Army Soldier Gets 70 Months for Turning Telecom Metadata Into Extortion Leverage

U.S. Army soldier Cameron Wagenius got 70 months for stealing AT&T Snowflake data on 100M+ customers and extorting victims for Bitcoin.

Army Soldier Gets 70 Months for Turning Telecom Metadata Into Extortion Leverage
Data Breaches

Illustrative image generated with AI

Listen to this articleAudio edition · 10 min

A federal sentence for the “Kiberphant0m” campaign

Cameron John Wagenius, a 22-year-old U.S. Army soldier known online as “Kiberphant0m,” was sentenced on September 26, 2026 to 70 months in federal prison. The court also ordered him to pay $294,978 in restitution.

Wagenius had pleaded guilty to every count contained in two federal indictments. The cases covered unauthorized access to telecommunications data, theft, attempted extortion, and renewed threats to expose sensitive information.

The scale of the stolen material was far greater than Wagenius’s direct proceeds. Prosecutors said he made only about $1,500 by selling data, even though the campaign affected major companies and exposed records associated with more than 100 million people.

At the time of the criminal activity, Wagenius was stationed at a U.S. Army base in South Korea. He also held a secret security clearance, turning an already substantial cybercrime prosecution into an insider-threat investigation involving an active-duty service member.

Exposed Snowflake credentials provided the initial access

Wagenius worked with three alleged co-conspirators to access accounts belonging to large customers of Snowflake, the cloud data storage service. The compromised accounts used exposed credentials and did not require multi-factor authentication.

That combination allowed valid usernames and passwords to become an entry point into data environments holding extensive corporate and customer records. The activity did not depend on a disclosed vulnerability in Snowflake’s platform.

Snowflake has since made MFA mandatory for all accounts. No further technical remediation specific to the telecom intrusions has been disclosed, nor have investigators released indicators such as IP addresses, account names, file hashes, or access tokens.

The case demonstrates why credential exposure cannot be treated as a password-reset issue alone. Organizations using cloud data platforms should review historical authentication and data-access records, rotate exposed credentials, invalidate active sessions where appropriate, and verify that MFA enrollment covers every account rather than only administrators.

AT&T metadata became both merchandise and leverage

In October 2024, Wagenius claimed on cybercrime forums that he possessed call and text metadata associated with tens of millions of AT&T customers. The wider stolen dataset from 2024 covered more than 100 million AT&T customers.

The information included originating and receiving telephone numbers, timestamps, and call durations. Although those fields are not the content of calls or text messages, they can reveal communication patterns, relationships, frequency of contact, and potentially sensitive associations.

Wagenius also claimed to have breached more than a dozen telecommunications companies worldwide, including Verizon’s Push-to-Talk business. The full scope of those assertions has not been publicly confirmed.

The group used threatened publication as an extortion mechanism. AT&T paid it a $370,000 Bitcoin ransom, but the payment did not end the exposure risk.

After alleged collaborator Conor Riley Moucka was arrested, Wagenius posted material that he claimed included AT&T call logs for then-President-elect Donald Trump and then-Vice President Kamala Harris. He also published schematics that he alleged had been stolen from the U.S. National Security Agency.

The authenticity and complete provenance of those specific materials have not been disclosed. Wagenius nevertheless admitted attempting to extort victims again and threatening to reveal national security secrets.

The alleged conspiracy connected several established cybercrime identities

A report published in late November 2025 identified Wagenius as likely being a U.S. soldier stationed in South Korea. Authorities arrested him less than a month later.

Federal prosecutors named three alleged collaborators:

  • Conor Riley Moucka, also known as “Judische,” is from Kitchener, Ontario. He was arrested in 2024 and pleaded guilty in August 2026 in connection with the Snowflake data thefts.
  • Kenneth Schuchman, 28, of Vancouver, Washington, allegedly assisted Wagenius’s extortion efforts. Schuchman had previously pleaded guilty in 2019 to operating the Satori botnet, a network of compromised Internet of Things devices used for distributed denial-of-service attacks.
  • John Erin Binns, an American living in Turkey, is wanted in connection with a 2021 T-Mobile breach that exposed personal information belonging to at least 76 million customers.

Two co-conspirators were still facing charges. Allegations against defendants who have not been convicted remain unproven unless established in court.

A secret clearance brought military investigators into the case

The Defense Criminal Investigative Service, the investigative arm of the U.S. Department of Defense Office of Inspector General, became involved after authorities learned that a soldier with a secret clearance was allegedly conducting cybercrime and extortion.

DCIS worked with the FBI, Army Criminal Investigation Division, and U.S. Secret Service. Paul Russell, a DCIS resident agent in charge, characterized the matter as an unusual and serious insider-threat investigation involving a soldier who was allegedly developing hacking tools and trafficking in stolen information.

The risk was not limited to whether Wagenius used classified access directly. A cleared service member participating in criminal forums, handling stolen data, and threatening disclosure of purported national security material creates opportunities for coercion, recruitment, and further unauthorized access.

Prosecutors said Wagenius intended to cause substantial harm and succeeded in harming individuals, American companies, and the U.S. government. His prompt guilty plea and substantial cooperation were also presented to the court before sentencing.

Jailhouse requests sought exploit code through an AI system

Wagenius’s computer-related conduct continued while he was incarcerated and awaiting sentencing, according to a federal memorandum filed by Seattle prosecutors on Sept. 19.

Bureau of Prisons records indicated that, in or around September 2025, he used another inmate’s email account to ask an outside person to query a commercial AI system. The requested material included Windows 10 Enterprise privilege-escalation and bypass vulnerabilities, along with complete working scripts. The specific Windows CVEs were not disclosed.

Less than a week later, Wagenius allegedly used a different inmate’s account to request technical steps and code for CVE-2023-45208, including a request to create code if none could be found.

CVE-2023-45208 is identified as a command-injection vulnerability affecting D-Link networking devices. It carries a CVSS score of 8.8 and the vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That rating describes an adjacent-network attack requiring low complexity, no privileges, and no user interaction, with potentially high impact on confidentiality, integrity, and availability. The affected D-Link models and versions were not disclosed here.

Prosecutors described the requests as prompt injection: deceptive instructions intended to make an AI service produce exploit content that its safeguards would normally withhold. Wagenius sometimes framed the activity as research for a book.

He also requested instructions for constructing an antenna from items available in prison to extend radio reception, as well as research about escaping custody. Prosecutors reported no evidence that he developed a working method to exploit or deploy the vulnerabilities he investigated. Wagenius maintained that he intended to provide vulnerability information to the Bureau of Prisons, but authorities said he violated prison computer-use rules.

The immediate defensive lesson is credential control

No evidence has been disclosed that the Snowflake compromises relied on a zero-day vulnerability. The documented weakness was more basic: exposed credentials protecting accounts without MFA.

Snowflake’s mandatory MFA policy directly addresses that access path. Organizations holding high-value datasets should still examine whether previously exposed credentials were reused elsewhere, whether unauthorized exports occurred before MFA enforcement, and whether former sessions or tokens remain valid.

For affected telecom customers, no individual remediation can remove metadata already stolen. The principal risks are continued publication, correlation with other breached datasets, and targeting based on communication relationships.

No additional compromise indicators or telecom-specific fixes have been released. That leaves defenders with identity controls, account auditing, credential rotation, and careful monitoring of sensitive data access as the most concrete available measures.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Related topicsAT&T data breachSnowflake hackKiberphant0mtelecom extortionVerizon breachCameron Wageniuscybersecurity
Back to home