A federal judge in Seattle sentenced Wagenius, 22, to 70 months in prison on Friday, concluding a major chapter in the sprawling Snowflake hacking saga. The court also ordered him to pay $294,978 in restitution.
Operating under the moniker 'Kiberphant0m' while stationed at a U.S. Army base in South Korea, Wagenius was part of a group that exploited exposed credentials and a lack of multi-factor authentication on the cloud data storage service Snowflake. According to the Justice Department, the group stole call and text metadata for more than 100 million AT&T customers and breached Verizon's Push-to-Talk business.
'The conspirators offered to sell stolen data for thousands of dollars via posts on these forums,' the Justice Department said. Prosecutors stated that the group attempted to extort at least $1 million from victim organizations and used the data for further crimes, including SIM-swapping. Wagenius was identified as the hacker by cybersecurity journalist Brian Krebs in late 2024, less than a month before his arrest in Texas. He pleaded guilty in February and July 2025 to charges including aggravated identity theft, wire fraud conspiracy, and computer fraud.
Several co-conspirators face their own legal battles. Connor Riley Moucka, known as 'Judische,' pleaded guilty in August 2026 for his role in the Snowflake campaign. Kenneth Schuchman, a 28-year-old man from Washington with a prior conviction for operating the Satori botnet, was also alleged to have assisted. Another alleged co-conspirator, John Erin Binns, who is also wanted for a 2021 data breach at T-Mobile that exposed 76 million customers, remains a fugitive in Turkey.