A former US Army soldier has been handed a 70-month prison sentence for orchestrating a complex cyber extortion scheme that targeted at least 10 major technology and telecommunications companies between April 2023 and December 2024. Cameron John Wagenius, who used online handles such as ‘kiberphant0m’ and ‘cyb3rph4nt0m’, pleaded guilty to multiple counts of hacking, identity theft, conspiracy, and extortion related to computer fraud.
Wagenius’s scheme involved stealing login credentials for the victim companies’ networks using a custom-built hacking tool called SSH Brute. He and his accomplices then used the Telegram messaging app to transfer stolen credentials and plan their attacks. Once they had accessed sensitive customer data, Wagenius and his conspirators would extort the victim organizations by threatening to post the stolen information on cybercrime forums like BreachForums and XSS.is. In some cases, they offered to sell the stolen data for thousands of dollars.
The extortion attempts were allegedly successful, with the group attempting to extract at least $1 million from their victims. Wagenius was also ordered to pay $294,978 in restitution for his role in hacking into telecom companies’ databases and extorting them under threat of releasing stolen data unless they paid ransoms.
This case highlights the growing concern of insider threats in cybersecurity. Wagenius’s involvement with the US Army while committing these crimes raises questions about the security measures in place to protect sensitive information within military organizations. The fact that he was able to develop and use a custom-built hacking tool also underscores the need for better threat detection and response capabilities.
The impact of this case extends beyond the companies directly targeted, as the data breaches linked to Wagenius’s scheme affected hundreds of millions of people. This serves as a stark reminder of the importance of robust cybersecurity measures in protecting sensitive customer information.
The investigation into Wagenius’s activities has led to charges against two accomplices, Connor Riley Moucka and John Erin Binns, who were accused of breaching and stealing terabytes of data from over 165 organizations using Snowflake cloud storage. Their case highlights the need for companies to implement robust security measures, including multi-factor authentication (MFA) and regular password rotations.
In light of this case, it is essential for individuals and organizations to prioritize cybersecurity awareness and take steps to protect themselves against cyber threats. This includes implementing robust security protocols, staying up-to-date with the latest threat intelligence, and educating employees on how to identify and report suspicious activity. By doing so, we can reduce the risk of falling victim to similar schemes and minimize the impact of data breaches.
Source: Bleeping Computer — 2026-09-28