NEWS

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier was sentenced to 70 months in prison and ordered to pay $294,978 restitution for hacking telecoms and stealing 100M+ AT&T records.

Dylan H.

News Desk

September 26, 2026
6 min read
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

Active-Duty Soldier Sentenced to Nearly Six Years for Telecom Extortion Spree

A U.S. Army soldier, identified as Cameron John Wagenius, 22, was sentenced on September 25, 2026 in U.S. District Court in Seattle, Washington, to 70 months in federal prison for hacking into more than a dozen telecommunications companies and stealing call and text metadata belonging to over 100 million AT&T customers in 2024. Wagenius, who operated online under the handle "Kiberphant0m," was stationed at a U.S. Army base in South Korea at the time of the intrusions. He pleaded guilty to all counts across two separate federal indictments and was ordered to pay $294,978 in restitution to victims.


Case Summary

AttributeValue
DefendantCameron John Wagenius ("Kiberphant0m"), 22
AffiliationU.S. Army soldier, stationed in South Korea
ChargesGuilty pleas on all counts across two federal indictments (computer intrusion and extortion-related offenses)
Sentence70 months (approximately 5 years, 10 months) federal prison
Restitution$294,978
Victims Affected100+ million AT&T customers; 12+ telecom companies worldwide
CourtU.S. District Court, Seattle, Washington
Sentencing DateSeptember 25, 2026

How the Scheme Worked

Snowflake Credential Abuse

According to court records, Wagenius "downloaded data from several large customers of the cloud data storage service Snowflake that had exposed credentials and did not enforce multi-factor authentication." Rather than exploiting a vulnerability in Snowflake's platform itself, the intrusions relied on credential stuffing and reused login details tied to Snowflake customer accounts that lacked MFA protections — a pattern consistent with the broader wave of Snowflake-linked breaches disclosed in 2024.

Extortion and Re-Extortion

Once inside victim environments, Wagenius and associates extracted large volumes of customer metadata, including from Verizon's Push-to-Talk business, and used the stolen data as leverage to extort the affected companies. Prosecutors noted that Wagenius went beyond a single extortion attempt, re-extorting some victims after initial payment demands and at points threatening to disclose what he characterized as national security secrets tied to the stolen data, escalating the pressure on victim organizations.

Limited Financial Gain, Outsized Harm

Despite the scale of the data stolen, prosecutors said Wagenius personally profited very little from the scheme — an estimated $1,500 from data sales. A DOJ sentencing statement underscored the disconnect between his financial take and the damage caused: "While Wagenius was not particularly financially successful as a cybercriminal, he both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government."

Broader Context: The 2024 Telecom Breach Wave

This case is directly tied to the mass-extortion campaign that exploited Snowflake customer accounts throughout 2024, in which attackers systematically targeted organizations that had not enabled multi-factor authentication on their Snowflake instances. AT&T disclosed in 2024 that attackers had accessed call and text metadata for nearly all of its wireless customers — the same dataset referenced in Wagenius's case, affecting more than 100 million individuals. The campaign also swept in other large telecom and enterprise Snowflake customers, cementing 2024 as a watershed year for credential-based cloud data theft at scale.

Wagenius did not act alone. Prosecutors identified several associates tied to the extortion campaign:

  • Kenneth Schuchman, 28, of Vancouver, Washington, who assisted with extortion efforts against victim companies.
  • Conor Riley Moucka, also known online as "Judische," of Kitchener, Ontario, who pleaded guilty in a related case in August 2026.
  • John Erin Binns, an American national living in Turkey, who still faces pending charges in connection with the scheme.

Notably, Wagenius's misconduct did not stop after his arrest. Prosecutors submitted evidence that in September 2025, while awaiting sentencing, Wagenius used other inmates' email accounts to solicit AI tools for information on Windows 10 privilege-escalation exploits, specific CVE details, and instructions for building a prison radio antenna. Investigators described his framing of the requests as a "book project" as a textbook example of prompt injection — an attempt to manipulate AI systems into bypassing safety guardrails. The court treated the incident as evidence of continued malicious intent, a factor that likely weighed on the final sentence.

Impact Assessment

Impact AreaDescription
Customer PrivacyCall and text metadata for 100M+ AT&T customers exposed, including calling patterns and contact records
Telecom Sector12+ telecom companies worldwide compromised via shared Snowflake credential weaknesses
Corporate ExtortionVerizon's Push-to-Talk business and other victims subjected to extortion and re-extortion demands
National Security ConcernsThreats to disclose data framed as national security-relevant, raising stakes beyond commercial harm
Institutional SecurityAttempted AI-assisted exploit research from inside a federal detention facility highlights gaps in incarcerated-inmate digital access controls

Recommendations

For Cloud Data Platform Customers (Snowflake and Similar Services)

  • Enforce mandatory multi-factor authentication on all accounts with access to cloud data warehouses — this single control would have blocked the credential-based intrusions at the root of this case.
  • Rotate and audit credentials regularly, and disable unused or stale service accounts that retain standing access to sensitive datasets.
  • Apply network-level allowlisting or IP-based access restrictions on data warehouse endpoints where feasible.

For Telecom Security Teams

  • Treat call detail record (CDR) and metadata stores as high-value targets equivalent to financial data, with corresponding monitoring and access controls.
  • Build extortion-response playbooks in advance — including legal, communications, and law enforcement coordination — since re-extortion attempts are increasingly common.
  • Monitor dark web and criminal forums for early indicators of stolen data being marketed, as this campaign's data was sold publicly before some victims were notified.

For Correctional and Detention Facilities

  • Review inmate access to third-party email and AI tools, given the demonstrated use of "prompt injection" framing to extract technical exploit information while incarcerated.
  • Strengthen monitoring of outbound requests from detained individuals with a history of technical cybercrime offenses.

Key Takeaways

  1. Cameron John Wagenius, a 22-year-old active-duty U.S. Army soldier, was sentenced to 70 months in federal prison and ordered to pay $294,978 in restitution for hacking telecom companies and extorting victims.
  2. The intrusions stemmed from Snowflake customer credentials that were exposed and lacked multi-factor authentication — not a platform-level vulnerability.
  3. The stolen dataset included metadata for over 100 million AT&T customers, tying this case directly to the broader 2024 Snowflake-linked telecom breach wave.
  4. Wagenius profited only about $1,500 despite the scale of the theft, underscoring that financial gain and real-world harm are not always proportional in cybercrime cases.
  5. Multiple co-conspirators — Kenneth Schuchman, Conor Riley Moucka ("Judische"), and John Erin Binns — face or have faced related charges, indicating a coordinated, multi-actor extortion operation.
  6. Wagenius attempted to solicit AI-generated exploit information from detention using a "prompt injection" framing, a factor prosecutors cited as evidence of continued malicious intent ahead of sentencing.

Sources