Image: krebsonsecurity.com · rights & removal
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
Reporting by Krebs on SecurityRead the original at krebsonsecurity.com
Executive Summary
Facts Only
* Cameron John Wagenius was sentenced to 70 months in federal prison and ordered to pay $294,978 in restitution.
* Wagenius adopted the persona “Kiberphant0m” while stationed at a U.S. Army base in South Korea.
* Kiberphant0m allegedly stole call and text metadata for more than 100 million AT&T customers in 2024.
* The data theft involved exploiting vulnerabilities in Snowflake credentials that lacked multi-factor authentication.
* Kiberphant0m claimed to have hacked into over a dozen telecommunications companies worldwide, including Verizon’s Push-to-Talk business.
* Wagenius allegedly re-extorted victims and threatened to disclose national security secrets.
* Kenneth Schuchman allegedly assisted Wagenius in extorting victim companies.
* Co-conspirators include Conor Riley Moucka ("Judische") and John Erin Binns, who was also wanted for a T-Mobile data breach.
* Wagenius reportedly attempted to find security vulnerabilities in the Bureau of Prisons (BOP) computer network while incarcerated by querying AI tools for exploit information related to CVEs.
* Wagenius made approximately $1,500 from selling stolen data and was ordered to pay $296,000 in restitution.
Full Take
The narrative presents a complex intersection of military service, sophisticated cybercrime, extortion, and insider threat dynamics. The story pivots on how actions taken by an individual, allegedly an insider with a secret clearance, translated into large-scale data theft and subsequent criminal enterprise. A key pattern emerges in the escalation from external data theft (Snowflake) to direct extortion of major telecom entities, followed by the incorporation of national security threats as leverage. Furthermore, the details surrounding Wagenius’s post-conviction activities—specifically his attempts to probe for vulnerabilities within a correctional system using AI prompts—suggest a disturbing synergy between criminal exploitation and an attempt to apply those skills toward state infrastructure, regardless of the stated motivation. The reaction from law enforcement involving multiple agencies (DCIS, FBI, etc.) highlights how such incidents trigger complex, multi-jurisdictional investigations based on insider threat recognition. The commentary layered onto the factual reporting suggests a public tension between viewing such actions as pure criminality versus acknowledging potential systemic vulnerabilities and the role of individual agency within complex security environments.
Patterns detected: ARC-0024 Ambiguity, ARC-0017 Motive-and-Bailey
From the original · Krebs on Security
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.Read the full story at krebsonsecurity.com
Sentinel — provisional
No strong signs of machine writing were found in the source article. Provisional estimate, not a finding that a person wrote it.
The text begins as a factual report but concludes with highly subjective, adversarial commentary, strongly indicating the latter portion was added by a human voice reacting to the preceding information.
This looks only at the wording of the original source article, not at this page's AI-written sections. A small local AI model made this estimate. It has not been checked against known human and machine texts, so treat it as provisional. It cannot show who wrote an article.
