U.S. Army Soldier Sentenced to Prison for Massive Cyber Extortion Campaign Targeting Global Telecommunications Giants

Cameron John Wagenius, a 22-year-old active-duty U.S. Army soldier, was sentenced today to 70 months in federal prison for his role as the mastermind behind a sophisticated, high-stakes cyber extortion campaign. Operating under the pseudonym "Kiberphant0m" while stationed at an Army base in South Korea, Wagenius orchestrated a series of data breaches that compromised the metadata of more than 100 million AT&T customers. In addition to his prison term, a federal judge in Seattle ordered Wagenius to pay $294,978 in restitution to his victims, marking the conclusion of a case that exposed glaring vulnerabilities in cloud infrastructure and the risks posed by radicalized insider threats.
The sentencing brings a definitive end to a digital crime spree that spanned international borders and prompted an unprecedented multi-agency investigation involving the FBI, the Defense Criminal Investigative Service (DCIS), the U.S. Secret Service, and the Army Criminal Investigative Division (CID).
The Mechanics of the Breach
The foundation of Wagenius’s campaign relied on the exploitation of the cloud data storage service Snowflake. During 2024, a significant number of Snowflake accounts belonging to major corporations were compromised due to inadequate security protocols, specifically the failure to enforce mandatory multi-factor authentication (MFA).
Wagenius and his co-conspirators leveraged these exposed credentials to gain unauthorized access to vast repositories of sensitive data. Once inside, they extracted call and text metadata—including source and destination phone numbers, timestamps, and the duration of communications—for tens of millions of users. The breach was not limited to AT&T; Kiberphant0m claimed responsibility for infiltrating over a dozen telecommunications companies worldwide, including the Push-to-Talk business unit of Verizon.
The strategy employed by the group was one of public extortion. Wagenius utilized prominent cybercrime forums to announce his illicit acquisitions, taunting the affected corporations and demanding payment in exchange for the non-disclosure of the stolen data.
Chronology of the Investigation and Arrest
The investigation gained momentum in late 2025, when cybersecurity researchers, notably those at KrebsOnSecurity, began mapping the digital footprint of Kiberphant0m. Analysts linked the persona’s activity patterns and technical preferences to a U.S. soldier stationed in South Korea.
- October 2024: Wagenius publicly brags on underground forums about the theft of metadata from tens of millions of AT&T customers.
- November 2025: Investigative reports publicly identify Kiberphant0m as a likely U.S. service member.
- December 2025: Federal agents move to arrest Wagenius. He is subsequently charged in two separate federal indictments.
- August 2026: Co-conspirator Conor Riley Moucka, known as "Judische," pleads guilty to his role in the Snowflake-related data thefts.
- September 2026: Federal prosecutors file a comprehensive sentencing memorandum detailing the scope of the criminal enterprise and the defendant’s continued attempts to breach computer systems while in custody.
- Today: The sentencing hearing in Seattle concludes with a 70-month prison sentence.
Co-Conspirators and the Cybercriminal Ecosystem
The prosecution of Wagenius has shed light on a broader, interconnected network of international cybercriminals. Among those linked to the scheme is Kenneth Schuchman, a 28-year-old from Vancouver, Washington. Schuchman, who previously pleaded guilty in 2019 to operating the "Satori" botnet—a massive network of infected Internet-of-Things (IoT) devices used for large-scale Distributed Denial-of-Service (DDoS) attacks—provided operational support to Wagenius.
Other key figures include Conor Riley Moucka of Kitchener, Ontario, who was apprehended in 2024 and entered a guilty plea in August 2026, and John Erin Binns, an American national currently residing in Turkey. Binns remains a person of interest in several high-profile investigations, including the 2021 T-Mobile breach that exposed the personal records of at least 76 million individuals.
The Insider Threat: A Security Paradigm Shift
The involvement of a soldier with secret-level security clearance created a uniquely complex challenge for the Department of Defense. Paul Russell, a resident agent in charge at the DCIS, highlighted the severity of the situation during post-sentencing remarks.
"We don’t often get leads where there’s an active-duty soldier with a secret clearance who is creating hacking tools and trafficking in data," Russell stated. "It was very serious from jump street, just because it was unique; it was an insider threat, and we weren’t sure what we were dealing with."
The realization that an individual with access to classified military information was also trafficking in stolen corporate and government data caused immediate alarm within the intelligence community. The potential for the exposure of national security secrets became a critical concern when, following the arrest of his associate Moucka, Wagenius leaked documents he claimed were NSA schematics and sensitive communication logs involving high-ranking U.S. government officials.
The "Prison Hacker" Phenomenon
Perhaps the most startling aspect of the case is the defendant’s inability to cease his criminal activities even after his initial arrest. Sentencing documents reveal that while incarcerated at a Bureau of Prisons (BOP) facility, Wagenius attempted to exploit the prison’s internal computer network.
Using the email accounts of other inmates, Wagenius attempted to perform "prompt injection" attacks on commercial AI tools. By framing his requests as research for a book, he sought detailed instructions and code to exploit vulnerabilities such as CVE-2023-45208, a known command injection flaw in D-Link networking hardware. Furthermore, he sought guidance on constructing makeshift radio antennas within the facility and researched methods for escaping incarceration.
Federal prosecutors noted that while there is no evidence he successfully deployed these exploits within the BOP infrastructure, the attempts demonstrated a "persistent and pathological" commitment to cybercrime.
Analysis: Implications for Corporate and Government Security
The case of Cameron Wagenius serves as a stark reminder of the fragile state of digital privacy in an era of automated, large-scale data harvesting. The failure of major telecommunications providers to implement robust multi-factor authentication and the subsequent ease with which Snowflake credentials were exploited underscores the necessity of a "Zero Trust" architecture.
Financially, the case presents a paradox. Despite the massive scale of the data exfiltration, the total monetary gain for Wagenius was reported to be approximately $1,500. This disparity between the immense damage caused to victims and the negligible financial return highlights a shift in cyber-motivation: for actors like Wagenius, the goal was as much about the thrill of the intrusion and the disruption of institutional stability as it was about monetary profit.
For the U.S. government, the case necessitates a re-evaluation of how it monitors the digital activities of service members with high-level clearances. The "insider threat" is no longer limited to physical document theft; it now encompasses the entire digital life of the employee.
As Wagenius begins his 70-month sentence, the telecommunications industry continues to grapple with the aftermath of the breaches. The incident has forced a industry-wide pivot toward more rigorous security audits and, in the case of Snowflake, the imposition of mandatory MFA across all user tiers. Ultimately, the prosecution serves as a deterrent, emphasizing that the anonymity of a hacker persona, even one bolstered by sophisticated technical skill, is rarely a match for the coordinated reach of federal law enforcement.







