News

US Army Soldier Gets Nearly Six Years After Hacking AT&T and Extorting Telecom Giants

Cameron Wagenius, the active-duty soldier behind Kiberphant0m, got 70 months for stealing AT&T call records via Snowflake and extorting telecoms. He pocketed about $1,500.

US Army Soldier Gets Nearly Six Years After Hacking AT&T and Extorting Telecom Giants

He held a secret clearance and wore a US Army uniform. Online he was Kiberphant0m, bragging about stealing phone records for tens of millions of AT&T customers. On September 25, a federal judge in Seattle sentenced Cameron John Wagenius, 22, to 70 months in prison and ordered him to pay about $294,978 in restitution.

All of it happened while he was on active duty.

Stolen through unlocked doors

Wagenius and his co-conspirators went after Snowflake cloud customers whose credentials had been exposed and whose accounts had no multi-factor authentication. They downloaded the data and then demanded payment. Snowflake has since made MFA mandatory.

The victims list reads like a consumer brand directory: AT&T, Ticketmaster, Advance Auto Parts and Santander among them. In October 2024, Wagenius boasted of holding AT&T call and text metadata for tens of millions of customers and claimed breaches of more than a dozen telecoms, including Verizon's Push-to-Talk service.

Escalation after the arrest

When co-conspirator Conor Riley Moucka, known as Judische, was arrested, Wagenius did not go quiet. He started re-extorting victims. He posted what he claimed were AT&T call logs for then President-elect Trump and Vice President Harris, along with what he said were NSA schematics.

The payday was tiny for the damage. AT&T had already paid the group about $370,000 in Bitcoin. Wagenius personally made about $1,500. The wider crew included Kenneth Schuchman, who has a history with the Satori botnet, and John Erin Binns, who is in Turkey and also wanted over the 2021 T-Mobile breach.

Investigators from DCIS, the FBI, Army CID and the Secret Service moved in after Brian Krebs flagged that Kiberphant0m looked like a soldier stationed in South Korea. Wagenius was later based at Fort Cavazos in Texas. DOJ and FBI officials singled out the betrayal of trust by someone serving on active duty.

Hacking from a cell

The strangest chapter came after his arrest. While in Bureau of Prisons custody awaiting sentencing, Wagenius used other inmates' email accounts to query commercial AI tools. He asked for Windows privilege-escalation CVEs, step-by-step exploitation of the D-Link flaw CVE-2023-45208, antenna designs for use inside prison and research on escaping.

To get past the chatbots' guardrails, he framed the questions as research for a book he was writing. It is a crude prompt-injection trick, and it is a reminder that AI tools are now part of the attacker toolkit even for someone behind bars.

The Snowflake campaign itself was never sophisticated. It worked because big companies left cloud accounts guarded by a single password, and a 22-year-old soldier noticed.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free