The news
Cameron Wagenius, a former U.S. Army soldier who hacked and extorted telecommunications companies while on active duty, was sentenced on September 25, 2026 to 70 months in federal prison, the Justice Department said.
U.S. District Judge Lauren King imposed the sentence, The Register reported. The case was prosecuted in the Western District of Washington, according to the Justice Department. Wagenius, who used the online alias kiberphant0m, was also ordered to pay $294,978 in restitution, the department said. BleepingComputer reported he also went by cyb3rph4nt0m.
According to court documents cited by BleepingComputer, Wagenius and accomplices targeted at least 10 technology and telecom organizations between April 2023 and December 2024. They used a tool called SSH Brute and other methods to steal login credentials, took data, and then extorted victims privately and on cybercrime forums including BreachForums and XSS.is, threatening to publish stolen records. Wagenius was stationed in South Korea and Texas during that period, The Record and The Register reported.
The group sought at least $1 million in ransom demands and sold some of the stolen data, reports said. The Record reported that prosecutors said Wagenius also tried to sell stolen information to a foreign military intelligence service. SecurityWeek reported that in November 2024 he publicly released confidential call records belonging to a government official while threatening further leaks, and The Register reported that stolen records were used for SIM-swapping fraud, in which criminals hijack a victim's phone number.
Wagenius was arrested in Texas in December 2024. According to the Justice Department, he pleaded guilty on March 5, 2025 to two counts of unlawfully transferring confidential phone records, and on July 15, 2025 to conspiracy to commit wire fraud, extortion in relation to computer fraud and aggravated identity theft. BleepingComputer reported that his co-conspirators, Connor Riley Moucka and John Erin Binns, were tied to the wider 2024 breaches of Snowflake cloud customers that affected AT&T, Ticketmaster and Santander customers. Assistant Attorney General A. Tysen Duva said Wagenius spent more than a year and a half “betraying the trust placed in him as an active duty soldier,” according to the Justice Department's announcement.
The numbers
- Prison sentence
- 70 months
- Restitution ordered
- $294,978
- Organizations targeted
- At least 10
- Ransom sought
- At least $1 million
- Period of criminal activity
- April 2023 to December 2024
Why CEOs should care
For CISOs, the method is the headline. This was not a zero-day campaign; it relied on stolen and brute-forced credentials against systems that accepted them. Security teams should confirm that every internet-facing login, including SSH access and cloud data platforms, requires multifactor authentication, and that credentials found in infostealer logs or leaked on forums are rotated quickly. The link to the Snowflake breaches shows how one weak login at a cloud service can expose a company's most sensitive customer records.
For general counsels and boards, the case shows what extortion looks like in practice: private demands followed by public threats on criminal forums, and data sold even when victims do not pay. Incident response plans should cover how the company will handle a demand, who decides, when law enforcement is contacted and how regulators and customers will be told. The attempted sale to a foreign intelligence service is a reminder that stolen telecom and customer data can carry national security weight.
For HR and security leaders jointly, the fact that the attacker was an active-duty service member underlines insider and personnel risk. People with technical skills and access can turn to crime; monitoring for unusual access and supporting clear reporting channels remain basic controls.
The bigger picture
The sentence closes another chapter in the 2024 wave of data theft from Snowflake customer accounts, which exposed customers of AT&T, Ticketmaster and Santander. BleepingComputer reported that co-conspirator Connor Riley Moucka, a Canadian known online as Judische, pleaded guilty in August 2026, a sign that U.S. authorities are pursuing extortion crews across borders.
Telecom call records are particularly sensitive because they can reveal who officials, executives and journalists communicate with, which is why these breaches drew attention well beyond the cybersecurity community.
What’s next
Watch for sentencing or trial developments involving Wagenius's co-conspirators, for further enforcement tied to the Snowflake breaches, and for whether the full list of victims, which The Register said has not been disclosed, becomes public. Companies that store customer data in cloud platforms should verify that multifactor authentication is enforced on every account, including service and legacy logins.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story






