U.S. Army Soldier Sentenced to Prison for Massive Telecommunications Data Breach and Extortion Scheme

Cameron John Wagenius, a 22-year-old U.S. Army soldier, was sentenced today to 70 months in federal prison for orchestrating a sophisticated international cybercrime campaign that compromised the sensitive metadata of over 100 million AT&T customers. Following a sentencing hearing in Seattle, the court also ordered Wagenius, who operated under the alias "Kiberphant0m," to pay nearly $300,000 in restitution to his victims. The sentencing concludes a high-profile investigation involving the Department of Defense, the FBI, and the Secret Service, highlighting the severe national security risks posed by insiders with specialized technical skills and high-level security clearances.
The Rise of Kiberphant0m: A Chronology of Malfeasance
The criminal career of Cameron Wagenius began while he was stationed at a U.S. Army base in South Korea. Utilizing his position to mask his activities, Wagenius adopted the digital persona Kiberphant0m, a name that would soon become synonymous with high-stakes extortion on underground cybercrime forums.
In late 2024, the scope of Wagenius’s activities became apparent when he boasted on public forums about infiltrating the cloud-based data storage infrastructure of Snowflake. By exploiting exposed credentials and bypassing systems that lacked mandatory multi-factor authentication (MFA), Wagenius and his co-conspirators gained unauthorized access to the records of major telecommunications providers.
The timeline of the breach and subsequent fallout is as follows:
- Late 2024: Wagenius begins leaking metadata—including source and destination numbers, timestamps, and call durations—for tens of millions of AT&T customers. He eventually claims responsibility for breaching over a dozen global telecommunications firms.
- November 2025: Cybersecurity researchers at KrebsOnSecurity identify a correlation between the Kiberphant0m persona and a U.S. soldier stationed in South Korea.
- December 2025: Following a joint investigation by federal agencies, Wagenius is apprehended and charged under two separate federal indictments.
- 2026: Wagenius enters a guilty plea to all charges. Simultaneously, his co-conspirator, Conor Riley Moucka, pleads guilty in August 2026 regarding his role in the Snowflake-related thefts.
- September 2026: Federal prosecutors file a comprehensive sentencing memorandum outlining the defendant’s post-arrest conduct while in custody.
- Present Day: Wagenius receives his final sentence of nearly six years in federal prison.
The Mechanics of the Breach
The breach was not merely a result of technical prowess but also of institutional oversight. The attackers targeted Snowflake customers who had failed to implement robust security hygiene, specifically the absence of MFA. This vulnerability allowed the group to harvest massive datasets.
The information stolen—while not containing the content of private conversations—provided a map of human connectivity, including call logs and text metadata. The sensitivity of this data lies in its ability to reveal patterns of life, business relationships, and social circles of millions of individuals, including high-profile political figures.
Accomplices and the Cybercriminal Ecosystem
Wagenius did not operate in a vacuum. The investigation revealed a network of collaborators, most notably Kenneth Schuchman, a 28-year-old from Vancouver, Washington. Schuchman, a known entity to law enforcement, had previously garnered notoriety for his 2019 guilty plea regarding the operation of the Satori botnet, which leveraged compromised Internet-of-Things (IoT) devices to execute devastating distributed denial-of-service (DDoS) attacks.
Furthermore, the involvement of John Erin Binns, an American national residing in Turkey, adds an international dimension to the case. Binns remains a person of interest in multiple jurisdictions, specifically regarding his alleged role in the 2021 T-Mobile data breach that affected 76 million people. The collaboration between these actors underscores the evolving nature of digital organized crime, where individuals with disparate skill sets—from botnet management to credential harvesting—align to maximize financial returns.
National Security and the Insider Threat
The involvement of an active-duty soldier with secret clearance sent shockwaves through the Department of Defense. Paul Russell, a resident agent in charge at the Defense Criminal Investigative Service (DCIS), remarked on the unprecedented nature of the threat. "We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data," Russell stated.
The severity of the case escalated significantly when, following the arrest of co-conspirator Conor Moucka, Kiberphant0m attempted to retaliate against the government and his corporate victims. He released what he purported to be AT&T call logs belonging to then President-elect Donald Trump and Vice President Kamala Harris. Additionally, he threatened to leak schematics allegedly stolen from the U.S. National Security Agency (NSA). This pivot from financial extortion to the weaponization of national security secrets transformed the investigation from a criminal matter into an urgent counterintelligence priority.
In-Custody Conduct: The "Prompt Injection" Attempt
Perhaps the most startling aspect of the case was the defendant’s behavior while awaiting sentencing. Despite being incarcerated in a federal facility, Wagenius continued his attempts to subvert computer security. Federal prosecutors documented how he used the email accounts of other inmates to manipulate commercial artificial intelligence (AI) tools.
Using a technique known as "prompt injection," Wagenius framed his requests as research for a book. He queried AI systems for information on Windows 10 privilege escalation vulnerabilities, specific CVEs (Common Vulnerabilities and Exposures) related to D-Link networking hardware, and even instructions for constructing improvised antennas to extend radio reception within the prison.
While the government acknowledged there was no evidence that Wagenius successfully deployed these vulnerabilities against Bureau of Prisons (BOP) infrastructure, the attempt illustrates a persistent, compulsive inclination toward system exploitation that persisted even after his initial apprehension.
Broader Implications for Corporate and Government Security
The case of Cameron Wagenius serves as a sobering case study for modern cybersecurity. Despite the immense potential value of the data he controlled, the extortion efforts were largely ineffective, yielding only an estimated $1,500 in illicit profit. This disparity between the massive potential for harm and the relatively meager financial gain highlights a shift in the threat landscape: attackers are often motivated by the notoriety of the "hack" as much as, or more than, the monetary reward.
For corporations, the incident reinforces the absolute necessity of enforcing multi-factor authentication across all cloud and third-party storage environments. For the military and government agencies, the case exposes critical gaps in the vetting and monitoring of personnel with access to sensitive digital infrastructure.
The fact that an individual with a secret clearance could operate an extortion ring from a military installation for an extended period has forced the Department of Defense to re-evaluate how it monitors the digital activity of service members. The sentencing of Wagenius may provide a measure of justice, but the systemic vulnerabilities he exploited remain a focal point for organizations worldwide. As AI tools become more integrated into daily life, the "prompt injection" techniques documented in the government’s sentencing memo will likely become a new frontier in security training, as organizations struggle to prevent malicious actors from using these tools to bridge the gap between intent and action.
Ultimately, the 70-month sentence is intended to act as both a punishment and a deterrent, signaling that while the digital world may offer a veneer of anonymity, the physical consequences for those who threaten the integrity of both corporate data and national security remain absolute.







