Ex-Soldier Sentenced to 70 Months for Data Theft Involving AT&T and Snowflake

www.news4hackers.com-ex-soldier-sentenced-to-70-months-for-data-theft-involving-at-t-and-snowflake-ex-soldier-sentenced-to-70-months-for-data-theft-involving-at-t-and-snowflake

Ex-US soldier receives 70-month sentence for involvement in data breaches targeting AT&T and Snowflake

Sentencing and Restitution

A former U.S. Army personnel was sentenced to 70 months in prison for participating in a cybercrime operation that compromised data from telecommunications providers and cloud storage services. Cameron John Wagenius, 22, was part of a group that infiltrated Snowflake customer accounts in 2024, stealing information from over 165 organizations using the cloud data storage and analytics platform. The perpetrators threatened to release the data unless victims paid ransom demands. Snowflake, a U.S.-based company with more than 13,000 global clients, became a focal point of the scheme. Wagenius was also ordered to pay $294,978 in restitution for his role in the crimes.

The Cybercrime Operation

The defendant conspired to breach telecommunications companies’ databases, access confidential records, and demand payments by threatening to expose the stolen information. According to the Justice Department, Wagenius exploited his position as an active-duty soldier to execute a large-scale cyberattack. He targeted both U.S. and international telecom firms, compromising personal data and attempting to sell the information to a foreign intelligence agency.

According to the Justice Department, Wagenius exploited his position as an active-duty soldier to execute a large-scale cyberattack.

Military Role and Exploitation

Court records indicate that between April 2023 and December 18, 2024, Wagenius operated under the online alias kiberphant0m, collaborating with others to defraud at least 10 organizations. The group obtained login credentials for protected networks using a custom hacking tool called SSH Brute, which Wagenius contributed to developing. They communicated through Telegram group chats to exchange stolen data and coordinate access to victim systems.

Tools and Techniques

The attacks involved unauthorized entry into corporate networks, with the stolen data later used for extortion and other fraudulent activities. Wagenius and his co-conspirators threatened to publish the information on cybercrime forums such as BreachForums and XSS.is, or sell it for substantial sums. At least some of the stolen data was sold, while portions were repurposed for schemes like SIM-swapping. The total ransom demands across the operation exceeded $1 million.

FBI Statement and National Security Concerns

The FBI highlighted the severity of Wagenius’s actions, noting that his conduct violated the trust placed in military personnel. Special Agent in Charge W. Mike Herrington stated that the defendant’s crimes posed a significant threat to privacy and national security.

Special Agent in Charge W. Mike Herrington stated that the defendant’s crimes posed a significant threat to privacy and national security.

Data Disclosure and Retaliation Threats

In November 2024, Wagenius disclosed stolen call detail records belonging to a government official and family members of another former official. The records contained metadata about calls but not their content. He threatened to release additional data unless he received payment, with one online post suggesting retaliation for the arrest of another cybercriminal.

Co-Conspirator and Legal Proceedings

Another individual linked to the Snowflake breaches, Connor Riley Moucka of Canada, pleaded guilty in August and is scheduled for sentencing on October 27.

Case Significance and Legal Consequences

The case underscores the growing risks posed by insider threats and the exploitation of military personnel for cybercriminal activities. The Justice Department emphasized that Wagenius’s actions demonstrated a deliberate disregard for his duty to protect national interests. The sentencing reflects the legal consequences for individuals who leverage their positions to facilitate large-scale data theft and extortion.



About Author

en_USEnglish