was promptly hit with two separate federal indictments and chose to cooperate with prosecutors, pleading guilty to all counts across both cases.

Paul Russell, the resident agent in charge at the Defense Criminal Investigative Service (DCIS)—the criminal investigative arm of the U.S. Department of Defense Office of Inspector General—noted the unique and alarming nature of the case. In interviews following the sentencing, Russell emphasized that discovering an active-duty military member with a secret security clearance actively manufacturing hacking tools, trading stolen corporate data, and engaging in international extortion was an extreme anomaly.

“We don’t often get leads where there’s an active-duty soldier with a secret clearance who’s creating hacking tools and trafficking in data,” Russell stated. “That doesn’t happen every day, and so when that hits, it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with.”

Incarceration and Attempted Exploits in Federal Custody

Even after his arrest and while awaiting trial in federal custody, Wagenius demonstrated a persistent drive to probe computer systems, landing himself in further administrative and legal trouble. A sentencing memo filed by federal prosecutors in Seattle on September 19 detailed how Wagenius had violated the computer use policies of the U.S. Bureau of Prisons (BOP) in an attempt to uncover vulnerabilities within correctional facility networks.

According to BOP records cited by the prosecution, Wagenius utilized another inmate’s email account in September 2025 to query a commercial artificial intelligence tool. Posing his requests through sophisticated prompt-injection techniques—often framing the queries as research for a book he claimed to be writing—Wagenius attempted to bypass AI safety guardrails. He asked the system to identify privilege escalation and bypass vulnerabilities in Windows 10 Enterprise, requested functional working scripts for specific Common Vulnerabilities and Exposures (CVEs), and asked for step-by-step instructions regarding CVE-2023-45208, a command injection vulnerability found in D-Link networking hardware.

Furthermore, records indicated that Wagenius used inmate communication channels to research how to construct makeshift radio antennas using commissary items to extend reception inside a prison environment, alongside queries concerning methods for escaping incarceration.

While federal prosecutors acknowledged they found no evidence that Wagenius successfully deployed these exploits against BOP computer systems—with the defendant claiming his research was intended to help authorities identify weaknesses—the incidents underscored his ongoing technical fixation. The government’s sentencing memo dryly noted that despite handling massive volumes of high-value corporate data, Wagenius’s direct financial gains from his cybercrime exploits totaled a mere $1,500. “While Wagenius was not particularly financially successful as a cybercriminal, he both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government,” the memo concluded.

Broader Implications for Corporate Cybersecurity and National Defense

The sentencing of Cameron Wagenius closes a significant chapter in one of the most disruptive cybercrime waves in recent memory, but the broader implications for enterprise security and military protocol continue to reverberate. The Snowflake-related extortions forced a painful reckoning across the cloud storage and telecommunications sectors, prompting widespread adoption of mandatory multi-factor authentication and rigorous credential management.

For the U.S. military and defense intelligence apparatus, the case serves as a stark warning regarding modern insider threats. The ease with which a junior service member with a secret clearance could pivot from military duties to international cyber extortion highlights critical gaps in personnel vetting and internal digital monitoring. As federal authorities continue legal proceedings against remaining co-constituents like John Erin Binns, the legal outcome for Wagenius stands as a severe deterrent against the weaponization of military access for illicit cyber operations.

You may also like

Leave a Comment