Cybersecurity

U.S. Army Soldier Sentenced to Nearly Six Years in Federal Prison for Massive Telecommunications Hacks and Extortion Schemes

Cameron John Wagenius, a 22-year-old active-duty U.S. Army soldier stationed in South Korea, has been sentenced to 70 months in federal prison following his guilty plea for orchestrating sweeping cyberattacks against major telecommunications companies. Operating under the online persona “Kiberphant0m,” Wagenius breached cloud-storage provider Snowflake to steal sensitive metadata belonging to over 100 million AT&T customers. Alongside a prison term handed down during a hearing in Seattle, the federal court ordered him to pay nearly $300,000 in restitution to victims.

The case underscores a complex intersection of insider threats, international cybercrime syndicates, vulnerabilities in third-party cloud configurations, and the aggressive exploitation of artificial intelligence. Federal prosecutors, working alongside an inter-agency task force, highlighted the unprecedented nature of an active-duty military member utilizing a secret security clearance to develop hacking tools, exfiltrate private data, and publicly extort high-profile corporate and government entities. Despite the staggering scale of the data breaches—which impacted dozens of global telecom operators and exposed the call logs of high-ranking political figures—investigators revealed that Wagenius earned a meager $1,500 in direct profits from his illicit enterprise.

Anatomy of the Breaches: The Snowflake Vulnerabilities and AT&T Exfiltration

The foundational breach that catalyzed the massive wave of extortions traced back to widespread security oversights within Snowflake, a widely utilized cloud data storage service. Investigators established that Wagenius and his co-conspirators targeted large corporate accounts that had left credentials exposed and failed to enforce multi-factor authentication (MFA). By exploiting these lapses, the threat actors accessed voluminous databases belonging to multiple corporations. Snowflake has since responded to the incident by mandating MFA across all customer accounts.

By October 2024, Wagenius leveraged his access to harvest massive quantities of mobile call and text metadata. This included vital telecommunications records such as source and destination numbers, timestamps, and call durations for tens of millions of AT&T customers. Operating as Kiberphant0m, the soldier expanded his scope beyond AT&T, claiming responsibility for breaching more than a dozen telecommunications firms worldwide, including Verizon’s Push-to-Talk business. Rather than quietly monetizing the data on underground forums, the cybercriminal ring adopted an aggressive public extortion strategy, threatening to publish confidential corporate information unless ransom demands were met.

The extortion attempts reached a volatile peak following the arrest of a co-conspirator. Even after AT&T reportedly paid the extortion group a $370,000 Bitcoin ransom, Kiberphant0m engaged in secondary extortion tactics. In a direct challenge to authorities, he posted what he claimed were AT&T call logs for then-President-elect Donald Trump and then-Vice President Kamala Harris on hacker forums. Furthermore, he threatened to leak classified or sensitive schematics allegedly stolen from the U.S. National Security Agency (NSA).

A Global Network of Co-Conspirators

Federal indictments unsealed in the wake of the investigation revealed that Wagenius did not act alone. Prosecutors identified several key figures operating alongside the young soldier within the international cybercrime underground:

  • Kenneth Schuchman: A 28-year-old resident of Vancouver, Washington, with a notorious background in digital crime. Schuchman previously pleaded guilty in 2019 to operating the Satori botnet—a massive collection of compromised Internet-of-Things (IoT) devices deployed for large-scale distributed denial-of-service (DDoS) attacks. Prosecutors stated Schuchman assisted Wagenius in executing extortion schemes against victim corporations.
  • Conor Riley Moucka (a.k.a. “Judische”): A resident of Kitchener, Ontario, arrested in 2024 for his role in the Snowflake data thefts. Moucka formally pleaded guilty to related charges in August 2026.
  • John Erin Binns: An American national currently residing in Turkey, who remains wanted by U.S. authorities. Binns is also linked to the high-profile 2021 data breach at T-Mobile that exposed the personal information of at least 76 million customers.
See also  The Future of AI Wearables at a Crossroads Privacy Concerns and Functional Challenges Threaten to Derail the Smart Glasses Revolution

The collaborative nature of these cybercriminal enterprises highlights how disparate threat actors coalesce around shared credential vulnerabilities, pooling resources to maximize leverage against major corporate targets.

Chronology of an Investigation: From Anonymous Forum Bragging to Federal Arrest

The swift identification and apprehension of Cameron Wagenius represent a major success for a multi-agency federal task force, though it began with investigative journalism.

