A U.S. Army soldier who leveraged his position to orchestrate a sophisticated cyber-extortion campaign—stealing the metadata of more than 100 million AT&T customers—was sentenced to 70 months in federal prison on Tuesday. Cameron John Wagenius, 22, was ordered to pay nearly $300,000 in restitution to his victims, marking the conclusion of a high-profile case that exposed glaring vulnerabilities in corporate data security and the dangers of the insider threat within the military.
Wagenius, who was stationed at a U.S. Army base in South Korea at the time of his offenses, operated under the cybercriminal handle “Kiberphant0m.” Working in tandem with a small group of co-conspirators, he exploited gaps in cloud storage security to siphon massive troves of sensitive information. His activities brought him into the crosshairs of federal authorities after he began publicly bragging about his exploits on various cybercrime forums, ultimately leading to his arrest and subsequent guilty plea on all counts in two separate federal indictments.
The Rise and Fall of “Kiberphant0m”
The scope of the operation was significant. Wagenius and his associates targeted large customers of the cloud data storage service Snowflake. By identifying organizations that had left credentials exposed and failed to mandate multi-factor authentication (MFA)—a security oversight that Snowflake has since rectified across all its accounts—the group was able to gain unauthorized access to sensitive databases.
By October 2024, the persona Kiberphant0m began surfacing on dark web and hacker forums, boasting that he had successfully exfiltrated call and text metadata from tens of millions of AT&T customers. This data, which included source and destination phone numbers, timestamps, and the duration of communications, represented a treasure trove for threat actors. Beyond AT&T, Wagenius claimed to have compromised more than a dozen telecommunications companies worldwide, including Verizon’s “Push-to-Talk” business segment. He used this stolen data as leverage, attempting to extort these corporations with the threat that he would leak the information if his ransom demands were not met.
The investigation into the identity of Kiberphant0m culminated in late 2025, when researchers at KrebsOnSecurity publicly suggested that the individual behind the moniker was likely a U.S. soldier stationed in South Korea. The military and federal law enforcement agencies moved quickly, and by the end of the year, Wagenius was in custody.
An Insider Threat and Global Co-Conspirators
The complexity of the case was compounded by the diverse network of individuals involved. Federal prosecutors identified Kenneth Schuchman, a 28-year-old from Vancouver, Washington, as a key accomplice. Schuchman was no stranger to federal authorities; he had previously pleaded guilty in 2019 to operating the Satori botnet, an extensive collection of compromised Internet-of-Things (IoT) devices that had been used to launch massive distributed denial-of-service (DDoS) attacks.
Other members of the conspiracy remain subject to ongoing legal proceedings. Conor Riley Moucka, known by the alias “Judische,” was arrested in Ontario, Canada, and entered a guilty plea in August 2026. Another associate, John Erin Binns—an American citizen currently residing in Turkey—remains a person of interest for his alleged role in a separate, massive 2021 T-Mobile data breach that exposed the personal records of at least 76 million people.
For the Department of Defense, the case was particularly unsettling. Paul Russell, a resident agent in charge at the Defense Criminal Investigative Service (DCIS), noted that the involvement of an active-duty soldier with secret clearance elevated the incident from a standard cybercrime to a matter of national security. “We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data,” Russell remarked. “That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with.”
Escalation and Reckless Extortion
As the pressure mounted on the criminal enterprise, Wagenius’s behavior became increasingly erratic and dangerous. Following the arrest of his associate Moucka, and despite the fact that AT&T had already paid the group a $370,000 Bitcoin ransom, Wagenius attempted to re-extort the company. In a move that drew severe condemnation from federal officials, he leaked what he purported to be the call logs of high-profile political figures, including then President-elect Donald Trump and then Vice President Kamala Harris. Furthermore, he claimed to possess and distribute schematics allegedly stolen from the U.S. National Security Agency (NSA).
Continued Activity Behind Bars
Despite being incarcerated while awaiting his sentencing, Wagenius’s penchant for hacking did not cease. A sentencing memo filed by federal prosecutors in September 2026 revealed that he had repeatedly violated Bureau of Prisons (BOP) computer use policies, attempting to identify and exploit vulnerabilities within the prison system’s own internal networks.
Using the accounts of other inmates, Wagenius engaged in “prompt injection” attacks against commercial artificial intelligence tools. By framing his requests as part of a book-writing project, he attempted to bypass safety guardrails to obtain actionable code for exploiting Windows 10 Enterprise vulnerabilities and D-Link networking hardware. In one notable instance, he even sought instructions on how to construct a radio antenna using commissary items, as well as information related to escaping the facility.
While prosecutors acknowledged that there was no evidence Wagenius successfully deployed these vulnerabilities against the prison network, the attempts highlighted a persistent and troubling fixation on cyber exploitation. In his defense, Wagenius claimed he was merely researching these vulnerabilities to assist the BOP in strengthening their security posture—a defense that failed to sway the court.
A Disproportionate Impact
Perhaps the most ironic element of the case, according to investigators, is the disparity between the potential damage caused and the financial gain realized by the perpetrators. While the data stolen from AT&T and other firms held immense value on the black market, the government’s sentencing memo noted that Wagenius’s total take from his criminal activities amounted to a meager $1,500.
“While Wagenius was not particularly financially successful as a cybercriminal, he both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government,” the prosecution wrote. The judge’s sentence of 70 months reflects the gravity of that harm. As Wagenius begins his prison term, the case serves as a stark reminder of the reach of modern cyber-extortion and the profound security challenges posed when those entrusted with the nation’s secrets turn their skills against the public they are sworn to protect.

