Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies
A former U.S. Army soldier was sentenced to 70 months for extortion attacks on AT&T and Snowflake customers.
Cameron John Wagenius, 22, was sentenced to 70 months in prison and ordered to pay almost $295,000 in restitution after pleading guilty in July 2025. While on active duty, he and co-conspirators Connor Moucka and John Erin Binns stole credentials, broke into Snowflake customer environments, and attempted to extort organizations including AT&T, Ticketmaster, Advance Auto Parts, and Santander. Prosecutors said the group stole billions of records from more than 165 Snowflake customers and received over $2.5 million in extortion payments combined. Wagenius, known as kiberphant0m, used a tool called SSH Brute and leaked stolen call records tied to Donald Trump in failed attempts to extort $500,000 from AT&T.
- Wagenius was sentenced to 70 months and nearly $295,000 restitution.
- He and co-conspirators compromised more than 165 Snowflake customer environments.
- Named victims include AT&T, Ticketmaster, Advance Auto Parts, and Santander.
- Prosecutors said the group received over $2.5 million in extortion payments.
- He operated as kiberphant0m and used the SSH Brute credential tool.
Full article885 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Cameron Wagenius was involved in some of the most high-profile attacks of 2024 while on active duty.
Listen to this article
0:00
Learn more.
A former Army soldier responsible for a series of attacks and extortion attempts on telecom companies, including AT&T, was sentenced to 70 months in prison, the Justice Department said Friday.
Cameron John Wagenius engaged in a cybercrime spree for years, including while he was on active duty on a base in Texas. Prior to his arrest in December 2024, Wagenius attempted to sell stolen sensitive data to a foreign intelligence service and sought information online about defecting to Russia.
“Cameron Wagenius spent more than a year and a half betraying the trust placed in him as an active duty soldier by carrying out a sweeping cybercrime campaign,” said A. Tysen Duva, assistant attorney general of the Justice Department’s Criminal Division, said in a statement.
Wagenius, who pleaded guilty in July 2025, leaked stolen call records of President Donald Trump as part of multiple failed attempts to extort $500,000 from AT&T, Allison Nixon, chief research officer at Unit 221B, previously told CyberScoop.
Authorities did not name Wagenius’ alleged victims in court filings, but said he disclosed non-content call detail records belonging to a government official and family members of another former official. AT&T in July confirmed cybercriminals accessed the company’s Snowflake environment in April and stole six months of phone and text records of “nearly all” of its customers.
Wagenius’ and one of his co-conspirators, Connor Moucka, attempted to extort more than 10 organizations after stealing credentials and breaking into cloud platforms used by AT&T and other major companies based in the United States and abroad.
Moucka, a Canadian extradited to the United States in March 2025, pleaded guilty in August to playing a central role in one of the most far-reaching cyberattacks of 2024 — the widespread compromise of more than 165 Snowflake customer environments, resulting in massive data theft for extortion.
Wagenius, Moucka and their alleged co-conspirator John Erin Binns, who is not presently in U.S. custody, stole billions of sensitive records and received more than $2.5 million in extortion payments combined, according to prosecutors. Victims of the attack spree included AT&T, Ticketmaster, Advance Auto Parts and Santander.
Some of the records in Wagenius’ possession at the time of his arrest were stolen in the attack spree on Snowflake customer databases, according to cybercrime researchers. Officials said Wagenius was directly involved in attempted extortion attempts targeting multiple organizations for a combined total of more than $1 million.
The 22-year-old was ordered to pay almost $295,000 in restitution for his crimes.
“His hacking schemes were not only aimed at getting rich, he was also motivated by a desire to achieve status within criminal hacking communities,” Charles Neil Floyd, first assistant attorney for the U.S. District Court for the Western District of Washington, said in a statement. “This sentence must impose real consequences to deter him, and hopefully other would-be hackers.”
Wagenius, who identified himself as “kiberphant0m” and “cyb3rph4nt0m” on online criminal forums, used a hacking tool he helped develop called SSH Brute to steal credentials while on active duty, officials said. Wagenius and his co-conspirators threatened the victim organizations privately and in public forms, officials added.
“It is especially shocking that a member of our armed forces, sworn to defend Americans and their constitutional rights, would engage in such a violation of privacy,” W. Mike Herrington, special agent in charge of the FBI Seattle field office, said in a statement.
When federal law enforcement seized Wagenius’ devices in December 2024, they found evidence indicating he had access to thousands of stolen identification documents and large amounts of cryptocurrency. Days later, Wagenius purchased a new laptop against his commanding officer’s order, according to officials, and used it every day over a five-day period in the barracks at Fort Cavazos in Texas with VPN software to hide his identity and location.
Latest Podcasts
Government
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
CISA outlines improvement plan for CVE program
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
Pentagon cyber chief: The demand far exceeds supply
Technology
Threats
Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
Another worry for water systems: infostealer exposure
International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data