Army hacker Kiberphant0m lands 70 months for telecom extortion

A US soldier who stole call records from AT&T and others as the persona Kiberphant0m was sentenced to 70 months and $295,000 in restitution.

CSBadmin
2 Min Read

A former US Army soldier who ran an extortion spree from his base was sentenced in Seattle to 70 months in prison and ordered to pay $294,978 in restitution. Cameron John Wagenius, 22, pleaded guilty in July 2025 to the attacks carried out under the handle Kiberphant0m.

Prosecutors said Wagenius and co-conspirators pulled data from Snowflake customers whose credentials had leaked and who had not enforced multi-factor authentication. In October 2024 he claimed to have taken call and text metadata for tens of millions of AT&T customers, bragging on cybercrime forums and demanding payment to stay quiet. He is also tied to attacks on Verizon’s push-to-talk business and attempts to extort more than ten organisations.

Stolen records, a foreign buyer, and a Russia inquiry

Among the records he exposed were call logs for then President-elect Donald Trump. Investigators said Wagenius tried to sell stolen data to a foreign intelligence service and searched online for ways to defect to Russia before his December 2024 arrest.

His alleged collaborators include Conor Riley Moucka, who pleaded guilty in August 2026 to compromising more than 165 Snowflake customer environments, and John Erin Binns, who remains outside US custody. Kenneth Schuchman, who once pleaded guilty to running the Satori botnet, is named as an accomplice in the extortion attempts.

The case shows how far a single insider with a secret clearance and cloud credentials can reach, and why multi-factor authentication on data platforms is not optional.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.