Former Army soldier sentenced to nearly 6 years for telecom hacking, extortion

SimpleImages / Getty Images
Cameron Wagenius stole sensitive phone records while on active duty and sought to sell information to a foreign intelligence service, prosecutors said.
A former Army soldier who helped hack telecommunications companies and threatened to release stolen records unless they paid ransoms was sentenced Friday to 70 months in prison, the Justice Department said.
Cameron John Wagenius, 22, who operated online under the nickname “kiberphant0m,” was also ordered to pay $294,978 in restitution. Prosecutors said he and his co-conspirators attempted to extort at least $1 million from victim organizations during a campaign he carried out while on active duty.
The case drew attention following his December 2024 arrest, when cybersecurity journalist Brian Krebs reported that Wagenius was behind an account that posted what it claimed were AT&T call logs associated with then-President-elect Donald Trump and Vice President Kamala Harris. The posts followed the arrest of alleged hacker Connor Riley Moucka, who was accused of stealing data from companies that used the cloud storage service Snowflake.
In its sentencing announcement, Justice said Wagenius published two posts in November 2024 disclosing confidential call records belonging to a government official and family members of a former official. The department did not identify those individuals.
Wagenius threatened to release additional records unless he was paid a ransom. One post suggested he was retaliating for another cybercriminal’s recent arrest, prosecutors said.
“He targeted U.S. and foreign telecommunications companies, compromised the sensitive data of countless people, and even sought to traffic stolen information to a foreign intelligence service,” Assistant Attorney General A. Tysen Duva said in a statement.
The case was connected to a broader wave of data theft targeting Snowflake customers in 2024. Snowflake lets businesses store and analyze large amounts of data in the cloud. Hackers used stolen login credentials to access customer accounts that lacked multifactor authentication, then stole information to sell or use for extortion.
AT&T was among the victims. The company disclosed in July 2024 that hackers had stolen records of calls and texts involving nearly all its cellular customers over a six-month period in 2022 from its Snowflake account.
The Record reported last year that a filing in Wagenius’ case identified the prosecution of Moucka and fellow alleged hacker John Erin Binns as a related case. The outlet also detailed prosecutors’ allegations that Wagenius tried to sell stolen information to an email address he believed belonged to a foreign military intelligence service and searched online for information about defecting to Russia. The intelligence service’s country was not identified.
According to the DOJ, Wagenius and his associates obtained login credentials for at least 10 organizations between April 2023 and December 2024. Their methods included a hacking tool called SSH Brute that Wagenius helped develop. They used Telegram chats to exchange stolen credentials and discuss breaking into company networks.
After stealing data, the group demanded payments privately and threatened to publish the information on cybercrime forums, including BreachForums and XSS.is. They also sold some stolen data and used it for additional fraud, including SIM-swapping, prosecutors said.
Wagenius pleaded guilty in July 2025 to conspiracy to commit wire fraud, extortion in relation to computer fraud and aggravated identity theft. He separately pleaded guilty last March to two counts of unlawfully transferring confidential phone records.




