Cybersecurity and Digital Privacy

Former US Army Soldier Sentenced to Nearly Six Years in Federal Prison for Massive Snowflake Extortion and AT&T Data Breach

Cameron John Wagenius, a 22-year-old former United States Army soldier who operated under the high-profile cybercriminal moniker "Kiberphant0m," was sentenced today in a Seattle federal courtroom to 70 months in prison. Wagenius received his punishment following a guilty plea connected to an extensive international hacking campaign that compromised major telecommunications companies and leaked sensitive metadata for more than 100 million AT&T customers. In addition to his prison term, United States District Judge ordered Wagenius to pay $294,978 in victim restitution.

The sentencing marks a critical milestone in a multi-agency federal investigation that exposed an unprecedented insider threat within the United States military. Operating out of an Army base in South Korea while holding a secret security clearance, Wagenius utilized his digital access and technical capabilities to coordinate cyberattacks alongside a syndicate of international threat actors. Despite the massive scale of the data he and his co-conspirators exfiltrated—including call and text logs belonging to high-profile figures—investigators revealed that Wagenius earned a meager $1,500 in direct profits from his illicit enterprise, highlighting a stark discrepancy between the widespread chaos he generated and his personal financial gain.

Anatomy of the Snowflake Breach and Global Telecommunication Targeting

The sophisticated cyberattacks masterminded by Wagenius and his associates heavily leveraged vulnerabilities in cloud data storage provider Snowflake. In the wave of compromises that shook the cybersecurity landscape, threat actors gained unauthorized entry into large corporate tenant accounts hosted on Snowflake’s platform by exploiting exposed credentials. Critically, many of these corporate accounts failed to enforce mandatory multi-factor authentication (MFA), a massive security oversight that allowed unauthorized users to siphon staggering volumes of proprietary corporate records and customer data. Snowflake has since instituted mandatory MFA across all client environments to mitigate this vector.

Using the handle Kiberphant0m, Wagenius capitalized on these breaches by downloading massive troves of telecommunications data. By October 2024, he began publicly bragging on underground cybercrime forums about his acquisition of call and text metadata from more than a dozen international telecommunications networks, most notably AT&T and Verizon’s Push-to-Talk enterprise division. The stolen data packets contained highly sensitive metrics including source and destination telephone numbers, timestamps, communication durations, and routing information.

Rather than quietly monetizing the data through private sales, Kiberphant0m and his co-conspirators engaged in aggressive, public extortion schemes. The threat group threatened to dump the exfiltrated records online unless the targeted companies paid substantial cryptocurrency ransoms. In one instance, after AT&T reportedly paid a $370,000 Bitcoin ransom to satisfy the extortionists, the situation deteriorated further when members of the cybercriminal collective were compromised by law enforcement.

In a volatile retaliatory move following the arrest of co-conspirator Conor Riley Moucka, Kiberphant0m published what he claimed were the AT&T call logs of then-President-elect Donald Trump and then-Vice President Kamala Harris. Furthermore, the hacker threatened to leak schematics allegedly stolen from the United States National Security Agency (NSA), abruptly transforming a corporate extortion scheme into an international national security crisis.

A Timeline of Detection, Arrest, and Prosecution

The rapid unmasking and prosecution of Cameron Wagenius unfolded across an accelerated timeline of intense digital forensics and multi-agency law enforcement coordination:

  • October 2024: Kiberphant0m takes to cybercrime forums to openly boast about stealing call and text metadata belonging to tens of millions of AT&T customers, alongside executing parallel extortion campaigns against over a dozen telecom entities worldwide.
  • Late November 2024: Cybersecurity research publication KrebsOnSecurity publishes an investigative warning indicating that the threat actor operating as Kiberphant0m matches the digital and geographic footprint of an active-duty U.S. soldier stationed in South Korea.
  • December 2024: Federal law enforcement agents arrest Wagenius. He is promptly hit with two separate federal indictments detailing computer fraud, extortion, and unauthorized access charges, to which he quickly enters a guilty plea.
  • August 2026: Canadian co-conspirator Conor Riley Moucka, known online as "Judische," pleads guilty in connection to the broader Snowflake extortion conspiracy after being arrested in 2024.
  • September 2025 – September 2026: While incarcerated and awaiting sentencing in a federal Bureau of Prisons (BOP) facility, Wagenius attempts to compromise BOP computer networks by illicitly utilizing other inmates’ email accounts to query artificial intelligence tools for Windows privilege escalation CVEs and prison radio/antenna modifications.
  • Today: Wagenius is formally sentenced in Seattle to 70 months in federal prison and ordered to pay nearly $300,000 in victim restitution.

