Ethical Hacking News
A U.S. Army soldier has been sentenced to 70 months in prison for his role in hacking into multiple telecommunications companies and stealing mobile call and text metadata for over 100 million AT&T customers in 2024. The soldier, who operated under the cybercriminal persona "Kiberphant0m," was assisted by a 28-year-old man with a lengthy cybercriminal history and made a total of around $1,500 from selling stolen data. The case highlights the threat posed by insider threats, particularly in the context of national security.
A U.S. Army soldier, Cameron John Wagenius, has been sentenced to 70 months in federal prison for hacking into multiple telecommunications companies and stealing mobile call and text metadata for over 100 million AT&T customers.Kiberphant0m, Wagenius' cybercrime persona, downloaded data from cloud storage service Snowflake without proper authentication, allowing him to access sensitive information.Wagenius and his alleged co-conspirators, including Kenneth Schuchman, extorted companies in exchange for not publishing stolen data, with total earnings of around $1,500.Two other alleged co-conspirators, Conor Riley Moucka and John Erin Binns, are still facing charges in connection with the Snowflake data thefts.Kiberphant0m also re-extorted victims and threatened to disclose national security secrets, including allegedly stolen NSA schematics.The case highlights the threat posed by insider threats, particularly in the context of national security.The government considers Wagenius' extortion efforts largely unsuccessful, despite the enormous financial value of the stolen data.
U.S. Attorney's Office, District of Washington
A U.S. Army soldier who operated under the cybercriminal persona "Kiberphant0m" has been sentenced to 70 months in federal prison for his role in hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024. Cameron John Wagenius, 22, was stationed at a U.S. Army base in South Korea when he adopted the persona "Kiberphant0m." Working with three alleged co-conspirators, Kiberphant0m downloaded data from several large customers of the cloud data storage service Snowflake that had exposed credentials and did not enforce multi-factor authentication. This lack of security measures allowed Kiberphant0m to access sensitive information without proper authentication.
In October 2024, Kiberphant0m bragged on the cybercrime forums that he’d stolen the call and text metadata (e.g. source and destination number, timestamp, duration, etc.) for tens of millions of AT&T customers. Kiberphant0m claimed to have hacked into more than a dozen telecommunications companies worldwide, including Verizon’s Push-to-Talk business, and publicly extorted these companies in exchange for a promise not to publish the stolen data. The extortion efforts were largely unsuccessful, with Kiberphant0m making a total of around $1,500 from selling stolen data.
Kiberphant0m's cybercrime activities were discovered by KrebsOnSecurity, a cybersecurity blog, in late November 2025, which revealed that Wagenius was likely a U.S. soldier stationed in South Korea. Less than a month later, Wagenius was arrested and charged in two separate federal indictments. He soon pleaded guilty to all counts in both cases.
At his sentencing hearing in Seattle today, Wagenius was sentenced to nearly six years in federal prison, and ordered to pay $294,978 in restitution. Federal prosecutors said Wagenius was assisted in his efforts to extort victim companies by Kenneth Schuchman, a 28-year-old man from Vancouver, Washington who has a lengthy cybercriminal history. In 2019, Schuchman pleaded guilty to operating the Satori botnet, a vast collection of hacked Internet-of-Things (IoT) devices that was used for large-scale distributed denial-of-service (DDoS) attacks.
Two other alleged co-conspirators of Wagenius are still facing charges in connection with the Snowflake data thefts; Conor Riley Moucka, a.k.a. "Judische," of Kitchener, Ontario was arrested in 2024 and pleaded guilty in August 2026; and John Erin Binns, an American man currently living in Turkey who is also wanted for a 2021 data breach at T-Mobile that exposed the personal information of at least 76 million customers.
Kiberphant0m also admitted to re-extorting victims, and threatening to disclose national security secrets. Immediately following Moucka’s arrest — after AT&T had already paid the extortion group a $370,000 Bitcoin ransom — Kiberphant0m posted on hacker forums what he claimed were the AT&T call logs for then President-elect Donald Trump and for then Vice President Kamala Harris, as well as schematics allegedly stolen from the U.S. National Security Agency (NSA).
The case highlights the threat posed by insider threats, particularly in the context of national security. "We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data," said Paul Russell, resident agent in charge at the Defense Criminal Investigative Service (DCIS). "That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with."
Incredibly, despite the enormous financial value of the data stolen from AT&T and other telecom providers, Wagenius's extortion efforts were largely unsuccessful. The government's sentencing memo states that while Wagenius was not particularly financially successful as a cybercriminal, he both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government.
Related Information:
https://www.ethicalhackingnews.com/articles/A-Cybercrime-Conviction-The-Story-of-Kiberphant0m-and-the-Extortion-of-ATT-and-Verizon-ehn.shtml
https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions/
https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions
https://www.justice.gov/usao-wdwa/pr/former-us-soldier-sentenced-hacking-and-extortion-scheme-exposed-sensitive-data-us
Published: Fri Sep 25 17:47:03 2026 by llama3.2 3B Q4_K_M