Threats

Former Army Soldier Cameron Wagenius Sentenced to 70 Months for Snowflake and AT&T Data Theft Spree

September 26, 2026 04:00 · 8 min read
Former Army Soldier Cameron Wagenius Sentenced to 70 Months for Snowflake and AT&T Data Theft Spree

Former Army Soldier Sentenced for Multi-Company Cybercrime Spree

A former U.S. Army soldier, Cameron John Wagenius, has been sentenced to 70 months in federal prison for conducting a prolonged cybercrime campaign that targeted major corporations including AT&T and numerous Snowflake customers. The sentence was announced by the Justice Department on Friday, following Wagenius’ guilty plea in July 2025 to charges related to unauthorized access, data theft, and extortion attempts.

Crimes Committed While on Active Duty

Wagenius carried out these attacks while serving on active duty at Fort Cavazos in Texas, using his position and access to facilitate intrusions into corporate networks. Authorities stated he engaged in cybercriminal activities for years, including attempts to sell stolen data to foreign intelligence services and researching defection to Russia. His online aliases, “kiberphant0m” and “cyb3rph4nt0m,” were used on criminal forums where he collaborated with co-conspirators.

Role in Snowflake and AT&T Breaches

Wagenius was directly involved in compromising Snowflake customer environments, a breach that led to the theft of call detail records from AT&T. In July 2024, AT&T confirmed that cybercriminals had accessed its Snowflake instance and stole six months of phone and text records affecting nearly all of its customers. Wagenius leaked call records belonging to President Donald Trump as part of failed extortion attempts demanding $500,000 from the telecommunications giant.

Co-Conspirators and Extortion Campaign

He worked alongside Connor Moucka, a Canadian national extradited to the U.S. in March 2025 who pleaded guilty in August to playing a central role in the widespread Snowflake compromise affecting over 165 customer environments. Another alleged co-conspirator, John Erin Binns, remains outside U.S. custody. Together, the group stole billions of sensitive records and received more than $2.5 million in extortion payments, according to prosecutors.

Victims of the campaign included AT&T, Ticketmaster, Advance Auto Parts, and Santander. Wagenius was personally linked to extortion attempts targeting multiple organizations, with demands totaling over $1 million. Authorities confirmed he possessed stolen Snowflake-derived data at the time of his arrest in December 2024.

Forensic Evidence and Restitution

When law enforcement seized Wagenius’ devices in December 2024, they discovered thousands of stolen identification documents and significant cryptocurrency holdings. Despite being ordered not to, he purchased a new laptop and used it daily for five days in barracks at Fort Cavazos, employing VPN software to conceal his activities.

In addition to the prison sentence, Wagenius was ordered to pay nearly $295,000 in restitution to victims. Officials emphasized that his motivations extended beyond financial gain, citing a desire for status within hacking communities.

Statements from Law Enforcement

"Cameron Wagenius spent more than a year and a half betraying the trust placed in him as an active duty soldier by carrying out a sweeping cybercrime campaign,"

— A. Tysen Duva, Assistant Attorney General, Justice Department’s Criminal Division

"His hacking schemes were not only aimed at getting rich, he was also motivated by a desire to achieve status within criminal hacking communities."
— Charles Neil Floyd, First Assistant Attorney, U.S. District Court for the Western District of Washington

"It is especially shocking that a member of our armed forces, sworn to defend Americans and their constitutional rights, would engage in such a violation of privacy."
— W. Mike Herrington, Special Agent in Charge, FBI Seattle Field Office

The case underscores the risks posed by insider threats and the growing trend of cybercriminals exploiting cloud misconfigurations and stolen credentials to conduct large-scale data theft for extortion.


Source: CyberScoop

Source: CyberScoop

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free