Army Soldier Sentenced to 70 Months for AT&T, Verizon Data Extortion
Cameron John Wagenius, a 22-year-old Army soldier who used the alias 'Kiberphant0m,' was sentenced to nearly seven years in federal prison and ordered to pay $294,978 in restitution. He had pleaded guilty to hacking into telecom companies via exposed Snowflake cloud credentials, stealing call and text metadata from more than 100 million AT&T customers and Verizon's Push-to-Talk business, then extorting the firms not to leak the data.
GoKawiil's interpretation of the reporting above, not reported fact.
The case underscores how a single cloud misconfiguration—accounts without multi-factor authentication—enabled theft of metadata affecting tens of millions of customers, prompting Snowflake to mandate MFA industry-wide. It also shows extortion schemes increasingly relying on loosely organized networks of individuals, including a soldier stationed overseas and collaborators with prior cybercrime records, complicating attribution and prosecution.
- Wagenius received 70 months in prison and must pay nearly $300,000 in restitution.
- The breach exploited unsecured Snowflake cloud accounts lacking multi-factor authentication, later made mandatory.
- Investigative journalism from KrebsOnSecurity helped identify the suspect before his arrest.
Source: krebsonsecurity.com, 2026-09-25
Published there as: “U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.