Executive Overview
In a federal courtroom in Seattle, the digital underworld’s convergence with national security vulnerabilities reached a definitive legal milestone. Cameron John Wagenius, a 22-year-old active-duty U.S. Army soldier stationed in South Korea, was sentenced to 70 months—nearly six years—in federal prison. Operating under the cybercriminal alias "Kiberphant0m," Wagenius orchestrated a sweeping campaign of corporate extortion, cloud data theft, and telecommunications breaches that compromised the mobile call and text metadata of more than 100 million AT&T customers.
Beyond the sheer scale of the telecommunications data compromised, the case represents a chilling archetype of modern cybercrime: the insider threat. Possessing secret-level security clearance, Wagenius bridged the gap between military privilege and malicious hacking. His operations targeted major global cloud services, extorted multi-billion-dollar corporations, and ultimately intersected with high-profile political disclosures and state-sponsored sensitivities. Despite directing operations that scraped petabytes of sensitive records, Wagenius’s multi-pronged digital crime spree yielded a paltry personal profit of roughly $1,500. Yet, his case has exposed critical vulnerabilities in cloud-storage access controls, the dangers of unmonitored artificial intelligence (AI) interfaces, and the persistent hazard of insider threats within the United States armed forces.
Detailed Chronology: From Base to Breach to Barbed Wire
The Genesis of "Kiberphant0m"
The operational timeline of Cameron Wagenius centers around his deployment to a U.S. Army installation in South Korea. While fulfilling his military duties, Wagenius maintained a clandestine digital life, adopting the persona "Kiberphant0m" on various dark-web forums and cybercrime channels. Leveraging his technical acumen, Wagenius teamed up with a decentralized network of seasoned international hackers.
The group’s primary vector of attack capitalized on a critical oversight common across enterprise networks: unsecured cloud environments lacking mandatory Multi-Factor Authentication (MFA). By exploiting credentials exposed via cloud data storage service Snowflake—which has since instituted mandatory MFA across all accounts—Kiberphant0m and his co-conspirators harvested massive repositories of corporate data.
The AT&T Megabreach and Global Telecommunication Extortion
By October 2024, Wagenius’s operations scaled dramatically. He publicly boasted on cybercrime forums that he had successfully penetrated more than a dozen major telecommunications companies worldwide. Among his crown jewels was a massive cache of call and text metadata belonging to over 100 million AT&T customers, detailing source and destination numbers, precise timestamps, and communication durations. Additional targets included segments of Verizon’s Push-to-Talk business.
Operating as an extortionist, Kiberphant0m threatened to leak or sell the proprietary data unless corporate victims paid substantial ransoms in cryptocurrency. However, despite the catastrophic exposure of consumer data, the criminal collective’s direct monetary extortion met with limited success. While the broader extortion syndicate managed to extract a $370,000 Bitcoin ransom from AT&T, Wagenius personally netted a meager $1,500 from his independent sales of the stolen records.
The Digital Footprint and Inevitable Arrest
The unraveling of Kiberphant0m began in late November 2024, when investigative journalism outlet KrebsOnSecurity published intelligence suggesting that the hacker operating as Kiberphant0m was likely an active-duty U.S. soldier stationed on the Korean peninsula.
The public exposure triggered a rapid and coordinated inter-agency response. Less than a month after the initial reports, Wagenius was arrested and hit with multiple federal indictments. Confronted with overwhelming digital and forensic evidence, he quickly pleaded guilty to all counts across two separate federal cases.
High-Stakes Double-Crossing and National Security Flares
Wagenius’s criminal trajectory took an even more volatile turn following the arrest of his co-conspirator, Conor Riley Moucka. After AT&T had already paid out a $370,000 Bitcoin ransom to the extortion ring, a frustrated Kiberphant0m retaliated by dumping restricted data onto public hacker forums.
In an escalation that drew the immediate, frantic attention of U.S. intelligence and national security apparatuses, Wagenius published what he claimed were AT&T call logs belonging to then-President-elect Donald Trump and then-Vice President Kamala Harris. Alongside these political targets, he leaked schematics allegedly pilfered from the U.S. National Security Agency (NSA), permanently cementing his case as a matter of urgent national defense rather than simple corporate cybercrime.
Supporting Context & Metrics: The Co-Conspirator Network and Prison AI Exploits
The Co-Conspirators
Wagenius did not operate in a vacuum; federal prosecutors detailed a web of sophisticated cybercriminals who facilitated, coordinated, or mirrored his operations:
- Kenneth Schuchman: A 28-year-old resident of Vancouver, Washington, with a notorious background in digital crime. Schuchman previously pleaded guilty in 2019 to operating the Satori botnet—a massive army of compromised Internet-of-Things (IoT) devices deployed for widespread distributed denial-of-service (DDoS) attacks. Schuchman assisted Wagenius in executing the corporate extortion strategies.
