AT&T
Cameron John Wagenius was sentenced to 70 months in federal prison for breaching a handful of telecommunications companies, including AT&T. Credit: Brendan Stephens / Unsplash

Former US soldier gets nearly six-year sentence for hacking, extorting telecoms

A former soldier in the U.S. Army was sentenced to more than five years in federal prison after pleading guilty to hacking into several telecommunications companies and leaking sensitive records. 

Cameron John Wagenius, 22, was handed a 70-month sentence and is ordered to pay nearly $295,000 in restitution. 

Wagenius was an active duty soldier stationed in South Korea and at Fort Cavazos in Texas when he conducted the hacks between April 2023 and December 18, 2024. He worked with two other hackers to steal thousands of sensitive call records, according to court documents.

Wagenius initially pleaded guilty to two separate but related charges centered around posting confidential phone records to an online forum and sending the records through a platform. He later pleaded guilty in a Seattle federal court to wire fraud, extortion and aggravated identity theft. 

He attempted to extort multiple U.S.-based telecommunications companies after obtaining login credentials and breaching their systems. Wagenius and several others sought at least $1 million in ransoms for the stolen data.

Assistant Attorney General A. Tysen Duva noted that he “even sought to traffic stolen information to a foreign intelligence service.” 

“Cameron Wagenius spent more than a year and a half betraying the trust placed in him as an active duty soldier by carrying out a sweeping cybercrime campaign,” Duva said. “His actions reflect an alarming disregard for the security of the public and the United States.”

The Justice Department said he made two online posts in November 2024 claiming to have “confidential non-content call detail records belonging to a government official and family members of another former official and threatened to release additional confidential records unless paid a ransom.”

The case was tied to a spate of attacks in 2024 targeting more than 100 customers of data storage giant Snowflake, including AT&T. Cybersecurity experts cited by the Justice Department last year said Wagenius allegedly leaked call logs from AT&T belonging to President Donald Trump.

The AT&T breach involved metadata stolen through Snowflake that included nearly all call logs and texts made by the company’s customers over a six-month period in 2022. 

Under the username “kiberphant0m,” Wagenius worked with others to breach at least 10 organizations using a tool he created called “SSH Brute.”

Prosecutors said Wagenius and his crew “gained unlawful access to hundreds of thousands of sensitive business and customer records, including non-content call and text history records, telecommunication identifying information, and other personally identifiable information.”

Once the data was stolen and exfiltrated, Wagenius and others extorted the organizations in both public and private settings. He made posts on cybercrime forums such as BreachForums and XSS.is to market the stolen data. 

Court documents showed Wagenius successfully sold at least some of the stolen data and also used stolen data to carry out other fraud, including SIM-swapping. 

In November 2024, Wagenius contacted an email address he believed belonged to an unidentified country’s military intelligence service in an effort to sell the information he stole. 

Prosecutors obtained Google searches made by Wagenius that included “can hacking be treason,” “where can i defect the u.s government military which country will not hand me over,”  “U.S. military personnel defecting to Russia” and “Embassy of Russia – Washington, D.C,” and “how to get passport fast.”

Three unnamed co-conspirators were named in the court documents, including one based in Washington state and another in Canada. 

One of the court documents for Wagenius’ charges references a “related case” involving Connor Riley Moucka and John Erin Binns — two other hackers implicated in the theft of Snowflake data and previous targeting of telcos like AT&T and T-Mobile. 

Moucka agreed to be extradited to the U.S. from Canada and pleaded guilty last month.

Binns was detained by Turkish authorities in May 2024 after being indicted for his role in a previous hack of T-Mobile.

Recorded Future
No previous article
No new articles
Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.