A United States Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata belonging to more than 100 million AT&T customers was sentenced in federal court today to 70 months in prison. In addition to the nearly six-year federal prison term, the former soldier was ordered to pay close to $300,000 in restitution to his victims, bringing a significant legal conclusion to a high-profile case that blended military insider threats with international cyber extortion.
Cameron John Wagenius, a 22-year-old soldier who was stationed at a U.S. Army base in South Korea during the height of his illicit activities, operated within the cybercriminal underworld under the handle "Kiberphant0m." Working alongside a network of alleged co-conspirators, Wagenius targeted several large corporate clients utilizing the cloud data storage service Snowflake. These companies had inadvertently exposed credentials and failed to enforce multi-factor authentication, a critical security oversight that Snowflake has since addressed by mandating multi-factor authentication across all accounts.
The scope of the breach came to light in October 2024 when Kiberphant0m began bragging on various cybercrime forums that he had successfully exfiltrated call and text metadata—including source and destination numbers, timestamps, and call durations—for tens of millions of AT&T customers. Beyond AT&T, Kiberphant0m claimed responsibility for breaching more than a dozen telecommunications companies worldwide, including Verizon’s Push-to-Talk business. He and his associates publicly extorted these corporate entities, leveraging the threat of publishing sensitive metadata in exchange for ransom demands.
The trail leading to Wagenius began to solidify in late November 2024, when security researcher Brian Krebs published warnings indicating that the notorious persona Kiberphant0m was likely a U.S. soldier stationed in South Korea. Less than a month after those reports surfaced, Wagenius was arrested and subsequently faced two separate federal indictments. He moved quickly through the judicial process, pleading guilty to all counts across both cases. During his sentencing hearing in Seattle, federal judges handed down the nearly six-year sentence and finalized the restitution order of $294,978.
Federal prosecutors outlined a network of alleged co-conspirators who assisted Wagenius in his extortion schemes, noting the involvement of 28-year-old Kenneth Schuchman of Vancouver, Washington. Schuchman possesses a documented history in cybercrime, having pleaded guilty in 2019 to operating the Satori botnet, a vast and destructive collection of compromised Internet-of-Things devices utilized for large-scale distributed denial-of-service attacks.
Other key figures linked to the Snowflake data thefts continue to face legal scrutiny. Conor Riley Moucka, also known as "Judische," a resident of Kitchener, Ontario, was arrested in 2024 and entered a guilty plea in August 2026. Another co-conspirator, John Erin Binns, an American citizen currently residing in Turkey, remains wanted by authorities not only for his alleged role in these recent extortions but also for a massive 2021 data breach at T-Mobile that exposed the personal information of at least 76 million customers.
Investigators revealed that Kiberphant0m’s operations extended beyond corporate extortion into the realm of re-extortion and national security threats. Following Moucka’s arrest—and even after AT&T had already paid the extortion syndicate a $370,000 Bitcoin ransom—Kiberphant0m escalated his tactics. He posted what he claimed were the AT&T call logs of then President-elect Donald Trump and then Vice President Kamala Harris on hacker forums, alongside technical schematics allegedly stolen from the U.S. National Security Agency.
The involvement of an active-duty soldier with a secret security clearance triggered an immediate, multi-agency federal response. Paul Russell, a resident agent in charge at the Defense Criminal Investigative Service, the criminal investigative arm of the U.S. Department of Defense Office of Inspector General, explained the gravity of the situation. Russell worked the investigation alongside the Federal Bureau of Investigation, the Army Criminal Investigative Division, and the U.S. Secret Service.
"We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data," Russell remarked, emphasizing the unique and alarming nature of the breach. "That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with."
Complications surrounding Wagenius did not end with his guilty plea or his initial detention. A sentencing memo filed by federal prosecutors in Seattle detailed that while awaiting sentencing, Wagenius was caught attempting to probe the computer networks of the Bureau of Prisons for security vulnerabilities. Government records indicate that in September 2025, Wagenius used another inmate’s email system to prompt commercial artificial intelligence tools to reveal privilege escalation vulnerabilities and bypasses for Windows 10 Enterprise, requesting detailed CVE information and working scripts without omitted code.
Days later, Wagenius allegedly exploited another inmate’s email account to solicit step-by-step instructions and code for CVE-2023-45208, a command injection vulnerability affecting D-Link networking devices. Around the same time, he reportedly sought guidance on constructing improvised antennas within a prison environment using commissary items to extend radio reception, alongside inquiries concerning prison escape strategies.
Prosecutors noted that Wagenius frequently framed his queries to artificial intelligence tools as research for a book he claimed to be writing. This technique mirrors prompt injection methods, where malicious actors supply deceptive inputs to bypass safety guardrails programmed into commercial AI models to prevent the generation of exploitable computer code. While the government found no evidence that Wagenius successfully deployed these vulnerabilities within Bureau of Prisons systems, his actions demonstrated a persistent, unyielding drive toward cyber exploitation even while incarcerated.
Despite the monumental scale of the corporate databases he compromised, federal prosecutors revealed that Wagenius’s cybercriminal enterprise was remarkably unprofitable. Investigators estimated that across all his extortion attempts and data trafficking, Wagenius earned a meager total of around $1,500.
"While Wagenius was not particularly financially successful as a cybercriminal, he both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government," the federal sentencing memo concluded.
Leave a Reply