Threats

U.S. Army Soldier Cameron Wagenius Sentenced to 70 Months for Telecom Data Theft and Extortion Scheme

September 26, 2026 00:01 · 8 min read
U.S. Army Soldier Cameron Wagenius Sentenced to 70 Months for Telecom Data Theft and Extortion Scheme

Sentencing and Restitution for Telecom Data Breach

Cameron John Wagenius, a 22-year-old U.S. Army soldier stationed at a base in South Korea, was sentenced to 70 months in federal prison and ordered to pay $294,978 in restitution after pleading guilty to hacking telecommunications companies and stealing mobile call and text metadata from more than 100 million AT&T customers in 2024. The sentencing took place in Seattle, where prosecutors detailed how Wagenius operated under the online alias "Kiberphant0m" and coordinated with alleged co-conspirators to exploit weak security at cloud storage providers.

Exploitation of Snowflake Vulnerabilities and Telecom Intrusions

Working with three alleged accomplices, Wagenius accessed data from Snowflake customers that had exposed credentials and lacked multi-factor authentication — a vulnerability Snowflake later addressed by mandating MFA across all accounts. In October 2024, he claimed on cybercrime forums to have stolen call and text metadata for tens of millions of AT&T users, including details such as source and destination numbers, timestamps, and call durations. He also asserted he had breached more than a dozen telecommunications companies globally, including Verizon’s Push-to-Talk service, and publicly extorted them by threatening to leak the stolen data unless paid.

Investigation and Arrest Linked to Insider Threat Concerns

KrebsOnSecurity first warned in late November 2025 that "Kiberphant0m" was likely a U.S. soldier based in South Korea. Less than a month later, Wagenius was arrested and charged in two separate federal indictments. He subsequently pleaded guilty to all counts. Federal prosecutors noted he was assisted by Kenneth Schuchman, a 28-year-old from Vancouver, Washington, who had previously pleaded guilty in 2019 to operating the Satori botnet, a large IoT-driven DDoS network. Two other alleged co-conspirators remain charged: Conor Riley Moucka ("Judische") of Kitchener, Ontario, arrested in 2024 and who pleaded guilty in August 2026, and John Erin Binns, an American residing in Turkey who is also wanted for a 2021 T-Mobile breach affecting at least 76 million customers.

Post-Arrest Extortion Attempts and National Security Claims

After Moucka’s arrest — following AT&T’s payment of a $370,000 Bitcoin ransom — Wagenius posted on hacker forums what he claimed were call logs for then President-elect Donald Trump and Vice President Kamala Harris, along with schematics allegedly stolen from the U.S. National Security Agency (NSA). He also admitted to re-extorting victims and threatening to disclose national security secrets. These actions heightened concerns due to his status as an active-duty soldier with secret clearance.

Response from Defense Investigative Agencies

Paul Russell, resident agent in charge at the Defense Criminal Investigative Service (DCIS), explained that when the agency learned a soldier with secret clearance was allegedly involved in cybercrime and extortion, it launched a joint investigation with the FBI, Army Criminal Investigative Division (CID), and U.S. Secret Service. Russell emphasized the rarity of such insider threats: "We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data. That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with."

Prison Misconduct and AI-Assisted Vulnerability Research

A sentencing memo filed Sept. 19 by federal prosecutors in Seattle revealed that while Wagenius was cooperative during his plea, he violated Bureau of Prisons (BOP) computer use policies while incarcerated and awaiting sentencing. In or around September 2025, he used another inmate’s email to prompt a commercial AI tool to request information about Windows 10 Enterprise privilege escalation CVEs and working exploit scripts. Less than a week later, he used a different inmate’s email to ask for step-by-step details on CVE-2023-45208, a command injection flaw in D-Link networking devices. He also inquired about constructing makeshift antennas from prison commissary items to improve radio reception and sought guidance on escaping prison.

Prosecutors stated Wagenius framed these AI queries as research for a book he was writing — a tactic known as prompt injection, where deceptive inputs are used to bypass AI safety guards. However, the government found no evidence he successfully deployed any of the vulnerabilities he researched in BOP systems, and Wagenius claimed he was only seeking information to help the BOP improve its security.

Limited Financial Gain Despite Massive Data Theft

Despite accessing data from over 100 million AT&T customers and attempting to extort multiple telecom providers, Wagenius’s cybercriminal efforts yielded minimal financial return. The government’s sentencing memo stated he made only about $1,500 from selling stolen data. Nevertheless, prosecutors stressed that while he was not financially successful, he intended to and did cause significant harm to individual victims, U.S. corporations, and the government through the violation of privacy, abuse of trust, and threats to national security.


Source: Krebs on Security

Source: Krebs on Security

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free