US soldier gets 70 months in prison for extorting 10 tech, telecom firms

A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024.
21-year-old Cameron John Wagenius (also known online as 'kiberphant0m' and 'cyb3rph4nt0m' ) was arrested in Texas in December 2024.
He pleaded guilty in February 2025 to hacking AT&T and Verizon after being charged on two counts of unlawfully transferring confidential phone records, and in July 2025 to multiple counts of aggravated identity theft, conspiracy to commit wire fraud, and extortion related to computer fraud.
According to court documents, while on active duty with the U.S. Army, Wagenius and his accomplices stole login credentials for the victim's networks using the SSH Brute hacking tool he helped develop. They also used Telegram to transfer stolen credentials and plan their attacks.
"After data was stolen, Wagenius and his conspirators extorted the victim organizations both privately and in public forums. The extortion attempts included threats to post the stolen data on cybercrime forums such as BreachForums and XSS.is," the Justice Department said.
"In other instances, conspirators offered to sell stolen data for thousands of dollars via posts on these forums. They successfully sold at least some of this stolen data and also used stolen data to perpetuate other frauds, including SIM-swapping. In total, Wagenius and his co-conspirators attempted to extort at least $1 million from victim data owners."
In addition to the 70-month prison sentence, Wagenius was ordered to pay $294,978 in restitution for hacking into telecom companies' databases, accessing sensitive customer records, and extorting the companies under threat of releasing stolen data unless they paid ransoms.
Two of his accomplices, Connor Riley Moucka (a.ka. "Waifu" and "Judische") and John Erin Binns (aka "irdev" and "j_irdev1337"), were accused in November 2024 of breaching and stealing terabytes of data from more than 165 organizations using the services of Snowflake cloud storage company and demanding ransom payments to delete the stolen information and not leak it online.
Moucka was arrested on October 30, 2024, in Canada at the request of the United States and pleaded guilty to his role in the Snowflake hacking campaign in August 2026.
Data breaches linked to Snowflake attacks affected hundreds of millions of people, customers of AT&T, Ticketmaster, Santander, Los Angeles Unified, QuoteWizard/LendingTree, Pure Storage, Advance Auto Parts, and Neiman Marcus.
After these incidents led to massive data breaches, Snowflake announced it would enforce multi-factor authentication (MFA) and require customers to choose passwords at least 14 characters long.
References in this story
- Attention Required! | Cloudflare www.documentcloud.org
- Former U.S. Soldier Sentenced for Hacking and Extortion Scheme That Exposed Sensitive Data of U.S. Government Official www.justice.gov Cameron John Wagenius, 22, a former Army soldier who was most recently stationed in Texas, was sentenced today to 70 months in prison and ordered to pay $294,978 in restitution for conspiring to hack into…
- US indicts Snowflake hackers who extorted $2.5 million from 3 victims www.bleepingcomputer.com The Department of Justice has unsealed the indictment against two suspected Snowflake hackers, who breached more than 165 organizations using the services of the Snowflake cloud storage company.
- Suspect behind Snowflake data-theft attacks arrested in Canada www.bleepingcomputer.com Canadian authorities have arrested a man suspected of having stolen the data of hundreds of millions after targeting over 165 organizations, all of them customers of cloud storage company Snowflake.
- Canadian pleads guilty to Snowflake cloud data-theft attacks www.bleepingcomputer.com A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims.
- Data of 560 million Ticketmaster customers for sale after alleged breach www.bleepingcomputer.com A threat actor known as ShinyHunters is selling what they claim is the personal and financial information of 560 million Ticketmaster customers on the recently revived BreachForums hacking forum for $500,000.
- ShinyHunters claims Santander breach, selling data for 30M customers www.bleepingcomputer.com A threat actor known as ShinyHunters is claiming to be selling a massive trove of Santander Bank data, including information for 30 million customers, employees, and bank account data, two weeks after the bank reported…
- Los Angeles Unified confirms student data stolen in Snowflake account hack www.bleepingcomputer.com The Los Angeles Unified School District has confirmed a data breach after threat actors stole student and employee data by breaching the company's Snowflake account.
- What Snowflake isn't saying about its customer data breaches | TechCrunch techcrunch.com As another Snowflake customer confirms a data breach, the cloud data company says its position "remains unchanged."
- Pure Storage confirms data breach after Snowflake account hack www.bleepingcomputer.com Pure Storage, a leading provider of cloud storage systems and services, confirmed on Monday that attackers breached its Snowflake workspace and gained access to what the company describes as telemetry information
- Advance Auto Parts confirms data breach exposed employee information www.bleepingcomputer.com Advance Auto Parts has confirmed it suffered a data breach after a threat actor attempted to sell stolen data on a hacking forum earlier this month.
- Neiman Marcus confirms data breach after Snowflake account hack www.bleepingcomputer.com Luxury retailer Neiman Marcus confirmed it suffered a data breach after hackers attempted to sell the company's database stolen in recent Snowflake data theft attacks.


