A 22-year-old US Army soldier who admitted hacking several telecommunications companies and stealing call and text metadata belonging to more than 100 million AT&T customers has been sentenced to 70 months in federal prison.
Cameron John Wagenius was also ordered to pay $294,978 in restitution to victims following his conviction for his role in the cybercrime operation.
Wagenius, who was stationed at a US Army base in South Korea, operated online under the name “Kiberphant0m”. Prosecutors said he worked with three alleged co-conspirators to obtain data from several major customers of cloud storage provider Snowflake.
The group targeted companies whose credentials had been exposed and whose accounts lacked multi-factor authentication. Snowflake has since made multi-factor authentication mandatory across its accounts.
In October 2024, Wagenius reportedly boasted on cybercrime forums that he had obtained call and text metadata belonging to tens of millions of AT&T customers.

The stolen information included source and destination telephone numbers, timestamps and call durations.
He also claimed to have breached more than a dozen telecommunications companies around the world, including Verizon’s Push-to-Talk business.
Wagenius and his associates allegedly attempted to extort some of the companies by threatening to release the stolen information.
In November 2025, KrebsOnSecurity reported that Kiberphant0m was likely a US soldier based in South Korea. Wagenius was arrested less than a month later and subsequently faced charges in two separate federal indictments.
He eventually pleaded guilty to all the charges.
At his sentencing hearing in Seattle, Wagenius received a prison term of nearly six years and was ordered to pay $294,978 in restitution.
Federal prosecutors said Kenneth Schuchman, a 28-year-old from Vancouver, Washington, also assisted Wagenius in efforts to extort victims.
Schuchman has a history of cybercrime and pleaded guilty in 2019 to operating the Satori botnet, a network of compromised Internet-of-Things devices used to launch large-scale distributed denial-of-service attacks.
Two other alleged co-conspirators connected to the Snowflake data thefts are also facing charges.
Conor Riley Moucka, also known as “Judische”, from Kitchener, Ontario, was arrested in 2024 and pleaded guilty in August 2026. Another suspect, John Erin Binns, an American living in Turkey, is wanted in connection with the 2021 T-Mobile data breach that exposed the personal information of at least 76 million customers.
Wagenius also admitted to repeatedly extorting victims and threatening to reveal national security information.
After Moucka was arrested, and following the payment of a $370,000 Bitcoin ransom by AT&T, Kiberphant0m posted what he claimed were AT&T call records belonging to then President-elect Donald Trump and then Vice President Kamala Harris.
He also claimed to have obtained schematics from the US National Security Agency.
Paul Russell, resident agent in charge at the Defense Criminal Investigative Service, said the investigation began after authorities received information that a soldier with secret clearance was allegedly involved in hacking and extortion.
DCIS worked with the FBI, the Army Criminal Investigation Division and the US Secret Service during the investigation.
“We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data,” Russell said. “That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with.”
Despite pleading guilty and cooperating with investigators, prosecutors told the court that Wagenius continued attempting to research computer vulnerabilities while awaiting sentencing.
A sentencing memorandum filed on September 19 said he violated Bureau of Prisons computer-use policies by using another inmate’s email system to seek information about vulnerabilities in BOP computer networks.
“According to records from BOP, in or around September 2025, Wagenius used another inmate’s email system to request that the email recipient prompt a commercial AI tool to provide information about “[w]hat CVE’s are there for Windows 10 Enterprise privilege escalation and bypasses” and to “[p]rovide the CVE’s and a real world working script for each CVE . . . without omitted code,” the government’s memo states.
Less than a week later, prosecutors said Wagenius used another inmate’s email account to request information about CVE-2023-45208, a command-injection vulnerability affecting D-Link networking devices.
The memo also said he asked an AI tool for instructions on making an antenna inside prison to improve radio reception.
He was further accused of asking the recipient to research ways of escaping prison.
“In several instances, Wagenius framed the AI queries as being posed in connection to a book he was writing. This is a common method of ‘prompt injection,’ in which attackers feed specially crafted, deceptive inputs into commercial AI tools that are programmed to avoid outputting malicious code that can be used to exploit computer vulnerabilities,” the sentencing memo reads.
However, prosecutors told the court they had no evidence that Wagenius successfully used or deployed any of the vulnerabilities he researched against BOP systems.
They said he claimed he was researching “potential vulnerabilities to provide information to the BOP.”
Despite targeting data with significant financial value, prosecutors said Wagenius made relatively little money from his criminal activities.
According to the government’s sentencing memo, he earned only about $1,500 from selling stolen data.
“While Wagenius was not particularly financially successful as a cybercriminal, he both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government,” the memo states.




