"After data was stolen, Wagenius and his conspirators extorted the victim organizations both privately and in public forums."
Cameron John Wagenius: arrest, pleas and sentence
Cameron John Wagenius, 21, a former U.S. Army soldier who used the online aliases "kiberphant0m" and "cyb3rph4nt0m," was arrested in Texas in December 2024 and has been sentenced to 70 months in prison. Court records cited by the Justice Department show Wagenius pleaded guilty in February 2025 to hacking AT&T and Verizon after being charged on two counts of unlawfully transferring confidential phone records, and in July 2025 he pleaded guilty to multiple counts of aggravated identity theft, conspiracy to commit wire fraud, and extortion related to computer fraud.
In addition to imprisonment, Wagenius was ordered to pay $294,978 in restitution for hacking into telecommunications databases, accessing sensitive customer records, and extorting companies by threatening to release stolen data unless paid.
Scope of the campaign: targets, timeline and demands
According to charging documents, Wagenius and his co-conspirators attacked at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024. The conspirators attempted to extort at least $1 million from victims, sometimes offering stolen data for sale and at other times threatening public leaks on cybercrime forums. Prosecutors say the group successfully sold at least some of the stolen data and used it to commit other frauds including SIM-swapping.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTools and tradecraft: SSH Brute and Telegram
The court filings describe how Wagenius helped develop an SSH Brute hacking tool to steal login credentials for victim networks. Stolen credentials were planned, transferred and coordinated via Telegram, and the conspirators used public cybercrime forums such as BreachForums and XSS.is to threaten publication or to advertise data for sale.
Co-conspirators and the Snowflake-linked breaches
Two accomplices named in related cases—Connor Riley Moucka (also known as "Waifu" and "Judische") and John Erin Binns (aka "irdev" and "j_irdev1337")—were accused in November 2024 of stealing terabytes of data from more than 165 organizations by abusing the services of cloud storage provider Snowflake and demanding ransoms to delete or not leak the information. Moucka was arrested on October 30, 2024, in Canada at the request of the United States, and pleaded guilty to his role in the Snowflake hacking campaign in August 2026.
Breaches linked to the Snowflake incidents affected hundreds of millions of people and included customers of AT&T, Ticketmaster, Santander, Los Angeles Unified, QuoteWizard/LendingTree, Pure Storage, Advance Auto Parts, and Neiman Marcus.
Snowflake's response and immediate security changes
Following the series of incidents tied to abuse of Snowflake services, the company announced it would enforce multi-factor authentication (MFA) for customers and require passwords of at least 14 characters. Those changes were presented publicly by Snowflake after the breaches became known.
What this means for Snowflake customers, telecommunications companies, and security teams
- Snowflake customers: Expect enforced MFA and longer password requirements to be implemented; affected organizations should review access controls and credential protection practices in light of confirmed credential theft and resale.
- Telecommunications companies (AT&T, Verizon and peers): The cases demonstrate successful intrusions into telecom databases and use of that data in downstream frauds like SIM-swapping, underscoring the need to evaluate internal credential management and customer record protections.
- Security teams and incident responders: The mix of a bespoke SSH Brute tool, use of Telegram for coordination, and public extortion on BreachForums and XSS.is illustrates an operational pattern—credential theft, resale, and public shaming/leverage—that security operations should hunt for and block early in an intrusion lifecycle.
The sentencing and associated guilty pleas close one chapter of a multi-pronged criminal campaign that combined custom tooling, cloud-service abuse and public extortion. The record laid out in court filings connects a single actor's development work and hands-on intrusions to broader, high-impact data exposures affecting hundreds of millions of people and major corporate customers. Restitution orders and prison time address the criminality of this specific case; the technical and operational lessons that follow—hardening access, enforcing MFA, and watching for credential resale—will shape how the named victims and their customers respond going forward.




