A US Army Soldier’s Decade-Long Cybercrime Spree Ends with 70-Month Prison Sentence
Cameron John Wagenius, a 22-year-old US Army soldier stationed in South Korea, has been sentenced to 70 months in federal prison for his role in hacking into multiple telecommunications companies and stealing sensitive data from over 100 million AT&T customers. The conviction marks the culmination of a long-running cybercrime investigation that involved working with several alleged co-conspirators and extorting victims through online forums.
Wagenius, who adopted the cybercriminal persona “Kiberphant0m,” was able to carry out his nefarious activities despite holding a secret security clearance. He used this access to download data from cloud storage services like Snowflake, which had exposed credentials and weak security measures in place at the time. The stolen metadata included call and text records for tens of millions of AT&T customers, as well as sensitive information from other major telecommunications companies.
Kiberphant0m’s exploits were not limited to the United States; he claimed to have hacked into more than a dozen global telecoms firms, including Verizon’s Push-to-Talk business. He would then extort these companies by threatening to release the stolen data unless they paid a hefty ransom in Bitcoin. The cybercrime forums reveal that Kiberphant0m was brazen about his activities, boasting of his exploits and even sharing sensitive information from high-profile targets, including former President-elect Donald Trump and Vice President Kamala Harris.
The investigation into Wagenius’s activities was led by the Defense Criminal Investigative Service (DCIS) in collaboration with the FBI, Army CID, and US Secret Service. The DCIS notes that receiving a tip about an active-duty soldier with secret clearance involved in cybercrime was a rare occurrence, and it triggered a comprehensive response from all partner organizations.
What’s striking about this case is how Wagenius was able to carry out his activities despite being an insider threat. He pleaded guilty almost immediately after being arrested and has cooperated fully with investigators. However, recent reports suggest that he attempted to exploit vulnerabilities in the Bureau of Prisons’ computer network while incarcerated, highlighting the ongoing concern for security threats from within.
This case serves as a stark reminder of the importance of robust cybersecurity measures, particularly when sensitive information is stored online. It also underscores the need for organizations to enforce strict multi-factor authentication and monitor their cloud storage services closely. While Wagenius’s conviction marks an end to his cybercrime spree, it highlights the ongoing challenges that companies face in protecting themselves against insider threats and external attackers.
For individuals, this case serves as a reminder of the importance of taking cybersecurity seriously, even when dealing with seemingly trusted parties or institutions. By staying informed about online security best practices and being vigilant about potential threats, we can all play our part in preventing such incidents from occurring in the future.
Source: Krebs on Security — 2026-09-25