Ex-soldier's telecom hacking spree earns him 70 months
Former US soldier Cameron Wagenius was sentenced to 70 months for hacking telecom firms and seeking $1 million.
Former US Army soldier Cameron John Wagenius, 22, was sentenced to 70 months in prison and ordered to pay $294,978 in restitution for hacking telecommunications companies, stealing sensitive records, and attempting extortion. While on active duty between April 2023 and December 2024, he and three co-conspirators obtained credentials for at least ten organizations, including with a tool called SSH Brute, and stole hundreds of thousands of customer records. The Justice Department said they tried to extort at least $1 million, sold some data, and used other records for fraud including SIM swapping. Wagenius has also been linked to the 2024 Snowflake extortion campaign that affected AT&T, Verizon, and other companies.
- Cameron Wagenius, 22, received 70 months and $294,978 restitution.
- He targeted at least ten organizations while on active duty from 2023 to 2024.
- The group used SSH Brute and stolen credentials to take hundreds of thousands of records.
- Conspirators sought at least $1 million and committed SIM-swapping fraud.
- He was linked to the 2024 Snowflake extortion campaign affecting AT&T and Verizon.
Full article379 words · extracted from theregister.com · click to collapse
cyber-crime
Active-duty campaign targeted at least ten organizations and sought $1 million in ransom payments
A former US Army soldier has been sentenced to 70 months in prison for hacking telecoms companies, stealing sensitive records, and trying to extort more than $1 million from his victims.
Cameron John Wagenius, 22, carried out the campaign while serving on active duty. He pleaded guilty in March 2025 to unlawfully transferring confidential phone records, then admitted conspiracy to commit wire fraud, computer-related extortion, and aggravated identity theft in a separate case that July.
Court documents say Wagenius conspired with three others to obtain credentials for the protected networks of at least ten organizations between April 2023 and December 2024. During that period, he was stationed in South Korea and Texas.
REG AD
The Justice Department has not publicly identified the victims, describing them as US and overseas telecommunications companies and other organizations.
REG AD
Wagenius has also been linked to the 2024 Snowflake extortion campaign, which affected AT&T, Verizon, and numerous other companies, as The Register previously reported.
After two suspects were arrested in connection with the Snowflake attacks, an account controlled by Wagenius claimed to possess AT&T call records belonging to Donald Trump and Kamala Harris.
Using online aliases including "kiberphant0m," Wagenius and his co-conspirators obtained login credentials with a hacking tool he helped develop called SSH Brute, among other methods. They exchanged stolen credentials in Telegram group chats and discussed using them to gain unauthorized access to other parts of victims' networks.
Court documents say the group traded hundreds of credentials and stole hundreds of thousands of customer records from multiple companies.
Wagenius and his accomplices advertised stolen data through XSS, BreachForums, X, and Telegram.
Some posts offered the information for sale, while others threatened to publish it unless victims paid. The Justice Department said the conspirators attempted to extort at least $1 million in total, successfully sold some stolen data, and used other records to commit fraud, including SIM swapping.
US District Judge Lauren King told Wagenius at sentencing: "Your actions show a shocking disregard for the safety and security of the United States... You took these actions motivated by greed and a desire for notoriety."
Wagenius was also ordered to pay $294,978 in restitution. ®