Army soldier gets nearly six years for AT&T metadata theft and extortion scheme

 September 26, 2026

A U.S. Army soldier with a secret clearance was sentenced to 70 months in federal prison for hacking telecom firms and stealing call and text metadata for more than 100 million AT&T customers, an insider case that pulled in multiple federal agencies.

Cameron John Wagenius, 22, was sentenced in Seattle and ordered to pay $294,978 in restitution to victims after pleading guilty to hacking multiple telecommunications companies and stealing mobile call and text metadata tied to more than 100 million AT&T customers in 2024.

KrebsOnSecurity reported that Wagenius operated under the online persona “Kiberphant0m,” worked with alleged co-conspirators, and downloaded data from Snowflake cloud customers that had left credentials exposed and failed to enforce multi-factor authentication.

Federal prosecutors said he intended to cause serious harm even though his own extortion take was small. The case also showed how a soldier with access and clearance became an active cyber threat while stationed overseas.

Secret clearance, South Korea base, and a cybercrime persona

Wagenius was stationed at a U.S. Army base in South Korea when he used the “Kiberphant0m” identity. He had a secret clearance. That combination turned a data-theft case into an insider-threat investigation almost immediately.

Defense Criminal Investigative Service resident agent in charge Paul Russell described the reaction when investigators learned an active-duty soldier was allegedly building hacking tools and trafficking in stolen data.

"We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data. That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with."

DCIS worked the case with the FBI, Army Criminal Investigative Division, and the U.S. Secret Service. The joint response reflected the stakes: a cleared service member accused of stealing mass telecom metadata and trying to monetize it.

Accountability inside the ranks remains a live issue for the force, including Army discipline and complaint policy changes aimed at tightening standards and cutting abuse of process.

AT&T metadata, a Bitcoin ransom, and forum bragging

In 2024, Wagenius’s activity included the theft of mobile call and text metadata for more than 100 million AT&T customers. In October 2024, the Kiberphant0m persona bragged on cybercrime forums about stealing call and text metadata for tens of millions of AT&T customers.

He claimed hacks of more than a dozen telecommunications companies worldwide, including Verizon’s Push-to-Talk business. Prosecutors later said his extortion efforts largely failed and that he made around $1,500 selling stolen data.

AT&T still paid a $370,000 Bitcoin ransom to the extortion group. After alleged co-conspirator Conor Riley Moucka’s 2024 arrest, and after that ransom payment, Kiberphant0m posted what he claimed were AT&T call logs for then President-elect Donald Trump and then Vice President Kamala Harris, along with alleged National Security Agency schematics.

Those posts raised the pressure. Late in November 2025, KrebsOnSecurity warned that Kiberphant0m was likely a U.S. soldier stationed in South Korea. Less than a month later, Wagenius was arrested and charged in two separate federal indictments. He pleaded guilty to all counts in both cases soon after.

Military personnel decisions have drawn heavy scrutiny in recent months, from Pentagon moves blocking Army officers from promotion to broader leadership shakeups meant to reset standards.

Snowflake gaps and the path into the data

The theft route ran through weak corporate security. Large Snowflake customers had exposed credentials and did not require multi-factor authentication. Attackers used those openings to download customer data. Snowflake has since mandated multi-factor authentication on all accounts.

That sequence is familiar: a vendor platform, customers slow to lock down access, and criminals ready to harvest whatever sits behind a weak login. The harm landed on phone customers, companies, and investigators who then had to unwind the damage.

Prosecutors put the point directly in their sentencing memo.

"While Wagenius was not particularly financially successful as a cybercriminal, he both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government."

The memo also noted that Wagenius pleaded guilty almost immediately and had been remarkably cooperative. Cooperation did not erase the scale of the intrusion or the threats that followed.

Co-conspirators across borders

Kenneth Schuchman, 28, of Vancouver, Washington, assisted in efforts to extort victim companies. In 2019 he pleaded guilty to operating the Satori botnet used for large-scale distributed denial-of-service attacks.

Conor Riley Moucka, also known as “Judische,” of Kitchener, Ontario, was arrested in 2024 and pleaded guilty in August 2026. John Erin Binns, an American living in Turkey, still faces charges tied to the Snowflake data thefts and is wanted in connection with a 2021 T-Mobile breach that exposed personal information of at least 76 million customers.

The roster shows a mix of U.S. and foreign actors, prior botnet crime, and unfinished cases still hanging over major carriers. Wagenius’s role as a cleared soldier made his piece of the network especially dangerous.

Force management at the top of the Army has been in flux as well, including the departure of a top Army commander in Europe amid Pentagon personnel changes.

Jail emails, AI prompts, and prison-yard research

While locked up awaiting sentencing, Wagenius kept probing systems. Bureau of Prisons records described in the government’s Sept. 19 sentencing memo show that in or around September 2025 he used another inmate’s email system to have a recipient prompt a commercial AI tool for hacking material.

He sought information on Windows 10 Enterprise privilege-escalation CVEs and “a real world working script for each CVE... without omitted code.” He asked for step-by-step detail and code for CVE-2023-45208, a command-injection flaw in D-Link networking devices, and told the tool that if no code existed it should “make some.”

He also asked how to build an antenna in a prison environment with commissary or other readily available items to extend radio reception. Prosecutors said he requested research on escaping prison as well.

In several instances he framed the AI queries as research for a book he was writing. Prosecutors called that a common “prompt injection” tactic meant to bypass safety limits on commercial AI tools that are supposed to refuse malicious code requests.

When questioned, Wagenius said he was only researching “potential vulnerabilities to provide information to the BOP.” The government said it found no evidence he figured out how to use or deploy the vulnerabilities he was studying in Bureau of Prisons systems. The attempts still violated BOP computer-use rules and showed the same pattern that put him in custody in the first place.

Civilian leadership over the Army has shifted too, with Trump installing an acting Army secretary outside the usual succession line as the department reworks personnel control.

Seventy months and a bill for the damage

At the Seattle hearing, the court imposed 70 months in federal prison and $294,978 in restitution. Prosecutors had filed their sentencing memo on Sept. 19, laying out the guilty pleas, the limited $1,500 haul from data sales, the AT&T ransom paid by the company, the forum threats, and the jailhouse AI queries.

The sentence closes the main case against Wagenius. It does not restore the metadata taken from more than 100 million AT&T customer lines, undo the ransom payment, or finish the remaining charges against every alleged partner in the Snowflake thefts.

It does mark a clear result for a soldier who used a clearance, an overseas posting, and weak corporate logins to steal phone records at massive scale and then keep hunting for exploits from inside a federal jail.

When a cleared soldier turns data thief, the country needs courts that finish the job and a military that keeps unfit troops from holding the keys in the first place.

Most Recent Stories

Copyright 2026, Thin Line News LLC