Cybersecurity & Privacy

U.S. Army Soldier Sentenced to Prison for Massive Telecommunications Data Breach and Extortion Scheme

Cameron John Wagenius, a 22-year-old U.S. Army soldier, has been sentenced to 70 months in federal prison following his role in one of the most significant telecommunications data breaches in recent history. The sentencing, handed down by a federal judge in Seattle, marks the culmination of a high-stakes investigation into a cybercriminal collective that compromised the personal metadata of over 100 million AT&T customers. In addition to the six-year term of incarceration, Wagenius was ordered to pay $294,978 in restitution to the victims of his actions.

The case of Wagenius—who operated under the alias “Kiberphant0m”—represents a disturbing intersection of military insider threats and sophisticated cyber-extortion. Despite his rank and security clearance, Wagenius utilized his technical aptitude to target vulnerabilities in cloud infrastructure, ultimately threatening the privacy of millions and, according to federal prosecutors, attempting to leverage sensitive national security information for personal gain.

The Rise of Kiberphant0m: A Chronology of Cyber-Espionage

The digital trail of the Kiberphant0m persona began to materialize in 2024, while Wagenius was stationed at a U.S. Army installation in South Korea. Working in concert with a network of international co-conspirators, he capitalized on a series of security oversights at Snowflake, a prominent cloud data storage provider. At the time, several of Snowflake’s high-profile clients had failed to implement mandatory multi-factor authentication (MFA) on their accounts, leaving credentials exposed to brute-force attacks and credential stuffing.

By October 2024, the scope of the breach became clear. Wagenius publicly claimed on dark-web forums to have obtained the call and text metadata for tens of millions of AT&T customers. This metadata, which includes source and destination numbers, timestamps, and call durations, constitutes a significant privacy breach, allowing for the mapping of social networks and behavioral patterns of millions of individuals. Beyond AT&T, Kiberphant0m’s ambitions were global; he boasted of compromising more than a dozen telecommunications firms worldwide, including Verizon’s specialized Push-to-Talk infrastructure.

The investigation reached a turning point in late November 2024, when cybersecurity journalist Brian Krebs identified the likely perpetrator as a U.S. soldier stationed in South Korea. Following the report, federal authorities acted swiftly. In December 2024, Wagenius was apprehended, leading to two separate federal indictments. He entered guilty pleas to all counts, acknowledging his role in the breaches and the subsequent extortion attempts.

The Network of Co-Conspirators

Wagenius did not act in isolation. Federal prosecutors have highlighted a web of associates, most notably Kenneth Schuchman, a 28-year-old resident of Vancouver, Washington. Schuchman, who has a well-documented history of cybercriminal activity, previously gained notoriety for his 2019 conviction regarding the operation of the Satori botnet. The Satori botnet was a massive, automated network of compromised Internet-of-Things (IoT) devices used to launch distributed denial-of-service (DDoS) attacks against various targets.

Other key figures include Conor Riley Moucka, an Ontario resident known as “Judische,” who pleaded guilty in August 2026 for his involvement in the Snowflake-related thefts. Additionally, John Erin Binns, an American citizen currently residing in Turkey, remains a person of interest and is already wanted for his alleged role in the massive 2021 T-Mobile data breach that exposed the sensitive personal information of at least 76 million individuals.

National Security Implications and Extortion Tactics

The gravity of the situation was compounded by the nature of the data involved. Following the arrest of his accomplice Moucka, Wagenius engaged in a desperate and dangerous escalation. After AT&T had already paid a ransom of $370,000 in Bitcoin, Kiberphant0m reneged on the agreement. He publicly leaked what he alleged to be the call logs of high-ranking government officials, including then-President-elect Donald Trump and then-Vice President Kamala Harris.

Perhaps most alarmingly, Wagenius claimed to possess schematics stolen from the U.S. National Security Agency (NSA). This raised immediate concerns regarding the vulnerability of national security secrets to an individual with an active duty security clearance. Paul Russell, a resident agent in charge at the Defense Criminal Investigative Service (DCIS), underscored the severity of the situation.

“We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data,” Russell remarked. “That doesn’t happen every day. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with.”

Persistent Threats: The Prison Breach Attempt

Even after his arrest and while awaiting sentencing in federal custody, Wagenius displayed a persistent—and concerning—tendency to test security boundaries. A sentencing memo filed by federal prosecutors in September 2026 revealed that Wagenius had attempted to exploit the Bureau of Prisons (BOP) computer network.

While incarcerated, Wagenius allegedly utilized the email accounts of fellow inmates to solicit information from commercial AI tools. Under the guise of writing a book, he employed “prompt injection” techniques to bypass AI safety filters. His queries included requests for “real world working scripts” for privilege escalation vulnerabilities in Windows 10, instructions on exploiting a known command injection flaw in D-Link networking hardware (CVE-2023-45208), and even inquiries regarding how to fabricate an antenna within a prison environment to extend radio reception. He also conducted research into methods for escaping the facility.

The government maintains that there is no evidence Wagenius successfully deployed these vulnerabilities within the BOP systems. However, the attempts highlight a reflexive, compulsive drive to exploit systems that continued even after he was removed from the digital battlefield.

Analysis: A Failure of Digital Hygiene

The case of Cameron Wagenius is a case study in the consequences of inadequate cybersecurity hygiene at the enterprise level. The initial access gained by the Kiberphant0m collective was largely predicated on the lack of multi-factor authentication. While companies like Snowflake have since mandated MFA across all accounts, the damage was already done.

From an economic perspective, the operation was remarkably inefficient. Despite the catastrophic potential of the data stolen, prosecutors noted that Wagenius managed to net only approximately $1,500 from the sale of the information. This discrepancy between the massive scale of the harm caused and the minimal financial gain underscores the chaotic and often irrational nature of modern cyber-extortionists.

Conclusion and Broader Impact

The sentencing of Wagenius serves as a stark reminder of the evolving nature of the insider threat. When military personnel with access to sensitive systems engage in criminal behavior, the ripple effects touch national security, corporate integrity, and the personal privacy of millions of citizens.

For the telecommunications industry, the breach serves as a watershed moment, necessitating a transition toward more rigorous zero-trust architectures and mandatory authentication protocols. As for the legal implications, the 70-month sentence sends a clear signal that the U.S. Department of Justice and its partners—including the FBI, the Army Criminal Investigative Division, and the Secret Service—are prepared to treat cyber-extortion involving national security assets with the utmost gravity.

Wagenius’s transition from a soldier entrusted with secret-level clearances to a prisoner convicted of federal cyber-crimes highlights the critical need for continued vigilance in monitoring internal threats, particularly as AI tools lower the barrier to entry for exploiting complex digital infrastructure. The case is now closed, but the legislative and technological debates ignited by the Kiberphant0m affair are likely to persist for years to come.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Snapost
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.