Technology

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

Krebs on Security September 25, 2026 3 views
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

Advertisement

Cameron John Wagenius, a 22-year-old U.S. Army soldier stationed in South Korea, was sentenced today to 70 months in federal prison and ordered to pay nearly $300,000 in restitution for hacking into major telecommunications companies and extorting them with stolen customer data. The Seattle-based sentencing concludes a federal investigation into Wagenius, who operated under the cybercriminal alias “Kiberphant0m,” for stealing mobile call and text metadata belonging to more than 100 million AT&T customers in 2024.

According to federal prosecutors, Wagenius exploited exposed credentials and the lack of multi-factor authentication on the cloud data storage service Snowflake to access sensitive information. He claimed to have compromised over a dozen telecommunications firms globally, including Verizon’s Push-to-Talk business, and publicly threatened to publish the stolen data unless the companies paid ransoms. In October 2024, Kiberphant0m bragged on cybercrime forums about the theft of tens of millions of AT&T customer records, which included source and destination numbers, timestamps, and call durations.

The investigation gained momentum in late November 2025 when KrebsOnSecurity reported that Kiberphant0m was likely a U.S. soldier in South Korea. Wagenius was arrested and charged in two separate federal indictments less than a month later, eventually pleading guilty to all counts. Prosecutors identified Kenneth Schuchman, a 28-year-old from Vancouver, Washington, as a key assistant in the extortion scheme. Schuchman has a prior cybercriminal history, having pleaded guilty in 2019 to operating the Satori botnet, which was used for large-scale distributed denial-of-service attacks.

Two other alleged co-conspirators remain involved in the case. Conor Riley Moucka, also known as “Judische,” was arrested in 2024 and pleaded guilty in August 2026. John Erin Binns, an American resident of Turkey, is also facing charges; he is separately wanted for a 2021 data breach at T-Mobile that exposed the personal information of at least 76 million customers. Following Moucka’s arrest, Kiberphant0m allegedly re-extorted victims and posted what he claimed were call logs for then-President-elect Donald Trump and then-Vice President Kamala Harris, along with schematics allegedly stolen from the National Security Agency.

“We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data,” said Paul Russell, a resident agent in charge at the Defense Criminal Investigative Service. “That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with.”

Despite his cooperation with authorities, prosecutors noted that Wagenius continued to engage in cyber activities while incarcerated. A sentencing memo revealed that in September 2025, while awaiting sentencing at the Bureau of Prisons, Wagenius used other inmates’ email accounts to query commercial AI tools for information on security vulnerabilities, including Windows 10 privilege escalation exploits and D-Link command injection flaws. He also requested instructions on building an antenna in a prison environment to extend radio reception and asked for research on escaping prison.

Federal prosecutors stated that Wagenius framed these AI queries as part of a book he was writing, a technique known as “prompt injection” used to bypass safety filters in AI tools. The investigation was a joint effort involving the Defense Criminal Investigative Service, the FBI, the Army Criminal Investigative Division, and the U.S. Secret Service, highlighting the severity of the insider threat posed by an active-duty soldier with security clearance.

<small>Source: Krebs on Security — read the original story there.</small>

How did this make you feel?

Never miss a story

Get the best of SpeakOX in your inbox. No spam, unsubscribe anytime.

Advertisement

Category
Technology

Advertisement