Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies

A former Army soldier, Cameron John Wagenius, has been sentenced to 70 months in prison for his role in a series of high-profile cyberattacks on major companies, including AT&T and Snowflake. The attacks, which spanned multiple years and involved numerous victims, resulted in the theft of billions of sensitive records and extortion payments totaling over $2.5 million.

Wagenius, who was on active duty at the time of his crimes, used a sophisticated hacking tool called SSH Brute to steal credentials from cloud platforms used by AT&T and other major companies. He then attempted to extort more than 10 organizations for a combined total of over $1 million. The attacks were so brazen that Wagenius even leaked stolen call records of President Donald Trump as part of his extortion attempts.

The scope of the attacks is staggering. Authorities have confirmed that AT&T’s Snowflake environment was compromised in April, resulting in the theft of six months’ worth of phone and text records for nearly all of its customers. But this was just one of many victims; Wagenius and his co-conspirators also targeted Ticketmaster, Advance Auto Parts, Santander, and numerous other organizations.

Wagenius’s motives were not purely financial. According to officials, he was driven by a desire to gain status within the hacking community. He used online aliases such as “kiberphant0m” and “cyb3rph4nt0m” on forums where hackers traded tips and techniques. His online activity suggests that he was deeply involved in the dark web, where stolen data is bought and sold.

The investigation into Wagenius’s activities reveals a shocking level of brazenness. When federal law enforcement seized his devices in December 2024, they found evidence indicating he had access to thousands of stolen identification documents and large amounts of cryptocurrency. What’s even more disturbing is that Wagenius purchased a new laptop against his commanding officer’s order, using it every day over a five-day period in the barracks at Fort Cavazos in Texas with VPN software to hide his identity and location.

The implications of this case are far-reaching. It highlights the threat posed by insider threats – individuals who have access to sensitive information and use that access for malicious purposes. It also underscores the need for robust cybersecurity measures, particularly in high-risk industries such as telecommunications.

As we reflect on Wagenius’s sentence, it’s clear that law enforcement is taking these types of crimes seriously. But what can companies do to protect themselves from similar attacks? The takeaway here is that even with advanced security measures in place, insider threats remain a significant risk. Companies must be vigilant in monitoring their employees’ activities and ensure that they have robust incident response plans in place in the event of a breach.


Source: CyberScoop — 2026-09-25