Former US Army soldier Cameron Wagenius, who pleaded guilty in 2025 to hacking into telecom companies and to extortion, is sentenced to 70 months in prison
First reported by Krebsonsecurity ·
Active duty soldiers with secret clearances are now demonstrably capable of and willing to engage in cybercrime, creating a unique insider threat.
Cameron John Wagenius, a U.S. Army soldier stationed in South Korea, has been sentenced to 70 months in federal prison and ordered to pay nearly $300,000 in restitution. Operating under the cybercriminal alias "Kiberphant0m," Wagenius pleaded guilty to hacking into multiple telecommunications companies, including AT&T and Verizon's Push-to-Talk business. In 2024, he stole call and text metadata for over 100 million AT&T customers by exploiting exposed credentials on the cloud service Snowflake, which has since mandated multi-factor authentication. Wagenius also bragged about hacking over a dozen telecom companies and extorting them for not publishing the stolen data. He was assisted by Kenneth Schuchman, who previously pleaded guilty to operating the Satori botnet. Two other alleged co-conspirators, Conor Riley Moucka and John Erin Binns, are also facing charges. Wagenius was arrested and charged in two federal indictments after being identified as a soldier with secret clearance.
Wagenius's attempts to research vulnerabilities within the Bureau of Prisons' computer network using AI tools, even while incarcerated, highlight a persistent challenge for correctional facilities. The use of "prompt injection" to bypass AI safety measures for learning about exploitation techniques is a concerning indicator of how advanced tools are being leveraged by malicious actors, even from behind bars. This demonstrates a continuous adaptation of cybercriminal tactics using emerging technologies.
The sentencing underscores the serious consequences of exploiting cloud service vulnerabilities like those found in Snowflake, particularly when multi-factor authentication is not enforced. It also signals a potential increase in insider threats from individuals with privileged access and technical skills, prompting a re-evaluation of security protocols for military personnel and those with access to sensitive national security data.
AI-written summary. May contain errors.