U.S. Army Soldier Sentenced to Prison for Massive Telecommunications Data Breach and Extortion Scheme

Cameron John Wagenius, a 22-year-old U.S. Army soldier, was sentenced to 70 months in federal prison today, marking the conclusion of a high-stakes investigation into a sprawling cybercriminal campaign that compromised the sensitive metadata of over 100 million AT&T customers. In addition to his prison term, Wagenius, who operated under the digital alias "Kiberphant0m," has been ordered to pay $294,978 in restitution to his victims. The sentencing, held in a Seattle federal courtroom, serves as a sobering coda to a case that spanned continents and raised significant alarms regarding the vulnerability of national security and the integrity of corporate data infrastructure.
Wagenius, who was stationed at a military installation in South Korea at the time of his illicit activities, leveraged his position and technical proficiency to infiltrate the cloud-based storage services of major corporations, most notably Snowflake. By exploiting exposed credentials and targeting systems that lacked mandatory multi-factor authentication (MFA), Wagenius and his associates gained unauthorized access to massive troves of customer data.
A Chronology of Cyber-Extortion
The scope of the operation became clear in October 2024, when Wagenius took to various underground cybercrime forums to boast about his acquisition of call and text metadata—including timestamps, durations, and source/destination numbers—belonging to tens of millions of AT&T subscribers. His claims were not limited to a single provider; he asserted that he had successfully breached over a dozen telecommunications entities worldwide, including Verizon’s specialized Push-to-Talk business.
The investigation into the "Kiberphant0m" persona began in earnest in late 2025, when security researchers at KrebsOnSecurity identified patterns suggesting the perpetrator was likely a U.S. military member operating out of South Korea. This intelligence proved pivotal. By December 2025, a joint operation involving the FBI, the U.S. Army Criminal Investigative Division (CID), the U.S. Secret Service, and the Defense Criminal Investigative Service (DCIS) resulted in the arrest of Wagenius. He was charged under two separate federal indictments and quickly entered guilty pleas to all counts, acknowledging his role in the breaches and the subsequent extortion attempts.
The Network of Conspirators
Wagenius did not act alone. Prosecutors identified a sophisticated network of collaborators, among them Kenneth Schuchman, a 28-year-old from Vancouver, Washington. Schuchman, a figure previously known to federal authorities for his 2019 conviction regarding the operation of the Satori IoT botnet, played a critical role in the extortion efforts.
Other key figures involved in the broader Snowflake-related data theft saga include Conor Riley Moucka, also known as "Judische," a Canadian national from Kitchener, Ontario, who pleaded guilty to his role in August 2026. Furthermore, John Erin Binns, an American currently residing in Turkey, remains a subject of intense federal interest, linked not only to the Kiberphant0m case but also to a massive 2021 T-Mobile data breach that affected at least 76 million people.
The National Security Dimension
The gravity of the case escalated significantly when the extortion efforts pivoted toward national security. After AT&T reportedly paid a ransom of $370,000 in Bitcoin, the group continued to exert pressure on the company. Following the arrest of his associate, Moucka, Wagenius retaliated by leaking what he purported to be the call logs of high-ranking government officials, including President-elect Donald Trump and Vice President Kamala Harris. Furthermore, he claimed to possess and distribute schematics stolen from the U.S. National Security Agency (NSA).
Paul Russell, the resident agent in charge at the Defense Criminal Investigative Service, highlighted the unprecedented nature of the case. "We don’t often get leads where there’s an active-duty soldier with a secret clearance who is creating hacking tools and trafficking in data," Russell stated. "It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with."
Incarceration and Continued Subversion
Despite his cooperation with federal authorities following his arrest, the government’s sentencing memorandum filed on September 19, 2026, revealed that Wagenius remained a persistent threat even while in custody. During his pre-sentencing detention, he reportedly violated Bureau of Prisons (BOP) computer use policies in a concerted effort to identify vulnerabilities in the federal prison system’s own digital infrastructure.
Court records indicate that Wagenius attempted to manipulate commercial AI tools to provide technical guidance on Windows 10 privilege escalation and D-Link command injection vulnerabilities (CVE-2023-45208). Employing "prompt injection" techniques—a method of bypassing AI safety filters by framing requests within a fictionalized context, such as writing a book—Wagenius sought detailed, actionable code to exploit these systems. He even went as far as inquiring about methods for constructing radio antennas within a prison environment and researching potential escape tactics. While the government found no evidence that he successfully deployed these exploits, the attempt underscored a compulsive propensity for illicit technical subversion.
Analysis: Implications for Corporate and Military Security
The Wagenius case provides a stark case study in the risks of the modern digital landscape. The primary takeaway for the private sector is the critical necessity of multi-factor authentication (MFA) and the tightening of credential management within cloud-based storage environments. Snowflake, which was the central node of the breach, has since mandated MFA across all customer accounts, a move that security analysts argue should be a baseline standard for any firm handling sensitive metadata.
For the Department of Defense, the case exposes the vulnerabilities inherent in an era where junior-level personnel may possess the technical capability to bypass sophisticated corporate security measures while maintaining high-level security clearances. The "insider threat" posed by Wagenius was not just a failure of individual conduct but a challenge to existing military protocols regarding the monitoring of personnel with access to sensitive digital assets.
Despite the massive volume of data compromised—affecting roughly 100 million individuals—the financial gain for the perpetrators was surprisingly meager. Prosecutors noted that Wagenius earned only approximately $1,500 from the sale of stolen data, suggesting that his motivations were driven as much by notoriety, ego, and "hacking culture" status as by monetary profit.
"While Wagenius was not particularly financially successful as a cybercriminal, he both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government," the prosecution noted in its memo. The sentence of 70 months acts as a definitive deterrent, signaling that the intersection of military service, unauthorized cyber-activity, and extortion will be met with the full force of federal law enforcement.
As the digital ecosystem continues to expand, the Wagenius case will likely be cited in future policy discussions regarding the intersection of artificial intelligence, insider threat mitigation, and the protection of critical telecommunications infrastructure. The era of the "lone wolf" hacker has largely been replaced by these loosely affiliated, international, and highly persistent networks—a reality that necessitates a more integrated, cross-agency approach to global cybersecurity.







