Ex-Soldier Sentenced to 6 Years for Telecom Hacking and Extortion

Cameron John Wagenius, a 22-year-old former U.S. Army soldier who operated online as “kiberphant0m,” was sentenced Friday to 70 months in federal prison for orchestrating a telecom hacking and extortion campaign that targeted major corporations and sought at least $1 million in ransoms, according to the U.S. Department of Justice.

Federal Sentencing Details Restitution and Prison Term

U.S. authorities confirmed that Wagenius, most recently stationed in Texas, received his 70-month sentence on Friday after pleading guilty to multiple federal charges. In addition to the nearly six-year prison term, the court ordered him to pay $294,978 in restitution. Assistant Attorney General A. Tysen Duva stated that Wagenius targeted U.S. and foreign telecommunications companies, compromised sensitive data belonging to countless individuals, and attempted to traffic stolen information to a foreign intelligence service.

The Snowflake Breach and Telecom Extortion Methods

The case is tied to a broader wave of data thefts in 2024 involving Snowflake, a cloud storage service where businesses store large amounts of data. According to prosecutors, hackers used stolen login credentials to access customer accounts that lacked multifactor authentication. Wagenius and his co-conspirators obtained login credentials for at least 10 organizations between April 2023 and December 2024 using a custom tool called SSH Brute, which Wagenius helped develop. They coordinated attacks via Telegram chats, demanded private payouts, and threatened to expose stolen data on cybercrime forums like BreachForums and XSS.is, while also engaging in SIM-swapping fraud.

Did you know? The 2024 Snowflake data breaches impacted numerous major corporations, including AT&T, which disclosed that hackers stole records of calls and texts involving nearly all of its cellular customers over a six-month period in 2022.

Stolen Call Logs and Political Figures

Wagenius drew intense scrutiny in December 2024 when cybersecurity journalist Brian Krebs reported that the “kiberphant0m” account posted what it claimed were AT&T call logs associated with then-President-elect Donald Trump and Vice President Kamala Harris. The Justice Department reported that Wagenius published two posts in November 2024 disclosing confidential call records belonging to a government official and family members of a former official, though those individuals were not publicly identified. Charles Neil Floyd, first assistant U.S. attorney for the Western District of Washington, noted that Wagenius was motivated not only by financial gain but also by a desire to achieve status within criminal hacking communities.

Guilty Pleas and Legal Timeline

Court filings show a structured progression of legal accountability for the young soldier. Wagenius pleaded guilty in March 2025 to two counts of unlawfully transferring confidential phone records. He later entered additional guilty pleas in July 2025 to conspiracy to commit wire fraud, extortion in relation to computer fraud, and aggravated identity theft. Federal prosecutors also linked his prosecution to the related cases of alleged hackers Connor Riley Moucka and John Erin Binns.

Ex-Soldier Sentenced to 6 Years for Telecom Hacking and Extortion
Photo: bnonews.com

Frequently Asked Questions

What was Cameron John Wagenius’s online alias?

He operated online under the nickname “kiberphant0m.”

How long is Wagenius’s prison sentence?

He was sentenced to 70 months in federal prison, alongside an order to pay $294,978 in restitution.

What hacking tool was used in the conspiracy?

Prosecutors stated the group utilized a hacking tool called SSH Brute, which Wagenius helped develop, to target corporate networks.

What charges did Wagenius plead guilty to?

He pleaded guilty to conspiracy to commit wire fraud, extortion in relation to computer fraud, aggravated identity theft, and two counts of unlawfully transferring confidential phone records.


U.S. Army Soldier Pleads Guilty to Extorting Tech & Telecom Firms | Weekly Cybersecurity Update

Leave a Comment