U.S. Army Soldier Sentenced to Nearly Six Years in Federal Prison for Massive AT&T and Snowflake Extortion Scheme

A federal court in Seattle has sentenced 22-year-old U.S. Army soldier Cameron John Wagenius to 70 months in federal prison, followed by three years of supervised release, for his role in a sophisticated, multinational cybercrime and extortion campaign. Operating under the online moniker "Kiberphant0m" while stationed at a military base in South Korea, Wagenius infiltrated cloud storage provider Snowflake and multiple international telecommunications giants. The breach compromised sensitive mobile call and text metadata belonging to more than 100 million AT&T customers and exposed corporate networks worldwide. In addition to his prison term, U.S. District Judge ordered Wagenius to pay $294,978 in restitution to victims.
The sentencing marks a critical milestone in one of the most high-profile insider-threat cyber investigations in recent U.S. history. Prosecutors revealed that despite orchestrating massive data thefts impacting major corporations and high-profile public figures, Wagenius reaped a meager financial return of roughly $1,500 from his illicit operations. The case has underscored the vulnerability of enterprise cloud storage environments, the growing threat of insider actors with security clearances, and the misuse of emerging generative artificial intelligence tools by incarcerated individuals seeking to bypass security controls.
Chronology of the Cyberattack and Extortion Campaign
The origins of the conspiracy trace back to cloud storage giant Snowflake, whose ecosystem suffered a wave of unauthorized access incidents due to exposed corporate credentials and a historical lack of mandatory multi-factor authentication (MFA) across all accounts. Taking advantage of these lax security practices, Wagenius and a cell of cybercriminal co-conspirators harvested proprietary data from several prominent Snowflake enterprise customers.
By October 2024, Wagenius had escalated his activities, publicly boasting on underground cybercrime forums that he had exfiltrated call and text metadata—including source numbers, destination numbers, timestamps, and call durations—for tens of millions of AT&T customers. Operating globally, Kiberphant0m claimed responsibility for breaching over a dozen telecommunications firms, including Verizon’s Push-to-Talk business. The threat actor initiated a public extortion campaign, threatening to leak sensitive proprietary and customer data unless ransoms were paid.
The investigation accelerated significantly in late November 2024, when cybersecurity journalist Brian Krebs published reporting indicating that the notorious Kiberphant0m persona likely belonged to an active-duty U.S. soldier stationed in South Korea. Within weeks, federal law enforcement moved in. Wagenius was arrested in December 2024, facing multiple federal indictments. Demonstrating early cooperation with authorities, he quickly pleaded guilty to all charges.
While behind bars awaiting sentencing, Wagenius continued to pose a security management challenge. According to court filings submitted by federal prosecutors in September 2025, Wagenius exploited accounts belonging to fellow inmates to bypass Bureau of Prisons (BOP) computer usage policies. Using these intermediaries, he attempted to query commercial AI tools for privilege escalation vulnerabilities, D-Link command injection exploits, and instructions on constructing makeshift radio antennas or planning prison escapes. Prosecutors noted that Wagenius utilized prompt injection techniques—such as framing queries within the context of a fictional book he was writing—to trick safety-aligned AI models into outputting malicious code. Investigators found no evidence that these exploits were successfully deployed against BOP systems.
Co-Conspirators and the Wider Criminal Network
Wagenius did not act in isolation. Federal indictments and subsequent court proceedings have revealed an interconnected syndicate of seasoned digital extortionists operating across North America and overseas.
Chief among his alleged co-conspirators is Kenneth Schuchman, a 28-year-old resident of Vancouver, Washington. Schuchman possesses a notorious background in cybercrime, having pleaded guilty in 2019 to operating the Satori botnet—a massive collection of compromised Internet-of-Things (IoT) devices used to execute large-scale distributed denial-of-service (DDoS) attacks. Prosecutors allege Schuchman played a central advisory and facilitating role in the extortion schemes executed by the cell.
