
Ex-US soldier Cameron Wagenius gets 70 months for AT&T and Verizon hacks
Cameron John Wagenius, 22, who stole call and text metadata belonging to more than 100 million AT&T customers in 2024, was sentenced in Seattle to 70 months in prison and ordered to pay $294,978 in restitution.
A former U.S. Army soldier who stole call and text metadata belonging to more than 100 million AT&T customers in 2024 was sentenced on September 25 to 70 months in prison and ordered to pay $294,978 in restitution. Cameron John Wagenius, 22, received the sentence in Seattle.
The Snowflake breach and the extortions
According to Krebs on Security, Wagenius was stationed at a U.S. Army base in South Korea when he adopted the persona “Kiberphant0m”. He downloaded data from several large customers of the cloud storage service Snowflake that had exposed credentials and did not enforce multi-factor authentication.
In October 2024, he bragged that he had stolen metadata for tens of millions of AT&T customers and claimed to have breached more than a dozen telecommunications companies worldwide, including Verizon’s Push-to-Talk business. Prosecutors said he and his co-conspirators tried to extort more than $1 million, threatening to publish the stolen records on forums such as BreachForums and XSS.is.
AT&T had already paid the group a $370,000 Bitcoin ransom before another suspect was arrested, Krebs on Security reported; Wagenius then posted what he claimed were call logs for Donald Trump and Kamala Harris.
Guilty pleas and co-conspirators
Wagenius was arrested and charged in two separate federal indictments and pleaded guilty to all counts, including wire-fraud conspiracy, extortion in relation to computer fraud and aggravated identity theft. Prosecutors said Kenneth Schuchman, 28, who pleaded guilty in 2019 to running the Satori botnet, helped in the extortion attempts. Conor Riley Moucka of Kitchener, Ontario, pleaded guilty in August 2026 over the Snowflake thefts.
The sentencing memo says Wagenius made only about $1,500 from selling the stolen data. “While Wagenius was not particularly financially successful as a cybercriminal, he both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government,” it states.
Continued attempts from prison
Prosecutors said Wagenius kept looking for security holes while awaiting sentencing. Bureau of Prisons records show that in September 2025 he used other inmates’ email accounts to ask the recipients to prompt commercial AI tools for information about privilege-escalation flaws in Windows 10 Enterprise, and for a working exploit for CVE-2023-45208, a command-injection vulnerability in D-Link networking devices. He also asked how to build an antenna from prison commissary items and framed some requests as research for a book, a tactic prosecutors called a common prompt-injection method. The government said it has no evidence he deployed any of the vulnerabilities.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.