U.S. Army Soldier Sentenced to Prison for Massive Telecommunications Data Breach and Extortion Scheme

Cameron John Wagenius, a 22-year-old U.S. Army soldier, was sentenced today to 70 months in federal prison following a high-profile cybercrime spree that compromised the metadata of over 100 million AT&T customers. Operating under the alias Kiberphant0m while stationed at a military installation in South Korea, Wagenius orchestrated a series of data thefts that sent shockwaves through the telecommunications industry and drew the immediate attention of the Department of Defense and federal law enforcement agencies. In addition to his prison term, a federal judge in Seattle ordered Wagenius to pay $294,978 in restitution to his victims.
The sentencing concludes a complex criminal investigation involving the Federal Bureau of Investigation (FBI), the U.S. Secret Service, and the Defense Criminal Investigative Service (DCIS). Wagenius pleaded guilty to multiple counts related to his role in exploiting vulnerabilities within the Snowflake cloud storage platform, a campaign that targeted several large corporations and resulted in the unauthorized acquisition of sensitive customer metadata.
The Rise of Kiberphant0m: A Chronology of Malicious Activity
The trajectory of the Kiberphant0m persona began with the exploitation of exposed credentials and a lack of multi-factor authentication (MFA) on various Snowflake accounts. Throughout 2024, Wagenius and a network of collaborators targeted these accounts to exfiltrate vast troves of data.
- Early 2024: Wagenius begins his systematic exploitation of Snowflake customer accounts, leveraging poor security hygiene at target firms.
- October 2024: Kiberphant0m publicly claims responsibility on underground cybercrime forums for the theft of call and text metadata from tens of millions of AT&T customers.
- November 2025: KrebsOnSecurity publishes investigative findings suggesting that the actor behind the Kiberphant0m alias is an active-duty U.S. soldier based in South Korea.
- December 2025: Following the exposure of his activities, Wagenius is apprehended and formally charged in two separate federal indictments.
- August 2026: Conor Riley Moucka, an associate of Wagenius, enters a guilty plea in a Canadian court, marking a significant development in the international investigation.
- September 2026: Federal prosecutors file a comprehensive sentencing memorandum outlining the scope of the harm caused by the defendant.
- Present Day: Wagenius is sentenced to nearly six years in federal prison.
The Mechanics of the Breach and Extortion
The breach primarily involved the harvesting of "metadata"—the digital breadcrumbs generated by telecommunications networks. This data included source and destination telephone numbers, timestamps of calls and texts, and the duration of communications. While the content of the messages remained encrypted, the metadata itself is considered highly sensitive, as it allows for the construction of detailed social and professional maps of the individuals involved.
Wagenius did not act alone. His network included Kenneth Schuchman, a 28-year-old Washington resident with a well-documented history of cybercriminal activity. Schuchman, who previously pleaded guilty in 2019 for his role in operating the Satori IoT botnet, served as a key accomplice in the extortion efforts. Other figures involved in the broader Snowflake-related investigations include John Erin Binns, an American currently residing in Turkey, who has been linked to the massive 2021 T-Mobile data breach.
The audacity of the extortion scheme reached a peak when, following the arrest of co-conspirator Conor Riley Moucka, Wagenius attempted to exert further pressure. Despite an initial $370,000 Bitcoin payment made by AT&T to the extortion group, Wagenius reneged on his promise to delete the data. He subsequently leaked alleged call logs belonging to then President-elect Donald Trump and then Vice President Kamala Harris on hacker forums, alongside documents he claimed were stolen from the National Security Agency (NSA).
Institutional Response: The Insider Threat Challenge
The involvement of an active-duty soldier with secret-level security clearance presented an unprecedented challenge for the U.S. government. Paul Russell, the resident agent in charge at the DCIS, highlighted the unique danger posed by this case.
"We don’t often get leads where there’s an active-duty soldier with a secret clearance who’s creating hacking tools and trafficking in data," Russell stated. "That doesn’t happen every day. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with."
The investigation was characterized by an immediate and coordinated response across multiple federal agencies, underscoring the shift in how the military and the intelligence community view the intersection of traditional service and digital subversion.
Persistent Malicious Intentions While Incarcerated
A particularly concerning aspect of the sentencing memorandum reveals that Wagenius’s criminal intent did not cease upon his arrest. While detained by the Bureau of Prisons (BOP) awaiting his sentence, Wagenius was caught attempting to gain unauthorized access to the prison’s internal computer systems.
Records indicate that in September 2025, Wagenius used other inmates’ email accounts to solicit information from commercial AI platforms. He utilized a technique known as "prompt injection"—framing his requests as research for a book—to bypass the safety filters of these AI tools. He sought specific information regarding "privilege escalation" for Windows 10, instructions on how to exploit the CVE-2023-45208 vulnerability in D-Link hardware, and even instructions on how to manufacture a radio antenna using commissary items to improve reception within the facility. He further requested information on potential methods for escaping custody.
The government acknowledged that there was no evidence Wagenius successfully deployed these vulnerabilities within the BOP network, but the attempt demonstrated a persistent and high-level technical focus that worried federal prosecutors.
Broader Implications for Cybersecurity
The "Kiberphant0m" case serves as a stark case study in the risks of credential mismanagement and the necessity of mandatory multi-factor authentication. While the financial windfall for Wagenius was meager—prosecutors estimate he made only $1,500 from the venture—the damage to his victims and the reputation of the institutions involved was immense.
The breach of the Snowflake platform highlighted the vulnerability of third-party cloud service providers when security protocols are not strictly enforced. In response to these events, Snowflake has since mandated the use of MFA for all accounts, a move that security experts suggest is the baseline for modern enterprise data protection.
Furthermore, the case illustrates the geopolitical ramifications of modern cybercrime. The leakage of high-level political metadata and alleged NSA schematics underscores the danger of professional-grade cyber-extortionists who operate without borders. The fact that the extortion group targeted sensitive government data transformed the investigation from a private corporate matter into a national security priority.
Final Assessment
The 70-month sentence handed down to Wagenius reflects the gravity with which the court views insider threats, particularly those involving personnel with high-level clearances. While Wagenius was cooperative during the legal proceedings, his continued attempts to probe computer vulnerabilities while in federal custody suggest a deep-seated predisposition toward cyber-exploitation that remains a point of concern for correctional authorities.
This case will likely remain a landmark in federal cybersecurity litigation, serving as a reminder that even the most technically sophisticated individuals can be undone by the digital trail they leave behind. The focus now shifts to the remaining co-conspirators still facing charges, as the federal government continues to unwind the complex network that facilitated one of the most significant telecommunications breaches in recent history.







