"Your actions show a shocking disregard for the safety and security of the United States... You took these actions motivated by greed and a desire for notoriety," U.S. District Judge Lauren King told Cameron John Wagenius at sentencing.
The sentence and the charges
Cameron John Wagenius, 22, was sentenced to 70 months in prison and ordered to pay $294,978 in restitution after a federal prosecution tied him to a multi-year campaign of telecommunications hacks, thefts of sensitive records, and extortion. Wagenius pleaded guilty in March 2025 to unlawfully transferring confidential phone records, and in July 2025 he admitted conspiracy to commit wire fraud, computer-related extortion, and aggravated identity theft in a separate case.
Scope of the campaign: locations, targets, and scale
Court documents say Wagenius conspired with three others to obtain credentials for the protected networks of at least ten organizations between April 2023 and December 2024. During that period he was on active duty and stationed in South Korea and Texas. The Justice Department described the victims only as U.S. and overseas telecommunications companies and other organizations; it has not publicly identified individual victims.
Investigators say the group traded hundreds of credentials, stole hundreds of thousands of customer records from multiple companies, and attempted to extort at least $1 million in total. The Justice Department reported the conspirators successfully sold some stolen data and used other records to commit fraud, including SIM swapping.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildTools, channels, and methods: SSH Brute, Telegram, BreachForums, XSS, X
Wagenius and his co-conspirators obtained login credentials using a variety of methods, including a hacking tool Wagenius helped develop that court documents identify as SSH Brute. The group exchanged stolen credentials in Telegram group chats and discussed using them to gain unauthorized access to other parts of victims' networks.
The conspirators advertised stolen data through XSS, BreachForums, X, and Telegram; some posts offered the information for sale, while others threatened to publish it unless victims paid. Prosecutors say the group not only sought extortion payments but also monetized records through sales and used them to facilitate additional crimes, specifically SIM swapping.
Connection to the 2024 Snowflake extortion campaign and high-profile claims
Court filings link Wagenius to the 2024 Snowflake extortion campaign, which affected AT&T, Verizon, and numerous other companies, as previously reported by The Register. After two suspects were arrested in connection with the Snowflake attacks, an account controlled by Wagenius claimed to possess AT&T call records belonging to Donald Trump and Kamala Harris. Wagenius and associates operated under online aliases including "kiberphant0m."
What this means for telecommunication companies, military oversight, and security teams
- Affected enterprises and procurement leaders (telecommunications companies): The case demonstrates how stolen credentials and public posting on venues such as XSS and BreachForums can lead to large data losses and extortion attempts totaling at least $1 million; telecoms will need to account for both direct customer-record exposure and downstream fraud like SIM swapping.
- Policymakers, regulators, and military oversight: The campaign was carried out while Wagenius was on active duty and stationed in South Korea and Texas, a fact prosecutors highlighted at trial and sentencing; that detail will be of interest to authorities responsible for force protection and credentialing policies for service members.
- Technologists and security teams: The group's use of a bespoke tool (SSH Brute), credential trading in Telegram, and public sale or extortion via forums underscores the continued need to monitor brute-force tooling, credential re-use, and third-party market channels where stolen records are advertised or sold.
The 70-month sentence and the restitution order mark a concrete outcome for a case that combined hacking tools, open criminal marketplaces, and real-world fraud. The prosecution established a chain from credential compromise to mass-record theft, extortion threats, data sales, and SIM-swap-enabled fraud — while leaving unanswered public questions about which specific organizations were targeted and how they will remediate the losses. The Register's original reporting on the Snowflake campaign remains part of the public record on how these tactics have been applied against major carriers and other companies.