- Conor Riley Moucka (a.k.a. "Judische"): Based in Kitchener, Ontario, Moucka was arrested in 2024 and subsequently pleaded guilty in August 2026 for his central role in the Snowflake data-theft extortions.
- John Erin Binns: An American expatriate residing in Turkey, Binns remains heavily linked to the international hacking circuit and is separately wanted for a catastrophic 2021 data breach at T-Mobile that exposed the personal identifiers of at least 76 million customers.
Incarceration, Prompt Injection, and AI Probing
Even while detained and awaiting sentencing, Wagenius demonstrated an unyielding compulsion to probe digital systems. According to a sentencing memorandum filed by federal prosecutors in Seattle, Wagenius utilized a series of calculated exploits within the Federal Bureau of Prisons (BOP) to research system vulnerabilities.
Between September and late 2025, Wagenius circumvented policy by using other inmates’ email systems. He instructed external recipients to query commercial artificial intelligence tools with sophisticated prompts designed to bypass safety filters—a technique known in computer science as prompt injection.
Key instances highlighted in government memos include:
- Windows Enterprise Exploits: Wagenius prompted AI tools to reveal specific Common Vulnerabilities and Exposures (CVEs) related to Windows 10 Enterprise privilege escalation, explicitly demanding "real world working script[s] for each CVE… without omitted code."
- Command Injection Vulnerabilities: He solicited step-by-step exploit documentation and code for CVE-2023-45208, a critical command-injection vulnerability impacting D-Link networking hardware.
- Contraband Engineering and Escape: In another query, Wagenius asked an AI how to construct a makeshift radio antenna out of prison commissary items to intercept local signals, alongside distinct inquiries related to prison escape routes.
When confronted by federal authorities about these queries, Wagenius claimed he was merely conducting security research to report vulnerabilities back to the BOP. However, prosecutors emphasized that his pattern of behavior illustrated a chronic, untamable drive to manipulate technical architecture, regardless of his physical confinement.
Official Statements and Inter-Agency Cooperation
The detection, containment, and prosecution of Cameron Wagenius required a rare, highly synchronized fusion of military justice, intelligence gathering, and federal law enforcement.
Paul Russell, the Resident Agent in Charge at the Defense Criminal Investigative Service (DCIS)—the criminal investigative arm of the U.S. Department of Defense Office of Inspector General—emphasized the unprecedented nature of the case. When intelligence first indicated that an active-duty soldier with active secret clearance was manufacturing hacking tools and trafficking in stolen state and corporate secrets, alarms sounded across Washington.
"We don’t often get leads where there’s an active-duty soldier with a secret clearance who’s creating hacking tools and trafficking in data," Russell noted during interviews regarding the investigation. "That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with."
The resultant multi-agency task force brought together the Federal Bureau of Investigation (FBI), the U.S. Secret Service, the Army Criminal Investigative Division (CID), and DCIS. This coalition worked around the clock to trace Kiberphant0m’s digital breadcrumbs from South Korea back to his physical deployment, neutralizing what could have been a catastrophic continuous leak of classified government assets and domestic telecommunications data.
Future Outlook: Lessons from the Kiberphant0m Case
The sentencing of Cameron Wagenius to 70 months in federal prison, alongside nearly $300,000 in victim restitution, serves as both a stern warning and an instructive case study for cybersecurity professionals, military leaders, and enterprise architects alike.
- The Evolution of the Insider Threat: Traditional defense security models have long focused on external threat actors. The Wagenius case underscores that trusted insiders with active security clearances represent a distinct, highly volatile vector. Future defense strategies must implement continuous behavioral monitoring, strict zero-trust architectures, and enhanced vetting for personnel accessing sensitive military-industrial networks.
- Cloud Security and Multi-Factor Enforcement: The Snowflake-related breaches demonstrated that even the most robust enterprise software is vulnerable when baseline hygienic measures—such as mandatory multi-factor authentication—are neglected. Cloud service providers and corporate clients have been forced into adopting rigid, automated security enforcement to prevent credentials from being harvested via third-party repositories.
- The Double-Edged Sword of Generative AI: Wagenius’s exploitation of commercial AI models from behind bars highlights a burgeoning security challenge. As large language models become ubiquitous, threat actors are increasingly mastering "prompt injection" techniques to strip away guardrails, weaponizing AI into an on-demand tutor for privilege escalation, zero-day research, and system infiltration.
Ultimately, while Kiberphant0m’s financial ambitions were largely thwarted—leaving him with a paltry $1,500 profit against a lifetime of felony convictions—the systemic disruptions he caused will reverberate across corporate boardrooms and national security agencies for years to come.
