Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies

A former Army soldier has been sentenced to 70 months in prison for a brazen series of cyberattacks and extortion attempts targeting major companies, including AT&T, Snowflake, and Ticketmaster. Cameron Wagenius, who was on active duty when he committed the crimes, spent over a year and a half carrying out a sweeping cybercrime campaign that resulted in billions of sensitive records being stolen.

Wagenius’s attacks were part of a larger scheme involving multiple co-conspirators, including Connor Moucka, who pleaded guilty to playing a central role in one of the most far-reaching cyberattacks of 2024. The group targeted over 10 organizations, with Wagenius and his associates attempting to extort more than $1 million from their victims. AT&T confirmed that cybercriminals accessed its Snowflake environment in April, stealing six months’ worth of phone and text records for nearly all of its customers.

The attacks were facilitated by a hacking tool called SSH Brute, which Wagenius helped develop while on active duty. He used the tool to steal credentials from victim organizations, and then threatened them privately and publicly with the stolen data. The group also stole billions of sensitive records and received over $2.5 million in extortion payments.

Wagenius’s motivations for the attacks were not solely driven by financial gain. Prosecutors say he was motivated by a desire to achieve status within criminal hacking communities, which is particularly disturbing given his position as an active-duty soldier. As Charles Neil Floyd, first assistant attorney for the U.S. District Court for the Western District of Washington, noted, “His hacking schemes were not only aimed at getting rich, he was also motivated by a desire to achieve status within criminal hacking communities.”

The case highlights the growing threat of insider threats in the cybersecurity landscape. Wagenius’s actions demonstrate that even individuals with access to sensitive information and systems can pose a significant risk to national security and individual privacy. The fact that Wagenius used his position as an active-duty soldier to carry out these attacks is especially shocking, given his sworn duty to defend Americans and their constitutional rights.

The sentence handed down to Wagenius serves as a warning to would-be hackers: engaging in cybercrime will result in real consequences. As federal law enforcement officials noted, Wagenius’s devices were seized during the investigation, revealing evidence of thousands of stolen identification documents and large amounts of cryptocurrency.

For individuals and organizations seeking to protect themselves from similar threats, it’s essential to remain vigilant about insider risks. This includes implementing robust access controls, monitoring user activity, and conducting regular security audits. By taking proactive steps to mitigate insider threats, we can reduce the risk of these types of attacks occurring in the future.


Source: CyberScoop — 2026-09-25