A U.S. Army soldier, Cameron John Wagenius, 22, was sentenced to 70 months in federal prison and ordered to pay nearly $300,000 in restitution for hacking into telecommunications companies and stealing mobile call and text metadata for over 100 million AT&T customers in 2024, as reported by Krebs on Security. While stationed in South Korea, Wagenius operated under the cybercriminal alias "Kiberphant0m" and collaborated with three alleged co-conspirators. Their illicit activities involved exploiting vulnerabilities in the cloud data storage service Snowflake, which at the time had exposed credentials and lacked mandatory multi-factor authentication (MFA). Snowflake has since implemented MFA for all accounts.

In October 2024, Kiberphant0m boasted on cybercrime forums about obtaining the call and text metadata—including source and destination numbers, timestamps, and durations—for tens of millions of AT&T customers. He claimed to have infiltrated over a dozen telecommunications companies globally, including Verizon’s Push-to-Talk business, and publicly extorted these entities, threatening to release the stolen data if his demands were not met.

KrebsOnSecurity had previously flagged in November 2025 that Kiberphant0m was likely a U.S. soldier stationed in South Korea. Less than a month later, Wagenius was apprehended and charged in two separate federal indictments. He subsequently pleaded guilty to all counts in both cases. The sentencing hearing in Seattle resulted in Wagenius receiving a sentence of nearly six years in federal prison and an order to pay $294,978 in restitution.

Federal prosecutors revealed that Wagenius was aided in his extortion efforts by Kenneth Schuchman, a 28-year-old from Vancouver, Washington, who has a significant history in cybercrime. Schuchman had previously pleaded guilty in 2019 to operating the Satori botnet, a massive network of compromised Internet of Things (IoT) devices used for large-scale distributed denial-of-service (DDoS) attacks.

Two other alleged associates of Wagenius are still facing charges related to the Snowflake data thefts. Conor Riley Moucka, also known as "Judische," from Kitchener, Ontario, was arrested in 2024 and pleaded guilty in August 2026. John Erin Binns, an American residing in Turkey, is also wanted in connection with a 2021 data breach at T-Mobile that exposed the personal information of at least 76 million customers.

Kiberphant0m also admitted to re-extorting victims and making threats to disclose national security secrets. Following the arrest of Moucka, and after AT&T had already paid the extortion group a $370,000 Bitcoin ransom, Kiberphant0m posted on hacker forums what he claimed to be call logs for then-President-elect Donald Trump and then-Vice President Kamala Harris. He also allegedly shared schematics pilfered from the U.S. National Security Agency (NSA).

Paul Russell, a resident agent in charge at the Defense Criminal Investigative Service (DCIS), the investigative arm of the U.S. Department of Defense Office of Inspector General, stated that the DCIS initiated the investigation upon receiving information about a soldier with secret clearance allegedly involved in cybercrime and extortion. The investigation was a collaborative effort involving the FBI, the Army Criminal Investigative Division (CID), and the U.S. Secret Service.

"We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data," Russell commented. "That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with."

A sentencing memo filed on September 19 by federal prosecutors in Seattle highlighted that despite Wagenius’s early guilty plea and cooperation, he was recently caught attempting to probe for security vulnerabilities within the Bureau of Prisons’ (BOP) computer network. The government’s memo detailed that while incarcerated and awaiting sentencing, Wagenius violated BOP computer use policies in his efforts to understand vulnerabilities in BOP computer systems.

According to BOP records, around September 2025, Wagenius utilized another inmate’s email system to request that the recipient prompt a commercial AI tool for information regarding "what CVE’s are there for Windows 10 Enterprise privilege escalation and bypasses" and to "Provide the CVE’s and a real world working script for each CVE . . . without omitted code." The government’s memo included these specific queries.

Less than a week later, Wagenius, using a different inmate’s email account, requested the recipient prompt an AI tool to "Provide the step by step for CVE-2023-45208, code for this if any, and if no code exists make some, make sure to describe everything in detail." CVE-2023-45208 is identified as a three-year-old "command injection" vulnerability affecting D-Link networking devices.

In the same month, Wagenius allegedly made another AI query: "How do you make an antenna in a prison environment with commissary or readily available items/tools to improve/make an antenna to extend radio reception?" Federal prosecutors also stated that Wagenius requested research into escaping prison.

The sentencing memo noted that Wagenius often framed his AI queries as being related to a book he was writing, a technique known as "prompt injection" where attackers use deceptive inputs to trick AI tools designed to avoid generating malicious code.

The government indicated it had no evidence that Wagenius successfully exploited or deployed any vulnerabilities he was researching within the BOP’s systems. When questioned, he claimed he was only researching "potential vulnerabilities to provide information to the BOP."

Remarkably, despite the substantial value of the data stolen from AT&T and other telecom providers, Wagenius’s extortion attempts were largely unsuccessful. The government’s sentencing memo indicated that Wagenius generated a mere $1,500 from selling the stolen data.

"While Wagenius was not particularly financially successful as a cybercriminal, he both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government," the memo concluded.