Co-Conspirators and the Global Cybercrime Syndicate

Federal prosecutors have outlined a broader network of defendants working in tandem with Wagenius to execute the global Snowflake data thefts and subsequent extortion operations. Among them is Kenneth Schuchman, a 28-year-old resident of Vancouver, Washington, with a notorious history in the cybercrime underground. Schuchman previously pleaded guilty in 2019 to operating the Satori botnet, a vast and destructive network of compromised Internet-of-Things (IoT) devices deployed to launch massive distributed denial-of-service (DDoS) attacks against global internet infrastructure.

Another primary co-conspirator, Conor Riley Moucka of Kitchener, Ontario, formally pleaded guilty in August 2026 following his apprehension by Canadian authorities. Meanwhile, a third individual, American national John Erin Binns, remains a fugitive living in Turkey. Binns is not only tied to the Snowflake extortion campaigns but is also heavily wanted by law enforcement for his alleged role in the catastrophic 2021 T-Mobile data breach, which exposed the personally identifiable information of at least 76 million customers.

The Insider Threat: Official Responses and Inter-Agency Investigation

The involvement of an active-duty service member holding a secret security clearance elevated the case from a standard corporate cybercrime investigation to a high-priority national security counter-intelligence operation. Paul Russell, the resident agent in charge at the Defense Criminal Investigative Service (DCIS)—the criminal investigative arm of the Department of Defense Office of Inspector General—emphasized the alarming nature of the discovery.

"We don’t often get leads where there’s an active-duty soldier with a secret clearance who’s creating hacking tools and trafficking in data," Russell noted. "That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with."

The multi-agency task force that brought Wagenius to justice required unprecedented cooperation between the DCIS, the Federal Bureau of Investigation (FBI), the Army Criminal Investigation Division (CID), and the United States Secret Service. The convergence of military counterintelligence and federal cybercrime units underscores how modern military infrastructure must increasingly contend with technologically proficient personnel who choose to weaponize their access against both private corporations and national interests.

Prison Misconduct and "Prompt Injection" AI Exploits

Even while sitting behind bars awaiting his day in court, Wagenius demonstrated an active persistence in exploring cybersecurity exploits. According to a sentencing memorandum filed by federal prosecutors in Seattle, Wagenius violated Bureau of Prisons computer use policies in September 2025 by routing unauthorized technical inquiries through the email accounts of fellow inmates.

Investigators discovered that Wagenius instructed email recipients to query commercial artificial intelligence platforms using sophisticated "prompt injection" techniques—a method designed to bypass safety filters programmed into AI tools to prevent the generation of malicious exploit code. Disguising his requests as research for a book he claimed to be writing, Wagenius sought specific Common Vulnerabilities and Exposures (CVEs) related to Windows 10 Enterprise privilege escalation, step-by-step instructions and executable code for D-Link command injection vulnerabilities (CVE-2023-45208), and methods for constructing makeshift antennas from prison commissary items to boost radio reception and research prison escape vectors.

While government prosecutors noted there was no evidence that Wagenius successfully deployed these vulnerabilities within the prison system’s computer architecture, the attempted breaches reinforced the assessment that his technical curiosity and operational drive posed an ongoing security risk.

Broader Implications for Enterprise Security and Cloud Storage

The conviction and sentencing of Cameron Wagenius serve as a watershed moment illustrating the vulnerabilities inherent in modern cloud infrastructure and corporate identity management. The Snowflake extortion campaigns demonstrated that even enterprise-grade cloud ecosystems can be severely compromised not through zero-day exploits of the underlying platform, but through basic administrative lapses, such as failing to enforce multi-factor authentication across all user accounts.

Furthermore, the case emphasizes the profound danger posed by technologically proficient insider threats. As modern militaries and corporations integrate digital transformation initiatives, the convergence of authorized internal access with malicious external syndicates presents complex challenges for security architects. Although Wagenius ultimately realized minimal financial reward—netting a mere $1,500 from his exploits—the cascading damages, operational disruptions, and threats to national security metrics underscore the disproportionate devastation a single insider can unleash in an interconnected global economy.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button