Another key figure is Conor Riley Moucka, operating under the alias "Judische," a Canadian citizen from Kitchener, Ontario. Moucka was arrested in 2024 and subsequently entered a guilty plea in August 2026 for his participation in the Snowflake-related extortions. Meanwhile, American national John Erin Binns, currently residing in Turkey, remains wanted by U.S. authorities. Binns is heavily implicated not only in the recent Snowflake enterprise breaches but also in the catastrophic 2021 T-Mobile data breach, which compromised the personal records of at least 76 million customers.
The escalation of the cyberattack reached a geopolitical apex following Moucka’s arrest. Even after AT&T and other victims had funneled hundreds of thousands of dollars in Bitcoin ransoms—including a reported $370,000 payout by AT&T—Kiberphant0m engaged in secondary extortion tactics. Frustrated by law enforcement interventions, Wagenius retaliated by leaking unverified call logs allegedly belonging to then President-elect Donald Trump and then Vice President Kamala Harris, alongside documents purporting to be schematics stolen from the U.S. National Security Agency (NSA).
Multilateral Law Enforcement Response and Insider Threat Concerns
The investigation into Wagenius and his associates required an unprecedented level of coordination among military and federal civilian law enforcement agencies. Paul Russell, the resident agent in charge at the Defense Criminal Investigative Service (DCIS)—the criminal investigative arm of the Department of Defense Office of Inspector General—highlighted the extraordinary nature of the case.
When intelligence indicated that an active-duty soldier holding a secret security clearance was actively developing cyber-offensive tools and trafficking stolen enterprise data, DCIS immediately launched a joint task force alongside the Federal Bureau of Investigation (FBI), the Army Criminal Investigative Division (CID), and the U.S. Secret Service.
"We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data," Russell remarked following the sentencing. "That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with."
The involvement of an individual with a high-level military security clearance elevated the threat assessment from a routine corporate hack to a potential national security crisis. While investigators ultimately determined that the primary motivation was financial extortion and cybercriminal notoriety rather than traditional espionage, the ease with which Wagenius accessed classified networks and weaponized his technical skills has prompted a thorough review of internal vetting and digital monitoring protocols within the Department of Defense.
Broader Industry Implications and Cybersecurity Analysis
The fallout from the Wagenius case extends far beyond the courtroom, serving as a watershed moment for corporate cloud security, enterprise authentication standards, and the regulation of artificial intelligence.
First, the Snowflake breaches exposed a fundamental weakness in modern cloud architecture: the over-reliance on static credentials coupled with optional multi-factor authentication. Following the widespread fallout, Snowflake and thousands of enterprise clients transitioned to mandatory MFA enforcement, realizing that perimeter defenses are obsolete if administrative credentials are leaked, phished, or poorly managed.
Second, the telecommunications industry has faced intense regulatory scrutiny regarding the security of metadata repositories. While the stolen records did not include the audio content of phone calls or text messages, the leakage of comprehensive call-detail records for over 100 million customers exposed massive privacy vulnerabilities, enabling advanced tracking, profiling, and social engineering attacks against the public.
Finally, Wagenius’s post-arrest behavior inside the federal prison system has triggered alarm bells regarding the accessibility and safety guardrails of commercial artificial intelligence models. Security analysts point to his utilization of prompt-injection strategies to extract zero-day vulnerability research and exploit scripts as concrete proof that incarcerated bad actors will continuously attempt to leverage emerging technologies to expand their capabilities. As AI providers refine their safety filters, the incident illustrates the persistent cat-and-mouse game between threat actors attempting to weaponize generative models and security architects striving to restrict the proliferation of actionable exploit code.
As Wagenius begins his nearly six-year federal prison sentence, the broader criminal ecosystem associated with the Snowflake and AT&T extortions continues to face dismantling through international judicial cooperation. The case stands as a stark reminder of the convergence between conventional military personnel, transnational cybercrime syndicates, and the systemic vulnerabilities of global digital infrastructure.







