US soldier gets 70 months in prison for extorting 10 tech, telecom firms

Sep 28, 2026 - 13:30
0 0
US soldier gets 70 months in prison for extorting 10 tech, telecom firms

Prison

A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024.

21-year-old Cameron John Wagenius (also known online as 'kiberphant0m' and 'cyb3rph4nt0m' ) was arrested in Texas in December 2024.

He pleaded guilty in February 2025 to hacking AT&T and Verizon after being charged on two counts of unlawfully transferring confidential phone records, and in July 2025 to multiple counts of aggravated identity theft, conspiracy to commit wire fraud, and extortion related to computer fraud.

According to court documents, while on active duty with the U.S. Army, Wagenius and his accomplices stole login credentials for the victim's networks using the SSH Brute hacking tool he helped develop. They also used Telegram to transfer stolen credentials and plan their attacks.

"After data was stolen, Wagenius and his conspirators extorted the victim organizations both privately and in public forums. The extortion attempts included threats to post the stolen data on cybercrime forums such as BreachForums and XSS.is," the Justice Department said.

"In other instances, conspirators offered to sell stolen data for thousands of dollars via posts on these forums. They successfully sold at least some of this stolen data and also used stolen data to perpetuate other frauds, including SIM-swapping. In total, Wagenius and his co-conspirators attempted to extort at least $1 million from victim data owners."

In addition to the 70-month prison sentence, Wagenius was ordered to pay $294,978 in restitution for hacking into telecom companies' databases, accessing sensitive customer records, and extorting the companies under threat of releasing stolen data unless they paid ransoms.

Two of his accomplices, Connor Riley Moucka (a.ka. "Waifu" and "Judische") and John Erin Binns (aka "irdev" and "j_irdev1337"), were accused in November 2024 of breaching and stealing terabytes of data from more than 165 organizations using the services of Snowflake cloud storage company and demanding ransom payments to delete the stolen information and not leak it online.

Moucka was arrested on October 30, 2024, in Canada at the request of the United States and pleaded guilty to his role in the Snowflake hacking campaign in August 2026.

Data breaches linked to Snowflake attacks affected hundreds of millions of people, customers of AT&T, Ticketmaster, Santander, Los Angeles Unified, QuoteWizard/LendingTree, Pure Storage, Advance Auto Parts, and Neiman Marcus.

After these incidents led to massive data breaches, Snowflake announced it would enforce multi-factor authentication (MFA) and require customers to choose passwords at least 14 characters long.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0

Comments (0)

User