Cameron John Wagenius, a 22-year-old U.S. Army soldier formerly stationed in South Korea, has been sentenced to 70 months in federal prison following his role in a sophisticated cybercriminal enterprise that compromised the metadata of over 100 million AT&T customers. Beyond the custodial sentence handed down in a Seattle federal court, Wagenius has been ordered to pay approximately $294,978 in restitution. His conviction marks the culmination of a high-stakes investigation into an insider threat that rattled both the telecommunications industry and national security apparatus.
Operating under the pseudonym Kiberphant0m, Wagenius leveraged his technical expertise to exploit vulnerabilities in cloud-based data storage infrastructure. His activities, which spanned multiple continents and involved a network of digital co-conspirators, highlighted the acute risks posed when advanced hacking capabilities are combined with privileged access and a lack of stringent security protocols at the corporate level.
A Chronology of Cyber-Extortion
The timeline of Wagenius’s criminal activities began to surface in 2024, a year defined by significant breaches of Snowflake cloud storage accounts. By failing to mandate multi-factor authentication (MFA) across all client instances, these accounts became prime targets for threat actors. Wagenius and his associates systematically identified accounts with exposed credentials, gaining unauthorized access to vast repositories of sensitive information.
In October 2024, the scope of the threat became clear when the Kiberphant0m persona began broadcasting claims of success on various cybercrime forums. He boasted of harvesting call and text metadata—including timestamps, durations, and source/destination identifiers—for tens of millions of AT&T subscribers. His operations were not limited to a single entity; he claimed to have breached more than a dozen telecommunications firms globally, including the Push-to-Talk business division of Verizon.
The investigation intensified in November 2024, when security researchers at KrebsOnSecurity published analysis suggesting that the individual behind the Kiberphant0m handle was likely an active-duty U.S. soldier based in South Korea. This revelation accelerated inter-agency cooperation between the FBI, the U.S. Secret Service, and the Army Criminal Investigative Division (CID). By December 2024, Wagenius was in custody, facing two separate federal indictments. He ultimately entered guilty pleas to all charges, leading to the sentencing proceedings that concluded this week.
The Network of Conspirators
Wagenius did not act in isolation. Federal prosecutors detailed a collaborative effort involving several individuals with established histories in the cybercrime underground. Key among them is Kenneth Schuchman, a 28-year-old from Vancouver, Washington. Schuchman’s criminal record dates back to at least 2019, when he pleaded guilty to operating the Satori botnet, a massive collection of compromised Internet-of-Things (IoT) devices used to facilitate large-scale distributed denial-of-service (DDoS) attacks.
Other co-conspirators remain entangled in the legal system. Conor Riley Moucka, known by the alias Judische, was arrested in 2024 and pleaded guilty in August 2026. John Erin Binns, an American national currently residing in Turkey, remains a figure of significant interest to federal investigators. Binns is also a primary suspect in the 2021 T-Mobile data breach, which compromised the personal records of at least 76 million individuals. The persistence of these actors underscores the transnational nature of modern digital crime, where jurisdictional boundaries often hinder swift prosecution.
National Security Implications
The gravity of the Wagenius case was amplified by his attempts to leverage stolen information for political and national security-related leverage. Following the arrest of his associate, Moucka, and despite having already received a $370,000 Bitcoin ransom payment from AT&T, the Kiberphant0m persona resorted to aggressive re-extortion tactics.
In a move that drew immediate attention from the Department of Defense, the group published what they alleged to be call logs belonging to then-President-elect Donald Trump and then-Vice President Kamala Harris. Furthermore, they threatened to leak sensitive schematics allegedly purloined from the National Security Agency (NSA).
Paul Russell, the resident agent in charge at the Defense Criminal Investigative Service (DCIS), emphasized the rarity and severity of the threat. "We don’t often get leads where there’s an active duty soldier with a secret clearance who is creating hacking tools and trafficking in data," Russell stated. The involvement of an insider with security clearance forced a rapid mobilization of federal agencies, as the risk of classified information exposure necessitated an emergency-level response.
Incarceration and Continued Digital Risk
Perhaps the most startling aspect of the case emerged during the sentencing phase. Despite being incarcerated and awaiting his day in court, Wagenius allegedly continued his efforts to explore cyber vulnerabilities. A sentencing memo filed by federal prosecutors in September 2025 revealed that Wagenius exploited the Bureau of Prisons (BOP) email system to interact with commercial artificial intelligence tools.
Using the accounts of fellow inmates, Wagenius issued prompts designed to bypass the safety guardrails of AI models. He requested specific information regarding privilege escalation vulnerabilities in Windows 10, step-by-step instructions for exploiting the CVE-2023-45208 vulnerability in D-Link networking hardware, and even methods for constructing improvised antennas to enhance radio reception within a prison environment.
Prosecutors noted that Wagenius utilized a technique known as "prompt injection," framing his requests as research for a book he claimed to be writing. While the government found no evidence that he successfully deployed these exploits within the BOP infrastructure, the incident served as a stark reminder of the persistent threat posed by skilled cyber-actors, even while in state custody.
Broader Impact and Industry Response
While the damage caused to individual privacy and corporate reputation was immense, the financial gain for the perpetrators was remarkably low. The sentencing memo noted that Wagenius earned a total of approximately $1,500 from the sale of stolen data—a figure that pales in comparison to the millions of dollars in remediation and security upgrades forced upon the affected telecommunications companies.
The fallout from these breaches has necessitated a fundamental shift in how corporations manage cloud security. Snowflake, the platform at the center of the initial access, has since mandated multi-factor authentication for all users, closing the security gap that allowed the initial compromises to occur.
For the U.S. military, the case has prompted a reassessment of internal monitoring protocols. The "insider threat" posed by a soldier with high-level clearance using military resources to facilitate global cyber-extortion has forced the Department of Defense to tighten oversight of technical personnel. As digital threats continue to evolve, the case of Cameron Wagenius serves as a cautionary tale for both the private sector and government entities regarding the necessity of robust authentication, continuous monitoring, and the dangers of underestimating the persistence of motivated individual actors within a larger criminal ecosystem.
The 70-month sentence reflects not just the theft of data, but the calculated intent to disrupt the lives of millions and the reckless disregard for national security that defined the short, albeit destructive, criminal career of Kiberphant0m.
