By Global Cybersecurity & Defense Desk
Published: September 2026
Executive Overview
In a landmark federal sentencing hearing in Seattle, 22-year-old U.S. Army soldier Cameron John Wagenius was sentenced to 70 months—nearly six years—in federal prison. Wagenius, who operated in cybercriminal underground circles under the alias "Kiberphant0m," was also ordered to pay $294,978 in restitution to his victims.
Wagenius’s sentencing marks a critical milestone in one of the most high-profile corporate extortion campaigns in recent history. While stationed at a U.S. Army base in South Korea, Wagenius exploited compromised credentials to infiltrate cloud storage platforms and telecommunications giants, most notably making off with the call and text metadata of more than 100 million AT&T customers.
Operating alongside a notorious cadre of international cybercriminals, Wagenius orchestrated a scheme characterized by breathtaking audacity, targeting dozens of telecommunications companies worldwide. Despite the sheer scale of the data breaches—which exposed sensitive metadata for a vast majority of AT&T’s subscriber base and briefly put national security secrets in the crosshairs—investigative findings reveal a stark irony: the vast multi-nation operation netted Wagenius a meager $1,500 in direct profits.
Beyond the corporate ransoms and digital pillaging, the case triggered a massive, multi-agency federal counterintelligence response due to Wagenius’s active-duty military status and active security clearance. Even while incarcerated and awaiting sentencing, Wagenius continued to test the boundaries of digital security, caught attempting to leverage artificial intelligence (AI) to probe Bureau of Prisons (BOP) systems for vulnerabilities and researching prison escape methods.
Detailed Chronology: From Soldier to Cybercriminal Syndicate
The Genesis of "Kiberphant0m"
Cameron John Wagenius was an active-duty U.S. Army soldier stationed in South Korea, holding a secret military clearance. Beneath his uniform, however, Wagenius maintained a secret, highly active persona in elite cybercriminal forums: Kiberphant0m.
Working in tandem with an international ring of seasoned threat actors, Wagenius capitalized on a widespread campaign targeting cloud data storage provider Snowflake. The threat group successfully harvested massive troves of corporate data by exploiting accounts that had exposed credentials and—crucially—failed to enforce multi-factor authentication (MFA). (In the wake of these incidents, Snowflake mandated MFA across all accounts globally.)
By October 2024, Kiberphant0m’s operations escalated dramatically. Taking to cybercrime forums, the young soldier publicly bragged about stealing the call and text metadata—including source numbers, destination numbers, timestamps, and call durations—for tens of millions of AT&T customers. Claiming responsibility for breaches across more than a dozen telecommunications firms worldwide, including Verizon’s Push-to-Talk business, Kiberphant0m began publicly extorting these corporations under the threat of leaking proprietary subscriber data.
The Net Tightens: Investigation and Arrest
The digital trail eventually caught the attention of independent investigative journalists. In late November 2024, KrebsOnSecurity published investigative findings indicating that the notorious Kiberphant0m was likely an active-duty U.S. soldier stationed on the Korean peninsula.
The report acted as a catalyst for federal law enforcement. Less than a month later, in December 2024, federal authorities arrested Wagenius. He was promptly hit with two separate federal indictments, to which he swiftly pleaded guilty across all counts, opting for rapid cooperation with prosecutors.
The Extortion Unravels and Escalates
As federal investigators dug deeper into the syndicate, the scope of the conspiracy widened. Prosecutors revealed that Wagenius was assisted by Kenneth Schuchman, a 28-year-old from Vancouver, Washington, with an extensive cybercriminal pedigree. Schuchman had previously pleaded guilty in 2019 to operating the Satori botnet—a massive infrastructure of compromised Internet-of-Things (IoT) devices used to launch devastating distributed denial-of-service (DDoS) attacks.
Other co-conspirators faced legal action internationally:
- Conor Riley Moucka (a.k.a. "Judische"), a Canadian national from Kitchener, Ontario, was arrested in 2024 and pleaded guilty in August 2026 for his role in the Snowflake data thefts.
- John Erin Binns, an American citizen currently residing in Turkey, remains wanted not only for his alleged participation in the Snowflake extortions but also for his connection to a massive 2021 data breach at T-Mobile that compromised the personal information of at least 76 million customers.
