U.S. Soldier 'Kiberphant0m' Sentenced for Massive Telecom Data Theft and Extortion
A U.S. Army soldier, operating under the alias 'Kiberphant0m,' has been sentenced to 70 months in federal prison for orchestrating a sophisticated hacking and extortion scheme. The operation targeted multiple telecommunications companies, including **AT&T**, and involved the theft of call and text metadata for over 100 million customers. Authorities also revealed his continued attempts to exploit systems even while incarcerated.
# U.S. Soldier 'Kiberphant0m' Sentenced for Massive Telecom Data Theft and Extortion
**Cameron John Wagenius**, a 22-year-old U.S. Army soldier, has been sentenced to nearly six years in federal prison and ordered to pay almost $300,000 in restitution. Wagenius, known by his cybercriminal persona **Kiberphant0m**, pleaded guilty to hacking into numerous telecommunications companies and stealing sensitive customer data.

## The Rise of Kiberphant0m
Wagenius, stationed at a U.S. Army base in South Korea, collaborated with alleged co-conspirators to exploit cloud data storage service **Snowflake** accounts. These accounts, belonging to large customers, had exposed credentials and lacked multi-factor authentication (MFA). **Snowflake** has since mandated MFA for all accounts.
In October 2024, Kiberphant0m boasted on cybercrime forums about stealing call and text metadataβincluding source and destination numbers, timestamps, and durationsβfor tens of millions of **AT&T** customers. He claimed to have breached over a dozen telecommunications companies globally, including **Verizon's Push-to-Talk** business, and publicly attempted to extort them to prevent data publication.
## Unmasking the Insider Threat
In late November 2025, KrebsOnSecurity reported that Kiberphant0m was likely a U.S. soldier in South Korea. Less than a month later, Wagenius was arrested and subsequently pleaded guilty to all charges across two federal indictments.
**Paul Russell**, a resident agent in charge at the **Defense Criminal Investigative Service** (**DCIS**), highlighted the gravity of the case. He noted that leads involving active-duty soldiers with secret clearance engaged in cybercrime are rare and trigger a comprehensive response from partner agencies like the FBI, Army Criminal Investigative Division (CID), and U.S. Secret Service. "It was very serious from jump street, just because it was unique, it was an insider threat, and we weren't sure what we were dealing with," Russell stated.
## Co-Conspirators and Broader Implications
Federal prosecutors revealed that Wagenius was aided by **Kenneth Schuchman**, 28, of Vancouver, Washington, who has a history of cybercrime. Schuchman previously pleaded guilty in 2019 to operating the **Satori** botnet, a large network of compromised IoT devices used for DDoS attacks.
Two other alleged co-conspirators in the **Snowflake** data thefts are still facing charges. **Conor Riley Moucka**, also known as βJudische,β of Kitchener, Ontario, was arrested in 2024 and pleaded guilty in August 2026. **John Erin Binns**, an American residing in Turkey, is also wanted in connection with a 2021 data breach at **T-Mobile** that exposed the personal information of at least 76 million customers.
Kiberphant0m's activities also extended to re-extorting victims and making threats to disclose national security secrets. Following Moucka's arrest, and after **AT&T** had already paid a $370,000 Bitcoin ransom, Kiberphant0m reportedly posted what he claimed were the call logs for then President-elect Donald Trump and then Vice President Kamala Harris, alongside alleged schematics from the **U.S. National Security Agency** (**NSA**).
## Continued Attempts While Incarcerated
Despite his cooperation after pleading guilty, Wagenius was caught attempting to identify security vulnerabilities within the **Bureau of Prisons** (**BOP**) computer network while awaiting sentencing. A sentencing memo filed by federal prosecutors in Seattle detailed how Wagenius used other inmates' email systems to prompt commercial AI tools for information on Windows 10 Enterprise privilege escalation CVEs, including requests for working scripts without omitted code.
He also sought detailed steps and code for **CVE-2023-45208**, a command injection vulnerability in D-Link networking devices. Furthermore, Wagenius reportedly inquired about creating antennas in a prison environment to improve radio reception and even researched methods for escaping prison. Prosecutors noted that Wagenius often framed these AI queries as research for a book, a tactic known as 'prompt injection' designed to bypass AI safeguards against generating malicious content.
Authorities confirmed they found no evidence that Wagenius successfully exploited or deployed these vulnerabilities within **BOP** systems. When questioned, he claimed his research was intended to provide information to the **BOP**.
## Minimal Financial Gain, Significant Harm
Despite the vast scale and sensitive nature of the data stolen from **AT&T** and other telecom providers, Wagenius's extortion efforts yielded minimal financial success, with an estimated total of only $1,500 from selling stolen data. However, the government's sentencing memo emphasized the significant harm caused. "While Wagenius was not particularly financially successful as a cybercriminal, he both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government," the memo concluded.