Former US Soldier Sentenced for Hacking and Extortion of Tech and Telecom Firms
A former U.S. Army soldier has received a 70-month prison sentence for his role in a sophisticated hacking and extortion scheme targeting at least ten U.S. technology and telecommunications companies. **Cameron John Wagenius**, known online as 'kiberphant0m' and 'cyb3rph4nt0m', was part of a conspiracy that stole sensitive data and attempted to extort over $1 million from victim organizations.

**Cameron John Wagenius**, a 21-year-old former U.S. Army soldier, has been sentenced to 70 months in prison for a widespread hacking and extortion campaign. Wagenius, who operated under the online aliases 'kiberphant0m' and 'cyb3rph4nt0m', targeted at least ten U.S. technology and telecommunications firms between April 2023 and December 2024.
### The Charges and Guilty Plea
Wagenius was arrested in Texas in December 2024. He pleaded guilty in February 2025 to unlawfully transferring confidential phone records from **AT&T** and **Verizon**. Subsequently, in July 2025, he pleaded guilty to multiple counts including aggravated identity theft, conspiracy to commit wire fraud, and extortion related to computer fraud.
### Modus Operandi
According to court documents, Wagenius and his accomplices, while he was on active duty, leveraged an **SSH Brute** hacking tool they helped develop to steal login credentials for victim networks. They also utilized **Telegram** for coordinating attacks and transferring stolen credentials.
### Extortion and Data Monetization
The Department of Justice stated that after data theft, Wagenius and his co-conspirators engaged in extortion attempts, both privately and on public forums like **BreachForums** and **XSS.is**. Threats included public release of stolen data. In other instances, they offered to sell the data for thousands of dollars. They successfully sold some stolen data and used it to perpetrate other frauds, including SIM-swapping. The total attempted extortion from victim data owners exceeded $1 million.
In addition to his prison term, Wagenius has been ordered to pay $294,978 in restitution.
### Connections to Snowflake Attacks
Two of Wagenius's accomplices, **Connor Riley Moucka** (a.k.a. "Waifu" and "Judische") and **John Erin Binns** (a.k.a. "irdev" and "j_irdev1337"), were implicated in a broader campaign. In November 2024, they were accused of breaching over 165 organizations utilizing **Snowflake** cloud storage, stealing terabytes of data, and demanding ransom.
Moucka was arrested in Canada on October 30, 2024, and pleaded guilty to his role in the **Snowflake** hacking campaign in August 2026.
These **Snowflake**-linked data breaches impacted hundreds of millions of individuals, affecting customers of major entities such as **AT&T**, **Ticketmaster**, **Santander**, **Los Angeles Unified**, **QuoteWizard/LendingTree**, **Pure Storage**, **Advance Auto Parts**, and **Neiman Marcus**.
Following these incidents, **Snowflake** announced it would enforce multi-factor authentication (MFA) and require customers to choose passwords of at least 14 characters to bolster security measures.