As pressure mounted on the extortion ring—particularly following Moucka’s arrest and after AT&T had already funneled a $370,000 Bitcoin ransom to the group—Kiberphant0m engaged in volatile, erratic behavior. In an act of re-extortion and retaliation, Wagenius posted what he claimed were the call logs of then-President-elect Donald Trump and then-Vice President Kamala Harris, alongside schematics allegedly stolen from the U.S. National Security Agency (NSA).
Supporting Context & Metrics
The quantitative scale of the Wagenius enterprise reveals a striking disconnect between corporate risk exposure and actual criminal enrichment:
- 100+ Million: The number of AT&T customers whose mobile call and text metadata was compromised during the 2024 breach.
- $300,000 / $294,978: The exact restitution amount ordered by the federal judge to be paid by Wagenius to victims.
- 70 Months: The duration of federal prison time handed down to Wagenius during his Seattle sentencing hearing.
- $370,000: The Bitcoin ransom initially paid out by AT&T to the extortion syndicate before the leaks escalated.
- $1,500: The total actual cash profit Wagenius managed to extract from selling the stolen data, highlighting a staggering inefficiency in his criminal monetization strategy.
- Dozen+: The number of international telecommunications corporations globally targeted by Kiberphant0m’s extortion campaign.
Official Statements and Insider Threat Realities
The involvement of an active-duty soldier with a security clearance shocked the defense and intelligence communities, triggering a rare joint task force.
Paul Russell, resident agent in charge at the Defense Criminal Investigative Service (DCIS)—the criminal investigative arm of the U.S. Department of Defense Office of Inspector General—emphasized the unique nature of the threat. Working alongside the FBI, the Army Criminal Investigative Division (CID), and the U.S. Secret Service, DCIS faced a scenario that rarely crosses federal desks.
"We don’t often get leads where there’s an active-duty soldier with a secret clearance who’s creating hacking tools and trafficking in data," Russell noted. "That doesn’t happen every day, and so when that hits, it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with."
Despite Wagenius’s rapid guilty plea and subsequent cooperation, federal prosecutors highlighted his persistent, compulsive probing of secure systems—even from behind bars.
Behind Bars: AI-Assisted Probing and Prison Security Violations
A sentencing memorandum filed by federal prosecutors in Seattle on September 19 shed light on Wagenius’s behavior while incarcerated and awaiting trial. Despite facing severe federal charges, Wagenius violated the computer use policies of the Bureau of Prisons (BOP) in an effort to research system vulnerabilities and explore escape routes.
According to BOP records cited in the memo:
- September 2025: Wagenius used another inmate’s email access to instruct an email recipient to prompt a commercial AI tool. He asked for specific Common Vulnerabilities and Exposures (CVEs) related to Windows 10 Enterprise privilege escalation, alongside real-world working scripts "without omitted code."
- Days Later: Wagenius utilized a different inmate’s email account to direct an AI tool to generate step-by-step instructions and code for CVE-2023-45208, a command injection vulnerability found in D-Link networking devices.
- Radio & Escape Research: During the same timeframe, Wagenius requested instructions on constructing makeshift prison antennas from commissary items to boost radio reception, alongside queries regarding prison escape tactics.
When confronted by investigators, Wagenius claimed he was merely using a common "prompt injection" technique—framing his queries around a fictional book he was writing—to bypass AI safety guardrails that normally restrict the generation of exploit code. He maintained that he was only researching vulnerabilities to hand over to the BOP as security assistance. Prosecutors noted, however, that there was no evidence Wagenius successfully deployed these vulnerabilities within BOP networks.
Future Outlook
The sentencing of Cameron Wagenius closes a critical chapter in the fallout of the massive Snowflake cloud data breaches and corporate telecom extortions. However, the broader ecosystem of international cyber extortion remains a persistent global threat.
With co-conspirator Conor Riley Moucka recently entering a guilty plea, and figures like John Erin Binns remaining international fugitives, federal prosecutors continue to untangle the decentralized networks that bridge rogue insiders with transnational cyber syndicates.
For the Department of Defense, the case serves as a severe wake-up call regarding insider threats, credential hygiene, and the intersection of active military service with digital espionage. As artificial intelligence tools increasingly lower the barrier to entry for complex exploit research—even within correctional facilities—federal agencies face an evolving paradigm where technical aptitude, combined with malicious intent, demands unprecedented vigilance across both public defense infrastructure and private enterprise networks.
