A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata belonging to more than 100 million AT&T customers was sentenced to 70 months in federal prison and ordered to pay nearly $300,000 in restitution to victims.
Cameron John Wagenius, a 22-year-old soldier who was stationed at a U.S. Army base in South Korea at the time of the offenses, operated under the cybercriminal persona “Kiberphant0m.” Working alongside a network of alleged co-conspirators, Wagenius exploited compromised credentials to download sensitive data from several large enterprise customers utilizing the cloud data storage service Snowflake. Because these accounts failed to enforce multi-factor authentication, the threat actors gained unauthorized access. In the wake of these incidents, Snowflake has since mandated multi-factor authentication across all accounts to prevent similar breaches.
The scope of the operation became public in October 2024, when Wagenius took to cybercrime forums to boast about stealing call and text metadata—including source and destination numbers, timestamps, and call durations—for tens of millions of AT&T customers. Kiberphant0m claimed responsibility for breaching more than a dozen telecommunications companies worldwide, including Verizon’s Push-to-Talk business, and publicly extorted these corporate entities under the threat of publishing the proprietary and confidential data.
The trajectory of the investigation shifted significantly in late November 2024, when KrebsOnSecurity published findings indicating that the hacker operating as Kiberphant0m was likely a U.S. soldier stationed in South Korea. Less than a month after that reporting, Wagenius was apprehended and subsequently faced two separate federal indictments. He swiftly entered a guilty plea to all counts across both cases.
At his sentencing hearing in federal court in Seattle, Wagenius received a sentence of nearly six years behind bars, alongside an order to pay $294,978 in restitution.
Federal prosecutors noted that Wagenius did not operate in a vacuum, receiving assistance in his extortion campaigns from Kenneth Schuchman, a 28-year-old resident of Vancouver, Washington, with a substantial criminal cyber background. Schuchman previously pleaded guilty in 2019 to operating the Satori botnet, a vast network of compromised Internet-of-Things devices leveraged to launch large-scale distributed denial-of-service attacks.
Wagenius was linked to other prominent figures in the cybercrime underground as well. Two alleged co-conspirators faced or are still facing charges connected to the Snowflake-related data thefts. Conor Riley Moucka, also known as “Judische,” a resident of Kitchener, Ontario, was arrested in 2024 and entered a guilty plea in August 2026. Another co-conspirator, John Erin Binns, is an American citizen currently residing in Turkey who is also wanted by law enforcement for his alleged involvement in a massive 2021 data breach at T-Mobile that compromised the personal details of at least 76 million customers.
The gravity of the charges escalated further as investigators uncovered that Kiberphant0m engaged in re-extortion tactics, threatening to leak sensitive national security secrets. Immediately following Moucka’s arrest—and after AT&T had already paid the extortion syndicate a Bitcoin ransom totaling approximately $370,000—Kiberphant0m published files on hacker forums. He claimed these files included AT&T call logs belonging to then President-elect Donald Trump and then Vice President Kamala Harris, as well as classified schematics allegedly stolen from the U.S. National Security Agency.
Paul Russell, resident agent in charge at the Defense Criminal Investigative Service, the criminal investigative arm of the U.S. Department of Defense Office of Inspector General, detailed the unique multi-agency response triggered by the case. When DCIS received intelligence that an active-duty soldier holding a secret security clearance was allegedly developing hacking tools and trafficking stolen data, the agency launched a joint investigation alongside the FBI, the Army Criminal Investigative Division, and the U.S. Secret Service.
According to Russell, discovering an insider threat of this magnitude was an extraordinary occurrence that immediately mobilized federal partners due to the high stakes and uncertainty surrounding the extent of the compromise.
Despite his immediate guilty plea and subsequent cooperation with authorities, Wagenius managed to draw further scrutiny from federal prosecutors while incarcerated and awaiting sentencing. A sentencing memo filed by federal prosecutors in Seattle revealed that Wagenius violated the computer use policies of the Bureau of Prisons in an attempt to probe vulnerabilities within the prison system’s computer networks.
BOP records indicated that in September 2025, Wagenius used another inmate’s email access to instruct an external recipient to query a commercial artificial intelligence tool for information regarding privilege escalation and bypass vulnerabilities in Windows 10 Enterprise, explicitly asking for functional working scripts without omitted code. Shortly thereafter, using a different inmate’s email account, Wagenius sought step-by-step instructions and code for CVE-2023-45208, a command injection vulnerability affecting D-Link networking devices.
During the same period, Wagenius also attempted to research how to construct a makeshift antenna using prison commissary items to enhance radio reception, alongside inquiries regarding prison escape strategies. Prosecutors noted that Wagenius frequently framed these AI prompts within the context of a fictional book he claimed to be writing, a classic prompt injection technique designed to bypass safety filters built into commercial AI models to prevent the generation of exploitative code.
While the government found no evidence that Wagenius successfully deployed or utilized these requested vulnerabilities within BOP systems—with Wagenius claiming his research was merely intended to supply vulnerability data to the prison administration—the incident underscored his persistent engagement with technical exploits.
Despite the massive theoretical value of the data stolen from AT&T and other telecom providers, investigators revealed that Wagenius’s extortion schemes yielded remarkably little financial return. According to the government’s sentencing memo, Wagenius generated a grand total of approximately $1,500 from selling the stolen data.
Prosecutors emphasized that despite his lack of financial gain, the defendant’s actions generated widespread disruption. The sentencing memo concluded that while Wagenius was not particularly successful as a cybercriminal from a monetary standpoint, he intended to cause—and ultimately did cause—substantial harm to individual citizens, major U.S. corporations, and the United States government.
Leave a Reply