Cybersecurity

U.S. Army Soldier Sentenced to Prison for Massive Telecommunications Data Breach and Extortion Scheme

Cameron John Wagenius, a 22-year-old active-duty U.S. Army soldier, was sentenced today to 70 months in federal prison following his role in a sophisticated, wide-reaching cybercrime campaign that compromised the personal metadata of over 100 million AT&T customers. Beyond the prison term, Wagenius—who operated under the alias “Kiberphant0m”—has been ordered to pay nearly $300,000 in restitution to the victimized telecommunications entities. The sentencing marks the conclusion of a high-stakes federal investigation that bridged military intelligence, domestic law enforcement, and international cybercrime syndicates.

The Rise of Kiberphant0m: A Global Cyber Campaign

Wagenius, stationed at a U.S. Army base in South Korea during the height of his criminal activity, utilized his technical expertise to infiltrate several major global telecommunications companies. His modus operandi centered on exploiting weak security configurations within cloud storage platforms, specifically targeting customers of the data storage service Snowflake. Investigators revealed that the breaches were facilitated by the presence of exposed credentials and a systemic failure by organizations to enforce multi-factor authentication (MFA).

The scope of the operation was staggering. In October 2024, the Kiberphant0m persona began surfacing on dark-web forums, where he publicly claimed responsibility for accessing the call and text metadata of tens of millions of individuals. This metadata included sensitive communication patterns: source and destination phone numbers, exact timestamps, and the duration of calls. Wagenius’s targets extended beyond AT&T to include various international carriers and segments of Verizon’s infrastructure, such as its Push-to-Talk business.

A Chronology of Infiltration and Arrest

The investigation into Wagenius gained significant momentum in November 2024, when cybersecurity journalist Brian Krebs published findings suggesting that the individual behind the Kiberphant0m alias was likely a U.S. service member stationed in South Korea. This revelation acted as a catalyst for a multi-agency task force involving the FBI, the U.S. Secret Service, the Army Criminal Investigative Division (CID), and the Defense Criminal Investigative Service (DCIS).

  • October 2024: Wagenius begins publicizing the theft of AT&T call/text metadata on cybercrime forums.
  • November 2024: Investigative reporting links the Kiberphant0m persona to a U.S. soldier in South Korea.
  • December 2024: Following the public exposure, federal authorities arrest Wagenius. He is hit with two separate federal indictments.
  • August 2026: Co-conspirator Conor Riley Moucka pleads guilty to his role in the Snowflake-related data thefts.
  • September 2026: Federal prosecutors file a detailed sentencing memo, highlighting the defendant’s continued attempts to compromise Bureau of Prisons (BOP) systems.
  • Today: Wagenius receives his 70-month sentence in a Seattle federal court.

The Network of Co-conspirators

Wagenius did not act in isolation. Prosecutors highlighted the involvement of Kenneth Schuchman, a 28-year-old from Vancouver, Washington, who served as a key accomplice. Schuchman brought a notorious background to the partnership, having previously pleaded guilty in 2019 to operating the Satori botnet, which hijacked thousands of Internet-of-Things (IoT) devices to conduct massive distributed denial-of-service (DDoS) attacks.

The conspiracy also included other international actors. Conor Riley Moucka, a Canadian citizen known as “Judische,” was arrested and pleaded guilty in 2026. Furthermore, John Erin Binns, an American currently residing in Turkey, remains linked to the group. Binns is also a person of interest in the 2021 T-Mobile data breach, which exposed the records of approximately 76 million customers.

National Security Concerns and Escalation

The case transcended standard corporate extortion when Wagenius began threatening to disclose sensitive national security information. Following the arrest of his associate, Moucka, and despite AT&T having already complied with a $370,000 Bitcoin ransom demand, Wagenius escalated his tactics. He leaked what he alleged to be the call logs of high-ranking government officials, including then President-elect Donald Trump and Vice President Kamala Harris. Furthermore, he claimed to possess stolen schematics belonging to the U.S. National Security Agency (NSA), creating an immediate and volatile national security crisis.

Paul Russell, the resident agent in charge at the Defense Criminal Investigative Service (DCIS), described the case as unprecedented. “We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data,” Russell stated. “It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with.”

Persistent Threats: The Inmate Hacker

Perhaps the most alarming aspect of the case is the defendant’s behavior while incarcerated. The sentencing memo filed in September 2026 details how Wagenius attempted to exploit the Bureau of Prisons’ computer systems while awaiting his fate. He utilized other inmates’ email accounts to prompt commercial AI tools for information regarding Windows 10 privilege escalation, command injection vulnerabilities in D-Link hardware, and even methods to improve radio antenna reception in a prison environment.

Wagenius employed “prompt injection” techniques—a method of bypassing AI safety guardrails—by framing his queries as research for a book he claimed to be writing. When confronted, he argued he was merely identifying vulnerabilities to assist the BOP, a claim the government viewed with significant skepticism.

Broader Implications and Corporate Responsibility

The financial returns for Wagenius were remarkably low, totaling only about $1,500 in illicit gains despite the massive scale of the data he controlled. This disparity underscores the dangerous nature of modern cybercrime: the harm caused to millions of private citizens and the disruption to critical infrastructure vastly outweigh the direct profit realized by the perpetrators.

The case serves as a stark warning regarding the necessity of robust security protocols. The exploitation of Snowflake-hosted data was entirely preventable through the universal application of multi-factor authentication. As the industry grapples with the fallout, the sentencing of Wagenius stands as a reminder of the intersection between personal deviance, institutional vulnerability, and the long arm of federal law enforcement.

The failure to secure these systems has left a lasting impact on millions of consumers whose private metadata was traded on the black market. While AT&T and other firms have since bolstered their defenses, the legal and psychological toll of the breach remains. The U.S. military and the Department of Defense are now tasked with reviewing internal security clearances and digital training to ensure that the "insider threat" posed by individuals like Wagenius is mitigated in the future.

As the legal proceedings conclude, the case of Kiberphant0m will likely be studied by cybersecurity professionals for years to come—not because of the complexity of the code, but because of the vulnerability of the organizations that allowed a single, rogue soldier to hold the personal information of 100 million people hostage. The sentencing of Wagenius is a victory for the agencies involved, yet it serves as a sobering reminder of the fragile state of data security in an increasingly interconnected global landscape.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button