A U.S. Army soldier, Cameron John Wagenius, 22, has been sentenced to 70 months in federal prison and ordered to pay nearly $300,000 in restitution for his role in hacking into telecommunications companies, including AT&T and Verizon, and stealing call and text metadata for over 100 million customers. The soldier, stationed in South Korea, operated under the cybercriminal alias "Kiberphant0m" and collaborated with at least three other individuals. This case highlights a significant insider threat to national security and corporate data.
Wagenius’s criminal enterprise began when he, as Kiberphant0m, gained access to sensitive data from major telecommunications companies by exploiting vulnerabilities in the cloud data storage service Snowflake. At the time, Snowflake had exposed credentials and lacked mandatory multi-factor authentication, a loophole that Kiberphant0m and his co-conspirators exploited. In October 2024, Kiberphant0m boasted on cybercrime forums about his successful theft of call and text metadata from tens of millions of AT&T customers. He claimed to have infiltrated over a dozen telecommunications companies globally, including Verizon’s Push-to-Talk business, and publicly extorted these entities, threatening to release the stolen information if his demands were not met.
The investigation into Kiberphant0m’s activities gained significant traction when KrebsOnSecurity, in November 2025, published an article suggesting that the hacker was likely a U.S. soldier stationed in South Korea. This alert proved crucial, as less than a month later, Wagenius was apprehended. He was subsequently charged in two separate federal indictments and ultimately pleaded guilty to all counts. The sentencing hearing in Seattle saw Wagenius receive his nearly six-year prison sentence and the substantial restitution order of $294,978.
Federal prosecutors revealed that Wagenius did not act alone. He was assisted in his extortion schemes by Kenneth Schuchman, a 28-year-old from Vancouver, Washington, with a documented history in cybercrime. Schuchman had previously pleaded guilty in 2019 to operating the Satori botnet, a massive network of compromised Internet-of-Things devices used for large-scale distributed denial-of-service attacks. The involvement of individuals with prior cybercriminal records underscores the persistent threat posed by the intersection of military personnel and organized hacking groups.
Two other alleged co-conspirators remain entangled in legal proceedings related to the Snowflake data breaches. Conor Riley Moucka, also known as "Judische," from Kitchener, Ontario, was arrested in 2024 and subsequently pleaded guilty in August 2026. The fourth alleged accomplice is John Erin Binns, an American national residing in Turkey, who is also implicated in a massive 2021 data breach at T-Mobile that compromised the personal information of at least 76 million customers. This broader network of individuals highlights the international scope of these sophisticated cybercriminal operations.
The severity of Kiberphant0m’s actions escalated beyond mere data theft and extortion. He admitted to re-extorting victims and, more alarmingly, threatened to disclose national security secrets. Following the arrest of Conor Riley Moucka, and after AT&T had already paid the extortion group a $370,000 Bitcoin ransom, Kiberphant0m posted what he claimed to be the call logs of then President-elect Donald Trump and then Vice President Kamala Harris on hacker forums. Furthermore, he allegedly shared schematics purportedly stolen from the U.S. National Security Agency (NSA), amplifying the national security implications of his crimes.
The investigation into Wagenius was a complex, multi-agency effort. Paul Russell, a resident agent in charge at the Defense Criminal Investigative Service (DCIS), the investigative arm of the U.S. Department of Defense Office of Inspector General, played a key role. When DCIS received information about a soldier with secret clearance allegedly involved in cybercrime and extortion, the agency immediately initiated a joint investigation with the FBI, the Army Criminal Investigative Division (CID), and the U.S. Secret Service. Russell emphasized the rarity and seriousness of such a case, stating, "We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data. That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with." The classification level of Wagenius’s clearance added a significant layer of concern, indicating potential access to highly sensitive information.
Compounding the gravity of his offenses, a sentencing memo filed by federal prosecutors in Seattle on September 19 revealed that even while incarcerated and awaiting sentencing, Wagenius continued to engage in illicit computer-related activities. He violated the computer use policies of the Bureau of Prisons (BOP) in attempts to identify vulnerabilities within the BOP’s computer network. In September 2025, Wagenius used another inmate’s email system to solicit information about "CVEs for Windows 10 Enterprise privilege escalation and bypasses" and requested real-world working scripts for these vulnerabilities. Less than a week later, he used a different inmate’s email account to seek detailed instructions and potential code for CVE-2023-45208, a command injection vulnerability in D-Link networking devices. He also inquired about constructing an antenna to improve radio reception within a prison environment using readily available items and commissary supplies. Furthermore, Wagenius allegedly requested research into methods of escaping from prison.
The sentencing memo notes that Wagenius often framed these AI queries as research for a book he was writing, a tactic described as "prompt injection," designed to circumvent AI safety protocols. While the government is unaware of any evidence that Wagenius successfully exploited these vulnerabilities within the BOP’s systems, his continued attempts to probe security weaknesses while in custody demonstrate a persistent and concerning aptitude for cyber intrusion. When questioned, Wagenius claimed his research was solely to provide information to the BOP.
Despite the immense potential financial value of the data he stole from AT&T and other telecommunications providers, Wagenius’s direct extortion efforts were largely unsuccessful. The government’s sentencing memo indicates that he only managed to generate approximately $1,500 from selling the stolen data. This starkly contrasts with the potential harm caused. The memo concludes, "While Wagenius was not particularly financially successful as a cybercriminal, he both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government." His actions, though not financially lucrative for him, represented a significant threat to the privacy of millions of individuals, the operational integrity of major corporations, and potentially the national security of the United States. The case serves as a potent reminder of the evolving landscape of cyber threats and the critical need for robust cybersecurity measures, especially when insider threats are involved.

