Former US soldier gets nearly six-year sentence for hacking, extorting telecoms

A former soldier in the U.S. Army was sentenced to more than five years in federal prison after pleading guilty to hacking into several telecommunications companies and leaking sensitive records.
Cameron John Wagenius, 22, was handed a 70-month sentence and is ordered to pay nearly $295,000 in restitution.
Wagenius was an active duty soldier stationed in South Korea and at Fort Cavazos in Texas when he conducted the hacks between April 2023 and December 18, 2024. He worked with two other hackers to steal thousands of sensitive call records, according to court documents.
Wagenius initially pleaded guilty to two separate but related charges centered around posting confidential phone records to an online forum and sending the records through a platform. He later pleaded guilty in a Seattle federal court to wire fraud, extortion and aggravated identity theft.
He attempted to extort multiple U.S.-based telecommunications companies after obtaining login credentials and breaching their systems. Wagenius and several others sought at least $1 million in ransoms for the stolen data.
Assistant Attorney General A. Tysen Duva noted that he “even sought to traffic stolen information to a foreign intelligence service.”
“Cameron Wagenius spent more than a year and a half betraying the trust placed in him as an active duty soldier by carrying out a sweeping cybercrime campaign,” Duva said. “His actions reflect an alarming disregard for the security of the public and the United States.”
The Justice Department said he made two online posts in November 2024 claiming to have “confidential non-content call detail records belonging to a government official and family members of another former official and threatened to release additional confidential records unless paid a ransom.”
The case was tied to a spate of attacks in 2024 targeting more than 100 customers of data storage giant Snowflake, including AT&T. Cybersecurity experts cited by the Justice Department last year said Wagenius allegedly leaked call logs from AT&T belonging to President Donald Trump.
The AT&T breach involved metadata stolen through Snowflake that included nearly all call logs and texts made by the company’s customers over a six-month period in 2022.
Under the username “kiberphant0m,” Wagenius worked with others to breach at least 10 organizations using a tool he created called “SSH Brute.”
Prosecutors said Wagenius and his crew “gained unlawful access to hundreds of thousands of sensitive business and customer records, including non-content call and text history records, telecommunication identifying information, and other personally identifiable information.”
Once the data was stolen and exfiltrated, Wagenius and others extorted the organizations in both public and private settings. He made posts on cybercrime forums such as BreachForums and XSS.is to market the stolen data.
Court documents showed Wagenius successfully sold at least some of the stolen data and also used stolen data to carry out other fraud, including SIM-swapping.
In November 2024, Wagenius contacted an email address he believed belonged to an unidentified country’s military intelligence service in an effort to sell the information he stole.
Prosecutors obtained Google searches made by Wagenius that included “can hacking be treason,” “where can i defect the u.s government military which country will not hand me over,” “U.S. military personnel defecting to Russia” and “Embassy of Russia – Washington, D.C,” and “how to get passport fast.”
Three unnamed co-conspirators were named in the court documents, including one based in Washington state and another in Canada.
One of the court documents for Wagenius’ charges references a “related case” involving Connor Riley Moucka and John Erin Binns — two other hackers implicated in the theft of Snowflake data and previous targeting of telcos like AT&T and T-Mobile.
Moucka agreed to be extradited to the U.S. from Canada and pleaded guilty last month.
Binns was detained by Turkish authorities in May 2024 after being indicted for his role in a previous hack of T-Mobile.
References in this story
- Snowflake Latest News therecord.media Explore the latest trending news and updates on Snowflake. Dive into insightful articles, analyses, and more to stay informed on Snowflake.
- Hackers stole ‘nearly all’ call logs over six months from AT&T therecord.media The telecom giant said the massive breach involving logs from 2022 occurred through the third-party cloud platform Snowflake.
- Alleged Snowflake hacker consents to extradition from Canada after US charges therecord.media Connor Riley Moucka signed a consent order on Friday in Ontario Superior Court in Kitchener that would allow him to be transferred to U.S. custody to face multiple charges.
- Canadian citizen allegedly involved in Snowflake attacks consents to extradition to US cyberscoop.com Connor Moucka, a 26-year-old arrested at the behest of U.S. authorities in October in Kitchener, Ontario, faces 20 federal charges.
- Canadian man pleads guilty to Snowflake hacks that led to 165 breaches therecord.media A 26-year-old from Ontario faces as many as 32 years in prison after pleading guilty to fraud, identity theft and conspiracy charges related to the 2024 hacks of cloud platform Snowflake.
- Exclusive: American who hacked T-Mobile servers in 2021 arrested in Turkey, to be extradited to U.S. thedesk.net John Binns, 24, admitted to accessing servers connected to T-Mobile; he was federally indicted in 2022.
- Sealed Indictment Shows Case Against Hacker Behind Massive T-Mobile Data Breach www.404media.co A sealed indictment obtained by 404 Media describes the case against John Binns, who allegedly hacked into T-Mobile, stole 40 million user records, and then sold them.
- T-Mobile reaches historic $350 million settlement in 2021 data breach therecord.media T-Mobile on Friday said it agreed to pay $350 million to a group of victims and commit $150 million extra to security upgrades to settle a class-action lawsuit brought in the wake of a 2021 hack of sensitive customer…
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
- jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51


