Cybersecurity & Protection

U.S. Army Soldier Sentenced to 70 Months in Prison for Massive Data Theft and Global Extortion Campaign

Cameron John Wagenius, a 22-year-old U.S. Army soldier formerly stationed in South Korea, was sentenced today to 70 months in federal prison following his role in a high-profile, international cybercrime operation that compromised the sensitive metadata of more than 100 million AT&T customers. In addition to the prison term, Wagenius—who operated under the alias “Kiberphant0m”—has been ordered to pay nearly $300,000 in restitution to the victims of his multi-layered extortion schemes.

The sentencing, held in a federal courtroom in Seattle, marks the culmination of a complex investigation involving the Department of Defense, the FBI, and the U.S. Secret Service. The case highlights the escalating threat of insider exploitation, particularly when individuals with high-level security clearances leverage their technical expertise to bypass corporate security infrastructures.

The Rise and Fall of Kiberphant0m

Wagenius’s descent into cybercrime began while he was serving on active duty. Operating from a military installation, he utilized his access to exploit vulnerabilities in cloud-based storage services, most notably Snowflake. The core of his operation relied on the exploitation of exposed credentials and a systemic failure among several large corporations to enforce multi-factor authentication (MFA) protocols. By targeting these lapses, Wagenius gained unauthorized access to massive datasets containing call and text metadata, including source and destination numbers, timestamps, and the duration of communications.

The chronology of his criminal activities peaked in late 2024, when he began publicly bragging on various dark-web forums about his successful infiltration of more than a dozen telecommunications firms worldwide, including Verizon’s specialized Push-to-Talk business. His strategy was brazen: he would exfiltrate private user data and then directly extort the corporations, threatening to leak the information publicly if his demands were not met.

The investigation gained critical momentum in November 2024, when cybersecurity journalist Brian Krebs identified a correlation between the “Kiberphant0m” persona and a U.S. soldier stationed in South Korea. Following this exposure, federal agents moved quickly, leading to his arrest and subsequent guilty plea on all counts across two separate federal indictments.

A Network of Co-conspirators

The prosecution of Wagenius has unraveled a broader web of cybercriminals. Prosecutors named Kenneth Schuchman, a 28-year-old resident of Vancouver, Washington, as a key accomplice. Schuchman is no stranger to law enforcement; he previously pleaded guilty in 2019 to operating the “Satori” botnet, an extensive collection of compromised Internet-of-Things (IoT) devices used to execute massive distributed denial-of-service (DDoS) attacks.

Other figures in the case include Conor Riley Moucka, known by the alias “Judische,” who was arrested in 2024 and pleaded guilty in August 2026. Furthermore, the investigation implicated John Erin Binns, an American citizen currently residing in Turkey. Binns remains a significant figure in the cybersecurity community, as he is also wanted in connection with the 2021 T-Mobile data breach that compromised the personal details of at least 76 million individuals.

The Breach and the Ransom

The scope of the data compromised by the group was staggering. By targeting the metadata of over 100 million AT&T customers, the attackers gained access to information that, while not containing the actual content of conversations, provides a detailed map of an individual’s social and professional network. This type of metadata is highly valuable for intelligence gathering and targeted social engineering attacks.

Despite the immense scale of the breach, the extortion attempts yielded surprisingly low financial returns. According to court filings, the group generated only approximately $1,500 in direct profits from the sale of stolen data, a stark contrast to the massive potential value of the exfiltrated information. However, the group’s reach extended beyond simple corporate extortion. In a move that escalated the severity of the case, Kiberphant0m attempted to leverage national security concerns. Following the arrest of his co-conspirator, Moucka—and despite AT&T having already paid a $370,000 Bitcoin ransom—Wagenius released what he claimed were internal call logs for then-President-elect Donald Trump and Vice President Kamala Harris. He further claimed to possess stolen schematics belonging to the U.S. National Security Agency (NSA), an act that immediately alerted the defense and intelligence communities to the gravity of the threat.

Defense Criminal Investigative Service Response

Paul Russell, a resident agent in charge at the Defense Criminal Investigative Service (DCIS), underscored the uniqueness of the case. “We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data,” Russell noted. The involvement of a soldier with high-level access triggered an immediate, multi-agency response.

“It was very serious from jump street,” Russell explained. “Because it was a unique insider threat, our partner organizations—the FBI, the Army Criminal Investigative Division (CID), and the Secret Service—had to mobilize quickly. We were dealing with someone who had both the motive and the clearance to do real, structural damage to U.S. interests.”

Persistent Criminal Intentions

Perhaps the most alarming aspect of the proceedings was the discovery that Wagenius’s criminal behavior did not cease after his arrest. A sentencing memo filed by federal prosecutors on September 19, 2026, revealed that while incarcerated and awaiting sentencing, Wagenius continued to attempt to exploit security vulnerabilities.

Using the accounts of other inmates to bypass restrictions, Wagenius utilized commercial AI tools to research privilege escalation and bypass techniques for Windows 10 Enterprise systems. He also sought detailed instructions on exploiting the CVE-2023-45208 vulnerability, a known command injection flaw in D-Link networking hardware. Furthermore, he inquired about constructing makeshift radio antennas within the prison environment and even researched methods for escape.

Wagenius attempted to mask these inquiries by framing them as research for a book, a tactic prosecutors identified as a form of “prompt injection.” This technique is designed to bypass the safety guardrails programmed into commercial AI models to prevent the generation of malicious code. While the government found no evidence that Wagenius successfully deployed these vulnerabilities within the Bureau of Prisons (BOP) network, the attempts demonstrate a persistent, high-level technical aptitude and a disregard for legal consequences that will likely influence his classification and monitoring during his 70-month sentence.

Broader Implications for Cybersecurity

The sentencing of Cameron Wagenius serves as a cautionary tale for both the private sector and military institutions. The primary implication is the critical necessity of multi-factor authentication. Snowflake’s decision to mandate MFA across all accounts following these breaches is a response that experts suggest should be the standard for all cloud-based services.

Furthermore, the case illustrates the vulnerability of the modern "insider threat." When an individual with a security clearance utilizes their position to facilitate global cybercrime, the traditional boundaries of cybersecurity defense become blurred. The case has spurred a reassessment of how the Department of Defense monitors the digital activities of personnel with access to sensitive systems.

Finally, the use of AI tools to facilitate illicit activities highlights a new frontier in cybercrime. As criminals become more adept at using prompt injection to extract technical guidance from AI, security providers and regulators will face the challenge of implementing more robust safety controls that cannot be circumvented by creative, albeit malicious, framing.

For the victims—the 100 million AT&T customers—the impact remains. While the metadata stolen does not represent the entirety of their private communications, the exposure of call and text patterns poses a lingering risk of targeted harassment and identity-related fraud. As Wagenius begins his prison term, the telecommunications industry and federal agencies continue the long process of auditing the damage and fortifying the systems that were so easily breached by a single, determined, and technically capable insider.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Lock It Soft
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.