A former US Army soldier has been handed a 70-month prison sentence for hacking and extorting at least 10 major tech and telecom companies between April 2023 and December 2024. Cameron John Wagenius, who used online handles such as ‘kiberphant0m’ and ‘cyb3rph4nt0m’, was arrested in Texas in December 2024 for his role in the high-profile cybercrime spree.
During this period, Wagenius and his accomplices stole login credentials from their victims using a custom-built hacking tool called SSH Brute. They then used the messaging app Telegram to transfer stolen login details and coordinate their attacks. Once they had access to sensitive systems, the group extorted their targets by threatening to release stolen data online unless they paid up.
The Justice Department revealed that Wagenius and his co-conspirators targeted at least 10 companies, including major players in the tech and telecom sectors. They attempted to extort over $1 million from their victims, often using public forums such as BreachForums and XSS.is to make these demands. In some cases, the group successfully sold stolen data for thousands of dollars.
The scale of the operation was significant, with the group hacking into databases containing sensitive customer records. Wagenius’s accomplices also used this information to commit further crimes, including SIM-swapping – a technique that allows attackers to take control of their victims’ phone numbers and disrupt their communication.
In addition to his prison sentence, Wagenius has been ordered to pay $294,978 in restitution for his role in the hacking operation. This sum reflects the financial losses suffered by his victims as a result of his crimes.
This case is part of a larger crackdown on cybercrime that has seen several high-profile convictions in recent months. In related news, two other individuals have been linked to Wagenius’s group – Connor Riley Moucka and John Erin Binns – who were accused of breaching the databases of over 165 organizations using Snowflake cloud storage. This incident led to massive data breaches affecting hundreds of millions of people.
The case highlights the importance of robust cybersecurity measures, particularly in industries that handle sensitive customer information. As the threat landscape continues to evolve, companies must stay vigilant and invest in robust security protocols – including multi-factor authentication (MFA) and password policies – to protect themselves against these types of attacks.
For individuals and organizations looking to strengthen their defenses, a key takeaway from this case is the importance of monitoring online activities for suspicious behavior. By staying alert and reporting any incidents to the relevant authorities, we can all play our part in preventing cybercrime.
Source: Bleeping Computer — 2026-09-28