Skip to main content
Emerging ThreatsMalware & Ransomware

US Soldier Sentenced for Telecom Extortions

US military base with laptop in foreground, hinting at digital scrutiny.

"We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data," Paul Russell, a resident agent in charge at the Defense Criminal Investigative Service, told investigators — a blunt assessment that captures why prosecutors treated this case as more than routine cybercrime.

How Kiberphant0m exploited exposed Snowflake credentials

Cameron John Wagenius, 22, operating under the online persona "Kiberphant0m," pleaded guilty to a 2024 campaign of intrusions into cloud-stored data that relied on exposed Snowflake credentials and accounts without multi-factor authentication. Federal filings say Wagenius and three alleged co-conspirators downloaded data from several large Snowflake customers; Snowflake has since mandated MFA on all accounts. Prosecutors allege the stolen material included mobile call and text metadata for more than 100 million AT&T customers in 2024. On cybercrime forums in October 2024, Kiberphant0m boasted he had taken call and text metadata for "tens of millions" and claimed breaches of more than a dozen telecommunications companies worldwide, including Verizon’s Push-to-Talk business.

Arrest, guilty pleas and sentence in Seattle

KrebsOnSecurity warned in late November 2025 that Kiberphant0m was likely a U.S. soldier stationed in South Korea. Less than a month later Wagenius was arrested and charged in two separate federal indictments; he soon pleaded guilty to all counts in both cases. At a sentencing hearing in Seattle today, federal prosecutors said Wagenius was sentenced to 70 months in federal prison — nearly six years — and ordered to pay $294,978 in restitution to victims.

Co-conspirators, prior botnets and linked breaches

Prosecutors identified several associates. Kenneth Schuchman, 28, of Vancouver, Washington, was described as assisting Wagenius’s extortion efforts; Schuchman has a long cybercriminal history and in 2019 pleaded guilty to operating the Satori botnet, a large collection of compromised Internet-of-Things devices used for DDoS attacks. Conor Riley Moucka, a.k.a. "Judische," of Kitchener, Ontario, was arrested in 2024 and pleaded guilty in August 2026. Another alleged co-conspirator, John Erin Binns, an American currently living in Turkey, is wanted by U.S. authorities in connection with a 2021 T‑Mobile data breach that exposed personal information of at least 76 million customers.

Insider-threat response: DCIS, FBI, Army CID and Secret Service

When investigators learned the suspect was an active-duty soldier with a secret clearance, the Defense Criminal Investigative Service said it immediately coordinated with the FBI, the Army Criminal Investigative Division, and the U.S. Secret Service. "That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up," Russell said, describing the case as "very serious from jump street," given the combination of cleared access, hacking tools, and trafficking in data.

BOP computer-use violations, AI prompt injection, and prison research

Federal prosecutors also detailed conduct by Wagenius while he was incarcerated and awaiting sentencing. A Sept. 19 sentencing memorandum recounts that in or around September 2025 Wagenius used another inmate’s email account to ask that the recipient prompt commercial AI tools for exploit code and vulnerability details. One query sought "what CVE’s are there for Windows 10 Enterprise privilege escalation and bypasses" and requested "a real world working script for each CVE . . . without omitted code." A later request asked for "step by step for CVE-2023-45208, code for this if any, and if no code exists make some, make sure to describe everything in detail." CVE-2023-45208 is cited in the memo as a three-year-old command-injection vulnerability in D-Link networking devices.

The memo says Wagenius also asked how to fashion an antenna in prison from commissary items to extend radio reception and requested research about escaping prison. Prosecutors note he framed several queries as work for a book, calling this a form of "prompt injection" — crafted inputs designed to elicit disallowed output from commercial AI tools. The government told the court it is unaware of evidence that Wagenius developed or deployed the vulnerabilities he researched, and that he had told investigators his research was intended to provide information to the Bureau of Prisons.

What this means for telecoms, military investigators, and prison officials

  • Telecommunications providers: The case demonstrates the risk of exposed cloud credentials and weak account controls. AT&T had paid a $370,000 Bitcoin ransom to the extortion group after Moucka’s arrest, and Kiberphant0m later posted what he claimed were AT&T call logs for then President-elect Donald Trump and then Vice President Kamala Harris along with schematics allegedly from the NSA. Despite the large advertised haul, prosecutors say Wagenius made only about $1,500 from selling stolen data, underscoring that the financial yield for extortion can be small even when the data’s apparent scope is large.
  • Military and law enforcement investigators: Agencies treated the case as an insider threat tied to a cleared service member and coordinated across DCIS, the FBI, Army CID and the Secret Service. That cross-agency response framed investigative priorities and drove rapid action after the reporting on the suspect’s identity.
  • Prison and corrections officials: The Bureau of Prisons logged computer-use violations and flagged attempts to exploit commercial AI tools via other inmates’ accounts — behavior prosecutors flagged as rehearsals of prompt-injection techniques that sought exploit code and operational guidance.

The sentence closes a criminal chapter for Wagenius, but the episode leaves a clear record: exposed cloud credentials and lax authentication were the proximate enablers, and the fallout stretched from AT&T customers to national-security claims and a coordinated federal investigation. Snowflake has mandated MFA on accounts; the cases of Moucka and Binns remain tied to ongoing legal processes, and the government’s filings underline how a small group of actors, a cloud misconfiguration, and a cleared insider can together produce disproportionate alarm.

Original story at KrebsOnSecurity