  • October 2024: Operating under the handle Kiberphant0m, Wagenius openly brags on underground cybercrime forums about stealing the call and text metadata of tens of millions of AT&T customers and extorting international telecommunications providers.
  • Late November 2025: Cybersecurity publication KrebsOnSecurity publishes an investigative report warning that the cybercriminal operating as Kiberphant0m is likely a U.S. soldier stationed at a military base in South Korea.
  • December 2025: Law enforcement acts on the intelligence. Wagenius is arrested and subsequently hit with two separate federal indictments in U.S. courts, where he promptly pleads guilty to all counts.
  • September 2026: Federal prosecutors file a comprehensive sentencing memorandum detailing not only the telecom hacks and extortion schemes, but also Wagenius’s subsequent attempts to probe Bureau of Prisons computer systems using generative AI while awaiting sentencing.
  • Sentencing Hearing: The federal court in Seattle sentences Wagenius to 70 months in prison and orders him to pay $294,978 in restitution to victims.

Inter-Agency Collaboration and the Insider Threat

The involvement of an active-duty service member with a secret security clearance alarmed federal defense and intelligence agencies. Paul Russell, a resident agent in charge at the Defense Criminal Investigative Service (DCIS)—the criminal investigative arm of the U.S. Department of Defense Office of Inspector General—emphasized the unusual and high-stakes nature of the case.

When DCIS received intelligence indicating that an active-duty soldier with elevated security clearances was actively manufacturing hacking tools and trafficking stolen data, a joint task force was immediately mobilized. The investigation brought together the Federal Bureau of Investigation (FBI), the Army Criminal Investigative Division (CID), and the U.S. Secret Service.

"We don’t often get leads where there’s an active-duty soldier with a secret clearance who’s creating hacking tools and trafficking in data," Russell remarked. "That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with."

See also  Unearthing Harvest: How IBM and the NSA Built a Cold War Supercomputer Ahead of Its Time

Incarceration Misconduct: AI Prompt Injection and Prison Evasion Research

Even while locked behind bars awaiting trial and sentencing, Wagenius continued attempting to probe digital defenses, turning his focus toward the institutions holding him. According to a sentencing memorandum filed by federal prosecutors in September 2026, Wagenius exploited the computer use policies of the Bureau of Prisons (BOP) by proxy, leveraging other inmates’ email accounts to query commercial artificial intelligence tools for system vulnerabilities.

Prosecutors revealed that in September 2025, Wagenius used an inmate’s email access to prompt an AI system regarding privilege escalation vulnerabilities in Windows 10 Enterprise, explicitly asking for "the CVE’s and a real world working script for each CVE… without omitted code." Within a week, he directed another AI inquiry toward CVE-2023-45208—a command injection vulnerability found in D-Link networking devices—demanding step-by-step implementation details and exploit code.

To bypass the safety guardrails programmed into commercial AI platforms to prevent the generation of malicious code, Wagenius utilized a technique known as "prompt injection." He framed his queries within the context of researching material for a book he claimed to be writing. Beyond software vulnerabilities, prison records indicate that Wagenius also used AI proxies to research how to construct improvised radio antennas using commissary items and, notably, how to escape from a correctional facility.

The Department of Justice noted that while the government found no evidence that Wagenius successfully deployed these researched vulnerabilities against BOP computer systems, the behavior demonstrated an ongoing, compulsive drive to exploit digital and physical security controls. When questioned by authorities, Wagenius maintained that he was merely researching potential vulnerabilities to report them to prison administrators.

Economic Reality and Broader Implications for Cybersecurity

Despite the massive disruption caused by the exfiltration of sensitive metadata and the intense public pressure exerted through extortion demands, the financial return for Wagenius was remarkably low. Government filings indicate that despite stealing data valued in the millions on the black market, Wagenius netted approximately $1,500 in direct profit from selling stolen information.

"While Wagenius was not particularly financially successful as a cybercriminal, he both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government," the sentencing memo concluded.

The case serves as a stark reminder of the evolving threat landscape confronting both corporate enterprises and national security apparatuses. It highlights the critical vulnerabilities introduced by third-party cloud vendors who fail to enforce baseline security protocols like multi-factor authentication, while simultaneously spotlighting the growing challenge of insider threats within military ranks. As generative artificial intelligence becomes more accessible, the ability of incarcerated or isolated threat actors to leverage automated systems for exploit research remains a pressing concern for modern correctional and national security frameworks.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Tech Newst
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.