Skip to main content
Emerging ThreatsData Breaches

Soldier's Cybercrime Spree Targets AT&T, Snowflake, Ends in 70-Month Sentence

Courthouse interior with natural light, featuring a podium and circular seal.

“Cameron Wagenius spent more than a year and a half betraying the trust placed in him as an active duty soldier by carrying out a sweeping cybercrime campaign,” A. Tysen Duva, assistant attorney general of the Justice Department’s Criminal Division, said in a statement.

Sentence, restitution and guilty plea

The Justice Department announced that Cameron John Wagenius was sentenced to 70 months in prison for a multi-year cybercrime spree. Wagenius pleaded guilty in July 2025 and was ordered to pay almost $295,000 in restitution. Prosecutors said he was directly involved in attempted extortion efforts that targeted multiple organizations for a combined total of more than $1 million.

Scale of the breaches tied to Snowflake and AT&T

Prosecutors and corporate disclosures linked Wagenius to intrusions that intersected with the 2024 compromise of Snowflake customer environments. Connor Moucka — a co-conspirator extradited from Canada and later pleading guilty — was described by prosecutors as having played a central role in the wider Snowflake attack, which compromised more than 165 customer environments.

AT&T confirmed in July that cybercriminals gained access to the company’s Snowflake environment in April and stole six months of phone and text records belonging to “nearly all” of its customers. Authorities said some of the records in Wagenius’ possession at arrest had been stolen in the attacks on Snowflake customer databases.

Tactics, tools and activity on an Army base

Officials said Wagenius, who identified online as “kiberphant0m” and “cyb3rph4nt0m,” used a hacking tool he helped develop called SSH Brute to steal credentials. When law enforcement seized his devices in December 2024, they found evidence of thousands of stolen identification documents and large amounts of cryptocurrency.

Days after that seizure, prosecutors said, Wagenius purchased a new laptop against his commanding officer’s order and used it daily for five days in the barracks at Fort Cavazos in Texas, running VPN software to conceal his identity and location. Authorities also said he attempted to sell stolen sensitive data to a foreign intelligence service and sought information online about defecting to Russia.

Co-conspirators, victims and extortion payments

Wagenius acted with at least two alleged co-conspirators named in filings: Connor Moucka, a Canadian who was extradited to the United States in March 2025 and pleaded guilty in August 2025, and John Erin Binns, who is not presently in U.S. custody. Prosecutors stated the trio stole billions of sensitive records and that the conspirators together received more than $2.5 million in extortion payments.

Authorities did not name all victims in court filings, but listed several organizations affected by the attack spree: AT&T, Ticketmaster, Advance Auto Parts and Santander. Allison Nixon, chief research officer at Unit 221B, previously told CyberScoop that leaked stolen call records of President Donald Trump were part of a failed attempt to extort $500,000 from AT&T.

How AT&T customers, Fort Cavazos command, and law enforcement are affected

  • AT&T customers: Corporate confirmation that six months of phone and text records for “nearly all” customers were stolen places a concrete data exposure on a very large population of subscribers and ties those records to the Snowflake compromise confirmed in April.
  • Fort Cavazos command: The case documents a member of active duty personnel conducting illicit cyber operations from base barracks — purchasing equipment against orders and using VPNs to mask activity — raising internal-security and supervision questions explicitly tied to behavior on base.
  • Law enforcement and prosecutors: The case resulted in a prison sentence, restitution and guilty pleas for at least two defendants, but also leaves at least one alleged co-conspirator not in U.S. custody and traces of billions of stolen records and multi-million-dollar extortion payments that prosecutors say were exchanged.

Officials framed the sentencing as both punishment and deterrent. Charles Neil Floyd, first assistant attorney for the U.S. District Court for the Western District of Washington, said the sentence “must impose real consequences to deter him, and hopefully other would-be hackers.” W. Mike Herrington, special agent in charge of the FBI Seattle field office, called it “especially shocking that a member of our armed forces, sworn to defend Americans and their constitutional rights, would engage in such a violation of privacy.”

The case ties together military access, bespoke credential-theft tooling, a large commercial-cloud compromise, high-profile data exposures and multi-million-dollar extortion schemes. With one defendant sentenced, restitution ordered and at least one co-conspirator still not in U.S. custody, prosecutors have closed one chapter while the scale of stolen records and the full recovery of extortion proceeds remain elements the filings identify but do not resolve.

Source: CyberScoop — Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies