A former U.S. Army soldier, Cameron John Wagenius, has been sentenced to 70 months in prison for participating in a hacking and extortion campaign which exposed sensitive information and targeted telecommunication companies. According to the U.S. Department of Justice, Wagenius has also been ordered to pay $294,978 in restitution. Wagenius was involved in the cybercrime operation while serving as an active duty military member.
In April 2023 and December 2024, he and other conspirators obtained credentials allowing them to access protected networks belonging to at least ten organizations. The stolen information was then used to extort victims by threatening publication or sale of the data without their payment.
Investigators have stated Wagenius was an online hacker known as “kiberphant0m” and he contributed to the development of the hacking tool SSH Brute, which was used to obtain login credentials.
To exchange stolen credentials and coordinate access to victim networks, the group communicated via Telegram. Additionally, public threats were made on cybercrime forums.
Stolen information was made available for sale on platforms including BreachForums and
Wagenius published two posts in November 2024 that contained stolen non-content call detail records associated with a former US government official and relatives of another former official. As part of the threats, the Justice Department also stated that additional confidential records would be released if a ransom was paid.
One of the posts indicated that the activity may be partly motivated by retaliation for the arrest of another cybercriminal.
There have been several attacks involving major telecommunications companies and other companies. According to cybersecurity researchers, Wagenius' possession of data was related to broader attacks targeting Snowflake customer environments. Several companies were affected by the campaign, including AT&T, Ticketmaster, Advance Auto Parts, and Santander.
Wagenius pleaded guilty in separate proceedings filed in the Western District of Washington in support of the charges.
A conviction for wire fraud, extortion using computers, and aggravated identity theft was obtained in July 2025. Prior to this, he had pleaded guilty to two counts of unlawfully transferring confidential phone records related to the same operation in March 2025. Additionally, Wagenius appears to be tied to the wave of attacks against organizations using Snowflake cloud environments that took place in 2024.
According to AT&T, attackers accessed call and text records covering nearly all of its mobile customers in December 2022. The stolen information was later associated with extortion activity involving several cyber criminals.
Moreover, court records and the investigation report indicate that Wagenius attempted to sell stolen information to an email address he believed was affiliated with a foreign military intelligence service. Moreover, the prosecution alleges that he searched the Internet for information about leaving the United States for Russia.
The intelligence services involved have not yet been publicly identified by the government.
Based on the findings of the investigation, the hacking operation was primarily a result of the use of stolen credentials, rather than an exploit of a specific software vulnerability. The credentials were used by Wagenius and his associates to gain access to company networks and cloud environments, using Telegram to communicate access details and coordinate further intrusions.
After invading victim networks, the group aimed at obtaining data to be monetized.
In some cases, information was provided to other criminals, whereas other records were used for fraud schemes, such as SIM swapping. Additionally, extortion demands were extorted through private communications as well as public postings on cybercrime forums.
The FBI, Defense Criminal Investigative Service, and other law enforcement agencies investigated these activities.
A warrant was issued for Wagenius' arrest in December 2024, bringing to a close the hacking activities he allegedly conducted for more than a year while remaining an active duty soldier.