U.S. Army Soldier Sentenced to 70 Months in Prison for Massive Telecom Extortion and Data Theft Operation

Cameron John Wagenius, a 22-year-old U.S. Army soldier, has been sentenced to 70 months in federal prison following his role in a sophisticated, wide-ranging cybercrime campaign that compromised the metadata of over 100 million AT&T customers. The sentencing, handed down by a federal judge in Seattle, concludes a high-stakes investigation into a series of extortion attempts that rattled the telecommunications industry and drew the immediate attention of national security agencies. Beyond the prison term, Wagenius was ordered to pay $294,978 in restitution to his victims.
The case of Wagenius, who operated under the alias “Kiberphant0m,” represents a significant intersection of insider threats and modern cyber-extortion. Stationed at a U.S. military base in South Korea at the time of his activities, Wagenius leveraged his technical proficiency to exploit vulnerabilities in cloud-based storage environments, specifically targeting companies utilizing Snowflake.
A Chronology of the Breach and Subsequent Investigation
The criminal activity initiated by Wagenius and his associates gained momentum in 2024, centered on the exploitation of cloud storage accounts that lacked multi-factor authentication (MFA). By accessing these insecure environments, the group was able to exfiltrate vast quantities of sensitive metadata—including timestamps, call durations, and destination numbers—for millions of users across multiple telecommunications providers worldwide.
The timeline of the investigation and the perpetrator’s downfall is as follows:
- Mid-2024: Wagenius and his co-conspirators begin exploiting misconfigured Snowflake credentials to harvest telecom customer data.
- October 2024: Kiberphant0m begins publicly bragging on dark web forums about the theft of call and text metadata from AT&T, while simultaneously claiming to have breached over a dozen global telecommunications companies, including Verizon’s Push-to-Talk network.
- November 2024: KrebsOnSecurity publishes a report identifying the likely location and occupation of the individual behind the Kiberphant0m persona, pointing toward a U.S. soldier in South Korea.
- December 2024: Following the investigative lead, federal authorities arrest Wagenius. He is subsequently hit with two separate federal indictments.
- August 2026: Conor Riley Moucka, a key co-conspirator, pleads guilty in Canada for his role in the Snowflake-related data thefts.
- September 2026: Federal prosecutors file a comprehensive sentencing memorandum detailing not only the original crimes but also subsequent attempts by Wagenius to probe Bureau of Prisons (BOP) systems while in custody.
- Current Date: Wagenius is sentenced to nearly six years in prison.
The Anatomy of the Extortion Campaign
While the scale of the data exfiltrated was immense, the financial gains for the perpetrators remained surprisingly modest. Prosecutors noted that Wagenius managed to extract only about $1,500 in direct profits from the stolen data, despite the monumental effort and risk involved. The group attempted to force larger payouts through extortion, threatening to dump the sensitive information publicly if companies failed to meet their ransom demands.
The operation turned particularly brazen following the arrest of co-conspirator Conor Riley Moucka. In a desperate move to re-extort victims after AT&T had already paid a $370,000 Bitcoin ransom, Kiberphant0m attempted to raise the stakes by claiming to release call logs belonging to high-profile political figures, including President-elect Donald Trump and Vice President Kamala Harris. Furthermore, the group claimed to be in possession of stolen schematics belonging to the U.S. National Security Agency (NSA), an assertion that triggered an immediate, multi-agency response from the Department of Defense and federal intelligence services.
Multi-Agency Response and the Insider Threat Problem
The involvement of a soldier with secret clearance elevated the case from a standard criminal investigation to a matter of national security. Paul Russell, a resident agent in charge at the Defense Criminal Investigative Service (DCIS), emphasized the rarity and gravity of the situation.
"We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data," Russell stated. The inter-agency task force, which included the FBI, the Army Criminal Investigative Division (CID), and the U.S. Secret Service, worked in tandem to neutralize the threat. The case serves as a stark reminder of the "insider threat" vulnerability, where individuals with authorized access to systems or specialized knowledge can leverage that access for malicious ends.
Unrepentant Conduct Behind Bars
One of the most troubling aspects of the sentencing memorandum is the disclosure of Wagenius’s behavior while awaiting trial. Despite his plea of guilt, prosecutors revealed that Wagenius did not cease his digital investigations. Using the email accounts of other inmates, he attempted to gain information on computer vulnerabilities by utilizing AI tools—a practice known as "prompt injection."
Wagenius reportedly asked AI models to provide information on privilege escalation vulnerabilities in Windows 10 and requested specific code for the CVE-2023-45208 exploit, a known vulnerability in D-Link networking devices. Furthermore, he inquired about constructing antennas within the prison environment to improve radio reception and even researched methods for prison escape.
While the government conceded they had no evidence that these probes were successfully executed against BOP infrastructure, the attempts demonstrated a continued commitment to malicious digital activity even after being apprehended. Wagenius claimed his inquiries were part of research for a book, but federal prosecutors characterized these as clear attempts to bypass AI safety guardrails.
Broader Implications for Cybersecurity
The fallout from the Wagenius case provides critical lessons for both the private sector and government entities. The primary vector for the breach—the failure to enforce multi-factor authentication on cloud storage services—has become a focal point for security audits across the industry. Snowflake, in response to the breaches, has since mandated MFA for all user accounts, a shift that cybersecurity experts hope will become a standard requirement for all enterprise-level cloud service providers.
Furthermore, the case underscores the growing misuse of generative AI in cybercrime. Attackers are increasingly using "jailbroken" or manipulated prompts to bypass the ethical filters that prevent AI tools from providing instructions on how to exploit software vulnerabilities. The sentencing of Wagenius serves as a deterrent but also highlights the need for more robust monitoring of institutional networks and a greater focus on the human element of cybersecurity.
The case also brings into sharp focus the role of international co-conspirators. With John Erin Binns still at large in Turkey—a man also linked to the massive 2021 T-Mobile breach—the investigation remains a global endeavor. The collaboration between the U.S. and its international partners, such as the Canadian authorities who apprehended Moucka, remains essential in tracking down actors who operate across borders to exploit American infrastructure.
Conclusion
Cameron John Wagenius’s journey from a soldier with a secret clearance to a convicted cyber-extortionist marks a definitive end to one of the most publicized data breaches of the mid-2020s. While the financial impact of his crimes was limited compared to the massive scale of the data involved, the systemic risks he posed—ranging from the exposure of national security documents to the targeting of high-level political communications—have left a lasting mark on federal law enforcement protocols.
As the telecommunications industry continues to harden its defenses, the sentence handed down in Seattle serves as a firm message regarding the consequences of weaponizing technical knowledge against the public and the state. The case of "Kiberphant0m" will likely be cited in future discussions regarding the intersection of internal military discipline, the security of cloud-based infrastructure, and the evolving threats posed by the intersection of AI-assisted hacking and traditional cyber-extortion.




