US Soldier Sentenced to 70 Months for Extorting Tech and Telecom Companies
A 21-year-old former U.S. Army personnel has been sentenced to 70 months in federal prison for orchestrating cyberattacks and demanding ransom from at least 10 technology and telecommunications companies.
Legal Consequences and Sentencing
Cameron John Wagenius, who operated under the online aliases ‘kiberphant0m’ and ‘cyb3rph4nt0m,’ was apprehended in Texas in December 2024. He admitted guilt in February 2025 for unauthorized access to AT&T and Verizon systems, with additional charges emerging in July 2025, including aggravated identity theft and extortion linked to computer fraud.
Sentencing Details
The court ordered Wagenius to pay $294,978 in restitution for unauthorized access to telecom databases, exposure of sensitive customer data, and ransom demands. The total ransom demands from victims exceeded $1 million.
Cyberattack Methods and Tactics
While serving in the U.S. Army, Wagenius and associates obtained login credentials for targeted networks using a custom-built SSH Brute hacking tool. They coordinated operations through Telegram, sharing stolen data and planning attacks. The Justice Department stated that stolen information was leveraged to blackmail companies through private communications and public cybercrime platforms.
Extortion Tactics
Extortion tactics involved threats to publish data on forums like BreachForums and XSS.is, as well as offering stolen information for sale at high prices. At least部分 of the data was successfully sold, with proceeds used to facilitate further fraudulent activities such as SIM-swapping.
Impact on Organizations
The breaches impacted hundreds of millions of individuals, affecting customers of AT&T, Ticketmaster, Santander, Los Angeles Unified, QuoteWizard/LendingTree, Pure Storage, Advance Auto Parts, and Neiman Marcus. Snowflake implemented mandatory multi-factor authentication and enforced password requirements of at least 14 characters for all users.
Co-Conspirators and Charges
Two co-conspirators, Connor Riley Moucka (also known as “Waifu” and “Judische”) and John Erin Binns (alias “irdev” and “j_irdev1337”), faced separate charges for breaching systems at over 165 organizations via Snowflake cloud storage. Moucka was detained in Canada in October 2024 under U.S. extradition and pleaded guilty in August 2026 to his role in the Snowflake-related cyberattacks.
“The stolen information was leveraged to blackmail companies through private communications and public cybercrime platforms,” according to the Justice Department.
Response and Preventive Measures
Snowflake implemented mandatory multi-factor authentication and enforced password requirements of at least 14 characters for all users. The breaches highlighted vulnerabilities in cloud storage systems, prompting organizations to enhance cybersecurity protocols.
