U.S. Army Soldier Sentenced to 70 Months for AT&T, Verizon Extortion
Cameron John Wagenius, 22, a former U.S. Army soldier who operated under the alias "Kiberphant0m," was sentenced on September 25, 2026, to 70 months in federal prison and ordered to pay $294,978 in restitution for a hacking and extortion scheme that compromised at least 10 organizations, including AT&T and Verizon, and exposed call and text metadata belonging to more than 100 million AT&T customers. The sentence was handed down in the U.S. District Court for the Western District of Washington in Seattle, closing out a case the Department of Justice says also exposed the confidential phone records of a sitting U.S. government official and the family of a former official.
Incident at a Glance
| Attribute | Value |
|---|---|
| Defendant | Cameron John Wagenius, 22, former U.S. Army soldier |
| Alias | "Kiberphant0m" |
| Sentence | 70 months in federal prison |
| Restitution | $294,978 |
| Court | U.S. District Court, Western District of Washington (Seattle) |
| Scheme window | April 2023 – December 18, 2024 |
| Victims | At least 10 organizations, including AT&T and Verizon |
| Data exposed | AT&T call/text metadata for 100+ million customers; Verizon Push-to-Talk business data |
| Method | Stolen credentials via the "SSH Brute" tool and exposed Snowflake accounts without MFA |
| Ransom demanded | Over $1 million total; AT&T reportedly paid $370,000 in Bitcoin |
| Wagenius's take | Approximately $1,500 from selling stolen data |
| Pleas | Guilty March 5, 2025 (phone-record charges) and July 15, 2025 (wire fraud, extortion, identity theft) |
| Co-conspirators | Kenneth Schuchman, Conor Riley Moucka ("Judische"), John Erin Binns |
How It Worked
Credential Theft via SSH Brute and Snowflake
According to the Department of Justice, Wagenius helped develop a hacking tool called "SSH Brute" that he and co-conspirators used to obtain login credentials for victim organizations' protected computer networks between April 2023 and December 18, 2024. Separately, the group is tied to a wider campaign that exploited Snowflake cloud-storage accounts left exposed without multi-factor authentication — the same weakness behind the 2024 wave of Snowflake-linked breaches at AT&T, Ticketmaster, and other major companies. Stolen credentials and access details were traded and coordinated through Telegram group chats, which prosecutors say the conspirators used to plan intrusions and split proceeds.
Stealing AT&T and Verizon Customer Data
The credentials gave Wagenius and his co-conspirators access to systems holding call detail records — non-content metadata showing the source number, destination number, timestamp, and call duration for AT&T customers, ultimately covering more than 100 million accounts. Verizon's Push-to-Talk business unit was also targeted. This metadata, while not call content, is highly sensitive: in bulk, it can map out an individual's personal and professional network, reveal undisclosed relationships, and expose the movements of public officials and their families.
Extortion, a Bitcoin Ransom, and a Retaliation Post
Wagenius and his conspirators used the stolen data to extort victim companies directly, demanding more than $1 million in total across the scheme. AT&T is reported to have paid a $370,000 Bitcoin ransom to the group before one alleged co-conspirator, Conor Riley Moucka, was arrested in Canada. Prosecutors say that immediately after Moucka's arrest, the "Kiberphant0m" persona posted on hacking forums what it claimed were AT&T call logs for then-President-elect Donald Trump and then-Vice President Kamala Harris, along with schematics allegedly stolen from the National Security Agency — a post the DOJ characterizes as retaliation for the arrest. In November 2024, Wagenius separately disclosed stolen confidential call detail records belonging to a sitting government official and the family members of a former official, threatening to release more unless he was paid.
Arrest and Post-Arrest Conduct
Wagenius was arrested in December 2024 and charged in two separate federal indictments. Investigators say that before his arrest, he attempted to sell stolen data to a foreign intelligence service and searched online for information about defecting to Russia. After being taken into custody, prosecutors say Wagenius used other inmates' email accounts and attempted AI prompt-injection techniques to research Windows privilege-escalation exploits, D-Link router vulnerabilities, prison-antenna construction, and escape methods — conduct he claimed was intended to help the Bureau of Prisons identify security gaps.
