U.S. Soldier Sentenced to 70 Months for Hacking AT&T and Verizon, Stealing Data of Over 100 Million Customers

Published:

A U.S. Army soldier has been sentenced to 70 months in federal prison for hacking into telecommunications companies and stealing mobile call and text metadata for over 100 million AT&T customers. Cameron John Wagenius, 22, was also ordered to pay nearly $300,000 in restitution to victims. His actions included extorting multiple companies, including Verizon, and he operated under the cybercriminal alias “Kiberphant0m.”

According to reporting by KrebsOnSecurity, Wagenius was stationed at a U.S. Army base in South Korea when he collaborated with co-conspirators to download sensitive data from clients of the cloud storage service Snowflake, which had vulnerabilities due to a lack of multi-factor authentication.

Criminal Activities and Arrest

In October 2024, Wagenius boasted on cybercrime forums about stealing call and text metadata from tens of millions of AT&T customers. He claimed to have hacked into numerous telecommunications companies worldwide and extorted them for not publishing the stolen data. Following a warning from KrebsOnSecurity in late November 2025, he was arrested less than a month later and charged in two federal indictments.

Sentencing and Further Investigations

At his sentencing hearing in Seattle, Wagenius received nearly six years in prison and was ordered to pay $294,978 in restitution. Federal prosecutors noted that he was assisted by Kenneth Schuchman, a man with a history of cybercrime, and that two other alleged co-conspirators are still facing charges related to the Snowflake data thefts.

Wagenius also attempted to find security vulnerabilities in the Bureau of Prisons’ computer network while incarcerated, raising concerns about his insider threat potential. Despite the significant data he stole, his extortion efforts reportedly yielded only about $1,500.

While Wagenius cooperated with authorities, the case highlights the serious implications of insider threats within military ranks and the ongoing challenges in securing sensitive data against cybercriminal activities.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

CrowdStrike recognized as leader in Forrester Wave for proactive security platforms

CrowdStrike has been recognized as a Leader in The Forrester Wave: Proactive Security Platforms, Q3 2026, achieving the highest score in the Strategy category...

Microsoft tracks Storm-2570’s consistent tactics across multiple ransomware deployments

Microsoft has identified Storm-2570, a ransomware affiliate, as a significant threat actor employing consistent tactics across various ransomware deployments, including Qilin, DragonForce, Anubis, and...

Citrix NetScaler ADC and Gateway products affected by multiple critical CVEs

Citrix has disclosed multiple critical vulnerabilities affecting its NetScaler ADC and Gateway products, with at least two of these vulnerabilities, CVE-2026-88771 and CVE-2026-88772, reportedly...

AI is transforming product team dynamics, says Muhammad Danish

Artificial intelligence (AI) is fundamentally transforming product team dynamics, according to Muhammad Danish, Senior Director of Product Design at Emirates NBD. He highlights that...