Security News

Former US Army Soldier Sentenced Over AT&T and Snowflake Extortion Spree

CyberScoop · 26 Sept 2026
Key Takeaway Australian SMBs using cloud platforms should enforce multi-factor authentication and unique credentials for every service to prevent stolen logins from cascading into a full data breach.

Cameron John Wagenius, a former US Army soldier, has been sentenced to 70 months in prison for a lengthy cybercrime campaign that targeted AT&T and other major companies, some of which occurred while he was on active duty. Wagenius pleaded guilty in July 2025 after stealing sensitive data, including call records linked to President Trump and other officials, and attempting to extort AT&T for $500,000. