U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A former US Army soldier has been sentenced to nearly six years in federal prison for hacking into multiple telecommunications companies and stealing sensitive data from over 100 million AT&T customers. Cameron Wagenius, who adopted the cybercriminal persona “Kiberphant0m,” was also ordered to pay $294,978 in restitution to the victims.

Wagenius’s crimes began in 2024 when he started extorting telecommunications companies, threatening to publish stolen data unless they paid a ransom. He claimed to have hacked into more than a dozen companies worldwide, including Verizon’s Push-to-Talk business. The stolen data included call and text metadata, such as source and destination numbers, timestamps, and durations.

What makes Wagenius’s case particularly disturbing is that he was able to carry out these crimes while still serving in the US Army. As a soldier with secret clearance, he had access to sensitive information and resources that likely aided him in his hacking efforts. His co-conspirators included Kenneth Schuchman, who has a history of cybercrime dating back to 2019 when he pleaded guilty to operating the Satori botnet.

Wagenius’s crimes also raised concerns about national security. He admitted to re-extorting victims and threatening to disclose sensitive information, including schematics allegedly stolen from the US National Security Agency (NSA). In a shocking move, immediately after his co-conspirator Conor Moucka was arrested, Wagenius posted on hacker forums what he claimed were AT&T call logs for then-President-elect Donald Trump and then-Vice President Kamala Harris.

The investigation into Wagenius’s crimes was led by the Defense Criminal Investigative Service (DCIS), which worked alongside the FBI, the Army Criminal Investigative Division (CID), and the US Secret Service. “We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data,” said Paul Russell, a resident agent in charge at DCIS.

Wagenius’s case serves as a reminder of the risks posed by insider threats. While he pleaded guilty almost immediately and has been cooperative, his recent attempts to find security vulnerabilities in the Bureau of Prisons’ computer network raise concerns about his ongoing threat potential. This incident highlights the importance of robust security measures and the need for organizations to remain vigilant against insider threats.

As a result of this case, it’s essential for companies to prioritize multi-factor authentication (MFA) and regularly review their cloud data storage practices to prevent similar breaches in the future. Moreover, organizations should be aware of the potential risks posed by insider threats and take steps to mitigate them, such as conducting regular security audits and monitoring employee activity.


Source: Krebs on Security — 2026-09-25