A U.S. Army soldier who leveraged his technical skills to orchestrate a sophisticated cyber-extortion campaign against global telecommunications giants has been sentenced to 70 months in federal prison. Cameron John Wagenius, a 22-year-old service member who operated under the digital alias “Kiberphant0m,” was ordered by a federal judge in Seattle to serve nearly six years behind bars and pay approximately $300,000 in restitution to his victims. The sentencing marks the conclusion of a high-stakes investigation into a breach that compromised the metadata of more than 100 million AT&T customers.
Wagenius, who was stationed at a U.S. Army base in South Korea at the time of his criminal activities, became a primary focus for federal authorities after he began infiltrating cloud data storage accounts. By targeting companies that utilized the Snowflake cloud platform, Wagenius and his co-conspirators exploited accounts that suffered from poor security hygiene—specifically, the failure to implement multi-factor authentication (MFA). Since the breaches, Snowflake has mandated the use of MFA across all customer accounts to prevent similar unauthorized access.
The scope of the operation was global. In October 2024, the persona Kiberphant0m began circulating claims on underground cybercrime forums, boasting that he had successfully exfiltrated call and text metadata—including source and destination phone numbers, timestamps, and call durations—for tens of millions of AT&T customers. Beyond AT&T, Wagenius claimed to have compromised over a dozen telecommunications firms worldwide, including the Push-to-Talk division of Verizon. He utilized this stolen data as leverage, publicly threatening these corporations with the release of sensitive customer information unless they met his extortion demands.
The trail leading to Wagenius began to heat up in late November 2025, when investigative reporting by KrebsOnSecurity suggested that the entity known as Kiberphant0m was likely a U.S. soldier based in South Korea. The identification of an active-duty military member as a major cyber-extortionist triggered an immediate, multi-agency response. Less than a month after the initial reports, Wagenius was taken into custody. He was subsequently charged in two separate federal indictments and quickly entered guilty pleas to all counts, acknowledging his role in the breaches and the subsequent extortion attempts.
The sentencing hearing in Seattle served to underscore the gravity of the offense. Beyond the financial impact, prosecutors highlighted the profound breach of trust and security associated with a soldier who held a secret clearance using his position to traffic in illicitly obtained data.
Federal investigators revealed that Wagenius did not act alone. He was supported by Kenneth Schuchman, a 28-year-old resident of Vancouver, Washington, who brought a significant history of cybercriminal activity to the partnership. Schuchman had previously gained notoriety in 2019 when he pleaded guilty to operating the Satori botnet, a massive infrastructure of compromised Internet-of-Things (IoT) devices that had been weaponized to launch large-scale distributed denial-of-service (DDoS) attacks.
The wider network involved in the Snowflake data thefts continues to face legal consequences. Conor Riley Moucka, an Ontario resident known online as “Judische,” was arrested in 2024 and entered a guilty plea in August 2026. Another key figure in the investigation, John Erin Binns, an American currently residing in Turkey, remains a person of interest; Binns is also wanted by authorities in connection with a massive 2021 T-Mobile data breach that exposed the personal records of at least 76 million individuals.
The behavior of Wagenius became increasingly erratic as the walls closed in. Prosecutors noted that the soldier admitted to “re-extorting” victims and even threatening to release classified national security secrets to further his objectives. In a particularly brazen move following the arrest of his co-conspirator Moucka—and despite the fact that AT&T had already paid the group a $370,000 ransom in Bitcoin—Wagenius posted what he claimed were private call logs belonging to then President-elect Donald Trump and then Vice President Kamala Harris. He further claimed to possess schematics stolen from the U.S. National Security Agency (NSA), escalating his activities from corporate extortion to a potential national security threat.
Paul Russell, a resident agent in charge at the Defense Criminal Investigative Service (DCIS), the investigative arm of the Department of Defense Office of Inspector General, described the unique challenges posed by the case. “We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data,” Russell said. “That doesn’t happen every day, and so when that hits, it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with.” The investigation required a synchronized effort between the FBI, the Army Criminal Investigative Division (CID), and the U.S. Secret Service.
Despite his cooperation with investigators following his arrest, Wagenius demonstrated a persistent desire to engage with cyber vulnerabilities even while in custody. A sentencing memo filed by federal prosecutors in September 2026 revealed that while awaiting his fate, Wagenius repeatedly violated Bureau of Prisons (BOP) computer use policies. He was caught using other inmates’ email accounts to solicit information from commercial artificial intelligence tools, specifically asking for details on how to exploit vulnerabilities in Windows 10 Enterprise and D-Link networking devices.
In these exchanges, Wagenius employed a technique known as “prompt injection,” a method used to bypass the safety guardrails built into AI models. By framing his requests within the context of a book he claimed to be writing, he attempted to trick the AI into providing functional exploit code and technical instructions for privilege escalation. In another instance, he reportedly researched methods for constructing antennas within a prison environment to extend radio reception and even inquired about potential escape routes. While the government noted there was no evidence he successfully deployed any of these exploits within the BOP network, the attempts highlighted a compulsive, if not entirely successful, dedication to his trade.
The irony of the case remains that for all the disruption caused to millions of customers and several major telecommunications corporations, the financial rewards for the group were relatively meager. The government’s sentencing memo noted that the total profit realized by Wagenius from the sale of stolen data amounted to approximately $1,500.
“While Wagenius was not particularly financially successful as a cybercriminal, he both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government,” the memo concluded. For the 22-year-old former soldier, the transition from a digital persona on the fringes of the dark web to a federal prisoner serves as a stark reminder of the legal and personal consequences of using advanced technical capabilities to challenge the security of both the private sector and the state.

