Soldier sentenced to 70 months for telecom and Snowflake extortions
Cameron John Wagenius was sentenced to 70 months and $294,978 restitution for extorting AT&T, Verizon and other firms after Snowflake data theft.
Cameron John Wagenius, a 22-year-old U.S. Army soldier known as kiberphant0m, was sentenced in Seattle to 70 months in federal prison and ordered to pay $294,978 in restitution after pleading guilty in July 2025. While on active duty and stationed in South Korea, he and co-conspirators Connor Moucka and John Erin Binns used exposed Snowflake credentials that lacked MFA, along with a tool called SSH Brute, to break into customer environments. Prosecutors said the group stole billions of records from more than 165 Snowflake customers, including call and text metadata for more than 100 million AT&T customers, and targeted or extorted AT&T, Verizon, Ticketmaster, Advance Auto Parts, and Santander, receiving more than $2.5 million combined. The reports differ on the AT&T payment: CyberScoop described failed attempts to extort $500,000 and a leak of stolen call records tied to Donald Trump, while Krebs on Security said AT&T paid the group $370,000 in Bitcoin. Krebs also reported that, from jail, Wagenius used other inmates' email to ask an AI tool for exploit assistance involving CVE-2023-45208.
- Cameron John Wagenius, 22, known as kiberphant0m, was sentenced in Seattle to 70 months in federal prison and $294,978 in restitution after pleading guilty in July 2025.
- While on active duty and stationed in South Korea, he and co-conspirators Connor Moucka and John Erin Binns used exposed Snowflake credentials without MFA and a tool called SSH Brute.
- Prosecutors said the group stole billions of records from more than 165 Snowflake customers, including call and text metadata for more than 100 million AT&T customers.
- Named targets or victims include AT&T, Verizon, Ticketmaster, Advance Auto Parts, and Santander; the group received more than $2.5 million in extortion payments combined.
- CyberScoop reported failed attempts to extort $500,000 from AT&T and a leak of stolen call records tied to Donald Trump; Krebs reported AT&T paid the group $370,000 in Bitcoin.
- Krebs reported that, while jailed, Wagenius used other inmates' email to ask an AI tool for exploit assistance involving CVE-2023-45208.
Coverage timelineoldest first · each row is one article
- · 1d agoArmy soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies
CyberScoop· 64
A former U.S. Army soldier was sentenced to 70 months for extortion attacks on AT&T and Snowflake customers.
- · 1d agoU.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
Krebs on Security· 68
A U.S. Army soldier received 70 months for extorting AT&T and Verizon after stealing call metadata.
Vulnerabilities in this storyAll →
- CVE-2023-452088.81%A command injection in the parsing_xml_stasurvey function inside libcgifunc.so of the D-Link DAP-X1860 repeater 1.00 through 1.01b05-01 allows attackers…published · dlink dap-1860 firmware PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-45208 |