Former Army Soldier Sentenced to 70 Months for Cyber Attacks on AT&T and Snowflake

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

A former Army soldier, Cameron John Wagenius, has been sentenced to 70 months in prison for a series of cyber attacks and extortion attempts targeting major telecom companies, including AT&T. The Justice Department announced the sentencing on Friday, highlighting Wagenius’s extensive cybercrime activities that spanned several years, even while he was on active duty at a Texas military base. Prior to his arrest in December 2024, he attempted to sell stolen sensitive data to a foreign intelligence service and sought information about defecting to Russia.

According to reporting by CyberScoop, Wagenius leaked call records of former President Donald Trump during multiple failed extortion attempts aimed at securing $500,000 from AT&T. Authorities revealed that he disclosed non-content call detail records belonging to a government official and family members of another official. In July, AT&T confirmed that cybercriminals had accessed its Snowflake environment, resulting in the theft of six months’ worth of phone and text records for nearly all its customers.

Wagenius and his co-conspirator, Connor Moucka, attempted to extort over ten organizations after breaching cloud platforms used by AT&T and other major companies. Moucka, who was extradited to the U.S. in March 2025, pleaded guilty in August to his role in one of the most extensive cyberattacks of 2024, which compromised over 165 Snowflake customer environments.

Prosecutors indicated that Wagenius, Moucka, and another alleged co-conspirator, John Erin Binns, who remains at large, collectively stole billions of sensitive records and received over $2.5 million in extortion payments. Victims included AT&T, Ticketmaster, Advance Auto Parts, and Santander. At the time of his arrest, Wagenius possessed records stolen during the Snowflake attack spree and was involved in extortion attempts totaling more than $1 million.

Wagenius was ordered to pay nearly $295,000 in restitution. Officials noted that his hacking activities were driven not only by financial gain but also by a desire for status within criminal hacking communities. The FBI expressed particular concern over the actions of a member of the armed forces engaging in such violations of privacy.

During the investigation, law enforcement discovered that Wagenius had access to thousands of stolen identification documents and significant amounts of cryptocurrency. He reportedly purchased a new laptop against orders from his commanding officer and used it daily while attempting to conceal his identity with VPN software.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

F5 Issues Advisory for CVE-2026-94127, Critical RCE Vulnerability in BIG-IP APM

Critical RCE Vulnerability in F5 BIG-IP APM: CVE-2026-94127 On September 22, 2026, F5 Networks issued a security advisory regarding CVE-2026-94127, a critical heap-based buffer overflow...

Unit 42 Experts Address Common Cybersecurity Myths and Misconceptions

In the ever-evolving landscape of cybersecurity, misconceptions can lead organizations to adopt ineffective strategies that leave them vulnerable to attacks. Insights from Unit 42...

Storm-3168 Threat Actor Exploits Compromised Service Principals for Destructive Azure Attacks

Microsoft Security Research has identified malicious cloud activity associated with JADEPUFFER, a threat actor discovered by Sysdig in July 2026 and reported to be...

CWME_REVIEW_REQUIRED

The 2026-2027 Dream with Us Design Challenge, organized by NASA, invites middle and high school students to participate in a project focused on the...