U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
A U.S. Army soldier, Cameron John Wagenius, 22, was sentenced to 70 months in federal prison after pleading guilty to hacking multiple telecommunications companies and stealing mobile call and text metadata for over 100 million AT&T customers. He was also ordered to pay $294,978 in restitution and acknowledged participating in extortion schemes tied to stolen cloud data from Snowflake accounts in 2024.

Why It Matters
The case highlights risks from exposed cloud credentials and weak account protections that enabled large-scale data theft, and it underscores concerns about insider threats when individuals with military security clearances engage in cybercrime. The investigation involved multiple federal agencies and connected the stolen data to broader extortion activity affecting major telecoms.
Key Facts
- Defendant: Cameron John Wagenius, 22
- Sentence: 70 months in federal prison
- Restitution: $294,978
- Victims affected: More than 100 million AT&T customers (call and text metadata)
- Alias: Kiberphant0m
Cameron John Wagenius, a 22-year-old U.S. Army soldier who admitted to operating under the alias “Kiberphant0m,” received a 70-month federal prison sentence today after pleading guilty to charges related to hacking telecommunications companies and stealing call and text metadata. Prosecutors say the intrusions targeted several large customers of the cloud data storage service Snowflake in 2024, where exposed credentials and lack of multi-factor authentication allowed download of sensitive metadata. Snowflake has since required multifactor authentication on all accounts.
According to charging documents and prosecutors’ filings, Wagenius worked with at least three alleged co-conspirators to exfiltrate data and then extorted victim companies by threatening to publish stolen records. In October 2024 he posted claims on cybercrime forums that he had obtained call and text metadata for tens of millions of AT&T customers and said he had compromised more than a dozen telecom companies worldwide, including targeting Verizon’s Push-to-Talk business. The extortion activity included demands for payment; the record notes AT&T previously paid a $370,000 Bitcoin ransom to the group.
Federal authorities said Wagenius was assisted by Kenneth Schuchman, a 28-year-old from Vancouver, Washington, who has a prior cybercriminal conviction for operating the Satori botnet. Two other alleged co-conspirators remain charged in connection with the Snowflake thefts: Conor Riley Moucka (arrested in 2024 and later pleaded guilty in August 2026) and John Erin Binns, an American living in Turkey who is wanted in a separate 2021 T-Mobile breach.
Investigators from the Defense Criminal Investigative Service, the FBI, the Army Criminal Investigative Division and the U.S. Secret Service worked the case after receiving information suggesting an active-duty soldier with secret clearance was involved. Prosecutors noted in a sentencing memo that Wagenius cooperated with authorities but also attempted, while incarcerated and awaiting sentence, to probe vulnerabilities in Bureau of Prisons systems by using other inmates’ email accounts to prompt commercial AI tools for exploit code and to research escape methods. The government said it is not aware of evidence that he successfully deployed any vulnerabilities against BOP systems.
Keep Reading

DC appeals court sides with Pentagon on blacklist of Anthropic
TikTok agrees to pay at least $100M in Alabama settlement
