SecurityDeveloping

Former U.S. Soldier Sentenced to 70 Months for Hacking and Extorting Telecoms

Cameron John Wagenius ordered to pay $294,978 in restitution for stealing data on over 100 million AT&T customers

By LineZotpaper
Published
Updated
Read Time2 min
Sources2 outlets
A former U.S. Army soldier has been sentenced to 70 months in federal prison for orchestrating a massive data theft and extortion campaign against AT&T, Verizon, and other technology companies. Cameron John Wagenius, who pleaded guilty last year, was also ordered to pay $294,978 in restitution to victims.

A federal judge in Seattle sentenced Wagenius, 22, to 70 months in prison on Friday, concluding a major chapter in the sprawling Snowflake hacking saga. The court also ordered him to pay $294,978 in restitution.

Operating under the moniker 'Kiberphant0m' while stationed at a U.S. Army base in South Korea, Wagenius was part of a group that exploited exposed credentials and a lack of multi-factor authentication on the cloud data storage service Snowflake. According to the Justice Department, the group stole call and text metadata for more than 100 million AT&T customers and breached Verizon's Push-to-Talk business.

'The conspirators offered to sell stolen data for thousands of dollars via posts on these forums,' the Justice Department said. Prosecutors stated that the group attempted to extort at least $1 million from victim organizations and used the data for further crimes, including SIM-swapping. Wagenius was identified as the hacker by cybersecurity journalist Brian Krebs in late 2024, less than a month before his arrest in Texas. He pleaded guilty in February and July 2025 to charges including aggravated identity theft, wire fraud conspiracy, and computer fraud.

Several co-conspirators face their own legal battles. Connor Riley Moucka, known as 'Judische,' pleaded guilty in August 2026 for his role in the Snowflake campaign. Kenneth Schuchman, a 28-year-old man from Washington with a prior conviction for operating the Satori botnet, was also alleged to have assisted. Another alleged co-conspirator, John Erin Binns, who is also wanted for a 2021 data breach at T-Mobile that exposed 76 million customers, remains a fugitive in Turkey.

§

Analysis

Why This Matters

  • The sentence holds an active-duty soldier accountable for using military access for large-scale cyber extortion.
  • It underscores the systemic risk of single points of failure in cloud services like Snowflake, affecting over 100 million telecom customers.
  • Affected consumers face ongoing exposure from data that was successfully sold to other criminals before the arrest.

Background

The case originates from a massive credential theft campaign targeting Snowflake, a cloud data storage provider, in 2024. Hackers used stolen login credentials to access the accounts of major telecom companies. In December 2024, cybersecurity journalist Brian Krebs identified the primary hacker as a U.S. Army soldier stationed in South Korea. Cameron Wagenius was arrested in Texas shortly after and charged in federal indictments.

Key Perspectives

[U.S. Justice Department]: Secured a significant prison sentence and restitution order, framing the case as a vital disruption of extortion targeting critical national infrastructure. [Victim Companies]: AT&T and Verizon faced significant reputational damage and incurred substantial remediation costs following the exposure of millions of customer records. [Cybersecurity Industry]: Views the incident as a stark warning about supply chain vulnerabilities, inspiring a push for stricter security protocols like mandatory multi-factor authentication.

What to Watch

  • The fate of fugitive co-conspirator John Erin Binns, who remains in Turkey.
  • Potential class-action lawsuits or state-level regulatory actions against the impacted telecom firms.
  • Whether the broader Snowflake investigation leads to further indictments or security mandates for cloud storage providers.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.