Guilty Pleas and Sentencing
Wagenius pleaded guilty on March 5, 2025, to two counts of unlawfully transferring confidential phone-record information, and again on July 15, 2025, to conspiracy to commit wire fraud, extortion in relation to computer fraud, and aggravated identity theft. Assistant Attorney General A. Tysen Duva said Wagenius "spent more than a year and a half betraying the trust placed in him as an active duty soldier by carrying out a sweeping cybercrime campaign." FBI Seattle Special Agent in Charge W. Mike Herrington called it "especially shocking that a member of our armed forces, sworn to defend Americans and their constitutional rights, would engage in such a violation of privacy." A Defense Criminal Investigative Service resident agent, Paul Russell, noted the rarity of the case: "We don't often get leads where there's an active duty soldier with a secret clearance who's creating hacking tools and trafficking in data."
Impact Assessment
| Impact Area | Description |
|---|---|
| Consumer privacy | Call and text metadata for 100+ million AT&T customers exposed, enabling network-mapping and de-anonymization |
| National security | Alleged exposure of call logs tied to a sitting government official and a former official's family; claimed NSA schematics posted publicly |
| Financial | Over $1 million demanded across victims; AT&T reportedly paid a $370,000 Bitcoin ransom; Wagenius himself profited only about $1,500 |
| Institutional trust | An active-duty soldier with a secret clearance built hacking tools and sold stolen data, undercutting assumptions about insider vetting |
| Ongoing exposure | Co-conspirators tied to the broader Snowflake breach wave (affecting AT&T, Ticketmaster, and others) remain at large or face separate prosecution |
Recommendations
For Telecom and Cloud Customers
- Enforce mandatory multi-factor authentication on all cloud data-warehouse accounts (Snowflake and equivalents) — the absence of MFA, not a platform flaw, was the root cause of the 2024 breach wave this case stems from.
- Rotate and audit credentials for any service account with access to customer call/text metadata, and monitor for anomalous bulk-export activity.
- Treat call detail records (CDRs) as sensitive PII in data-handling policy, not just billing exhaust — in aggregate they enable relationship-mapping and physical-movement inference.
For Security and Insider-Risk Teams
- Extend insider-threat monitoring to cover personnel with security clearances who also maintain a parallel life on cybercrime forums and Telegram — financial motive and ideology are not the only insider-risk indicators.
- Watch for extortion actors reusing previously stolen access after a co-conspirator's arrest; retaliatory data dumps (as seen here following Moucka's arrest) can accelerate rather than deter disclosure.
- Coordinate with law enforcement early when facing extortion demands; ransom payment did not prevent further disclosures in this case.
For Individuals and Government Officials
- Assume mobile carrier metadata (who you called, when, for how long) can be exposed even without a direct breach of your own device or account.
- Government personnel and their families should request enhanced monitoring or number changes if notified their carrier was affected by a metadata breach.
- Be skeptical of unsolicited contact referencing this or related breaches — stolen metadata is frequently repurposed for follow-on social-engineering attempts.
Key Takeaways
- Cameron Wagenius, a 22-year-old former U.S. Army soldier operating as "Kiberphant0m," was sentenced to 70 months in prison and ordered to pay $294,978 in restitution.
- The scheme, running from April 2023 to December 18, 2024, hit at least 10 organizations and exposed AT&T call/text metadata for more than 100 million customers plus Verizon Push-to-Talk business data.
- Access relied on a self-developed tool called "SSH Brute" and exposed Snowflake credentials lacking MFA — the same weakness behind the broader 2024 Snowflake breach wave.
- Despite demanding over $1 million and AT&T reportedly paying a $370,000 Bitcoin ransom, Wagenius personally netted only about $1,500.
- The case exposed confidential call records tied to a sitting government official and included a retaliatory post claiming to leak Trump and Harris call logs and NSA schematics after a co-conspirator's arrest.
- Co-conspirators Kenneth Schuchman, Conor Riley Moucka, and John Erin Binns remain tied to the broader case, with Moucka pleading guilty separately in August 2026 and Binns still at large in Turkey.
Sources
- KrebsOnSecurity — U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
- U.S. Department of Justice — Former U.S. Soldier Sentenced for Hacking and Extortion Scheme That Exposed Sensitive Data of U.S. Government Official
- CyberScoop — Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies