U.S. Army Soldier Sentenced to Nearly Six Years for Massive Telecom Data Extortion Scheme

A U.S. Army soldier who leveraged his technical skills to orchestrate a sophisticated cyber-extortion campaign against major telecommunications companies has been sentenced to 70 months in federal prison. Cameron John Wagenius, a 22-year-old active-duty soldier formerly stationed in South Korea, pleaded guilty to charges related to the theft of mobile call and text metadata belonging to more than 100 million AT&T customers. In addition to his prison term, a federal judge ordered Wagenius to pay nearly $300,000 in restitution to the victims of his crimes.

Wagenius, who operated under the menacing cybercriminal handle "Kiberphant0m," became the center of a high-stakes investigation that spanned multiple international jurisdictions. His criminal activities, which began in 2024, exposed the vulnerabilities of large-scale corporate data management, particularly within cloud storage environments. By exploiting unsecured credentials and capitalizing on companies that failed to enforce multi-factor authentication (MFA) on their Snowflake cloud accounts, Wagenius and his co-conspirators gained unauthorized access to vast troves of sensitive telecommunications data.

The scope of the breach was staggering. In October 2024, operating from his base in South Korea, Wagenius publicly boasted on various underground cybercrime forums that he had successfully exfiltrated call and text metadata—including source and destination phone numbers, timestamps, and call durations—for tens of millions of AT&T customers. His digital footprint extended well beyond a single carrier; Kiberphant0m claimed responsibility for compromising more than a dozen telecommunications firms worldwide, including Verizon’s specialized Push-to-Talk business. He utilized this stolen data as leverage, attempting to extort these corporations with threats to publicly leak the sensitive records if his ransom demands were not met.

The unraveling of the Kiberphant0m persona began in late November 2024, when security researchers at KrebsOnSecurity identified a high probability that the perpetrator was a U.S. service member stationed in South Korea. The investigative trail tightened rapidly, leading to the arrest of Wagenius less than a month later. Following his apprehension, he faced two separate federal indictments, ultimately choosing to plead guilty to all counts, marking a swift conclusion to a case that had sent shockwaves through the cybersecurity and national security communities.

The sentencing hearing in Seattle highlighted the collaborative effort required to bring Wagenius to justice. The case involved a multi-agency task force, including the FBI, the U.S. Secret Service, the Army Criminal Investigative Division (CID), and the Defense Criminal Investigative Service (DCIS). Paul Russell, a resident agent in charge at the DCIS, noted the rarity and gravity of the situation.

"We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data," Russell remarked. "That doesn’t happen every day, and so when that hits, it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with."

Wagenius did not act alone. Federal prosecutors revealed that he collaborated with Kenneth Schuchman, a 28-year-old resident of Vancouver, Washington, who already possessed a significant reputation in the cybercrime underworld. Schuchman had previously pleaded guilty in 2019 to his role in operating the "Satori" botnet, a massive network of compromised Internet-of-Things (IoT) devices used to launch devastating distributed denial-of-service (DDoS) attacks. Other co-conspirators tied to the Snowflake data thefts remain the subject of ongoing legal proceedings. Conor Riley Moucka, known as "Judische," was arrested in 2024 and entered a guilty plea in August 2026. John Erin Binns, an American currently residing in Turkey, remains wanted for his alleged involvement in a 2021 T-Mobile data breach that exposed the personal information of at least 76 million individuals.

The severity of the threat posed by Wagenius escalated significantly after his co-conspirators began facing legal pressure. In a desperate move to re-extort victims, Kiberphant0m threatened to disclose national security secrets. Following the arrest of Moucka, and despite the fact that AT&T had already paid the extortionists a ransom of $370,000 in Bitcoin, Wagenius posted what he claimed were private AT&T call logs belonging to then President-elect Donald Trump and then Vice President Kamala Harris. Furthermore, he claimed to possess and threatened to release schematics allegedly stolen from the U.S. National Security Agency (NSA), an act that drew intense scrutiny from federal authorities regarding the potential compromise of state secrets.

Despite the high-profile nature of his activities, the sentencing memo filed by federal prosecutors in September 2026 revealed a startling reality: Wagenius’s criminal enterprise was largely unsuccessful from a financial standpoint. Despite the immense value of the data he targeted, investigators determined that he earned a total of only about $1,500 throughout his criminal campaign. "While Wagenius was not particularly financially successful as a cybercriminal, he both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government," the memo noted.

Even while in custody awaiting sentencing, Wagenius continued to display the same impulsive and problematic behavior that led to his arrest. The government’s sentencing memorandum documented instances where Wagenius attempted to exploit the Bureau of Prisons (BOP) computer network. According to BOP records, in September 2025, Wagenius used the email accounts of other inmates to interact with commercial AI tools. Using a technique known as "prompt injection," he attempted to bypass the AI’s safety protocols to gain information on vulnerabilities in Windows 10 Enterprise, as well as specific details on how to exploit a known command injection vulnerability in D-Link networking devices.

In these exchanges, Wagenius often framed his requests as research for a book he claimed to be writing, a classic tactic used to circumvent the ethical safeguards built into AI platforms to prevent them from generating malicious code. He also reportedly searched for information on how to construct a radio antenna from commissary items and even inquired about methods for escaping prison. Prosecutors clarified that there was no evidence that Wagenius successfully deployed any of the vulnerabilities he researched within the BOP systems, and when confronted, he claimed he was merely identifying weaknesses to report them to the authorities.

The sentencing of Wagenius serves as a stark reminder of the risks posed by individuals with specialized technical training and security clearances who choose to operate outside the law. While his tenure as "Kiberphant0m" was brief, the combination of his insider status, the massive volume of personal data he compromised, and his reckless disregard for national security infrastructure ensured that the consequences of his actions would be severe. As he begins his 70-month sentence, the case remains a significant case study in the intersection of military insider threats and the evolving landscape of global cyber-extortion.

Share:

Muslim writes for Tech Maze.

Leave a comment