Former U.S. Army soldier Cameron John Wagenius, known online as kiberphant0m and cyb3rph4nt0m, was sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies from April 2023 through December 2024. He pleaded guilty to wire-fraud conspiracy, computer-fraud-related extortion, aggravated identity theft, and unlawful transfers of confidential phone records, and was ordered to pay $294,978 in restitution.
Wagenius and co-conspirators used stolen network credentials—including credentials obtained through the SSH Brute tool he helped develop—to access victim systems, steal data, demand ransoms, and sell stolen information through Telegram, BreachForums, and XSS.is. Prosecutors said the group sought at least $1 million and used compromised records in SIM-swapping fraud; the activity was also linked to the 2024 Snowflake customer-data theft and extortion campaign, which affected more than 165 organizations, including AT&T.

See the reporting duties and controls this puts on the clock.
12 events from the most recent confirmed update back to the earliest known activity.
Moucka pleaded guilty for his role in the Snowflake hacking campaign.
Wagenius pleaded guilty to conspiracy to commit wire fraud, computer-fraud-related extortion, and aggravated identity theft.
Wagenius pleaded guilty to hacking AT&T and Verizon and to two counts of unlawfully transferring confidential phone records.
Authorities arrested Wagenius in Texas following the telecom and technology company intrusion and extortion campaign.
Wagenius published two posts disclosing confidential call records belonging to a government official and relatives of a former official, and threatened further releases unless paid.
Connor Riley Moucka and John Erin Binns were accused of stealing terabytes of data from more than 165 organizations through Snowflake services and demanding ransom payments.
Canadian authorities arrested alleged Wagenius accomplice Connor Riley Moucka at the request of the United States in connection with the Snowflake-related campaign.
AT&T disclosed that attackers had stolen call and text records involving nearly all of its cellular customers from its Snowflake account.
A Snowflake-related campaign used stolen credentials to access customer accounts lacking multifactor authentication, steal data, and demand ransoms. The activity affected more than 165 organizations, including AT&T, Ticketmaster, Santander, and other companies.
Cameron John Wagenius and co-conspirators obtained credentials for at least 10 organizations, accessed victim networks, stole data, and extorted organizations. The group used SSH Brute, Telegram, BreachForums, and XSS.is, and also sold data and used it in fraud including SIM-swapping.
Attackers stole call and text records involving nearly all AT&T cellular customers over a six-month period in 2022 from AT&T's Snowflake account.
A court sentenced Wagenius to 70 months in prison and ordered $294,978 in restitution for hacking and extorting technology and telecommunications companies. Prosecutors said the group attempted to extort at least $1 million.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcenextgov.com
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.