← Back to news
Krebs on Security25 Sept 2026 · 2 min read

Army soldier sentenced to 70 months over telecom data theft and extortion scheme

A U.S. Army soldier has been sentenced to 70 months in federal prison for his role in a scheme involving the theft of telecommunications data and extortion attempts targeting major companies, accordin...

A U.S. Army soldier has been sentenced to 70 months in federal prison for his role in a scheme involving the theft of telecommunications data and extortion attempts targeting major companies, according to federal prosecutors.

Cameron John Wagenius, 22, who was stationed in South Korea at the time of the offenses, pleaded guilty in two federal cases. A Seattle court also ordered him to pay $294,978 in restitution. Prosecutors said Wagenius used the online alias “Kiberphant0m” while participating in intrusions involving organizations that stored data in Snowflake cloud environments.

The case centered in part on accounts that had exposed credentials and lacked multi-factor authentication. Authorities said the group obtained call and text-message metadata affecting more than 100 million AT&T customers. The records reportedly included information such as calling and receiving numbers, dates, times and call durations, rather than message contents.

Prosecutors alleged that Wagenius and others sought payments from victim companies in exchange for not releasing stolen information. The activity also allegedly affected Verizon’s Push-to-Talk business and more than a dozen telecommunications providers internationally. Although the stolen data had substantial value, the government said Wagenius personally received only about $1,500 from data sales.

The investigation involved the FBI, Army Criminal Investigation Division, U.S. Secret Service and Defense Criminal Investigative Service. Officials described the case as particularly serious because Wagenius was an active-duty service member with a security clearance.

  • Kenneth Schuchman, of Vancouver, Washington, was identified by prosecutors as an alleged participant in the extortion activity.
  • Conor Riley Moucka, of Ontario, pleaded guilty in August 2026 in a related Snowflake data-theft case.
  • John Erin Binns, an American living in Turkey, remains wanted in connection with separate allegations, including the 2021 T-Mobile breach.

In a sentencing filing, prosecutors also said Wagenius violated Bureau of Prisons computer-use rules while awaiting sentencing. They alleged he used other inmates’ email accounts to seek information through an AI service about Windows privilege-escalation flaws, a D-Link command-injection vulnerability, radio antenna construction and prison escape research. The government said it found no evidence that he successfully exploited Bureau of Prisons systems.

Snowflake has since required multi-factor authentication for customer accounts, a control intended to reduce the risk of unauthorized access using compromised credentials.

Share this article:TwitterLinkedIn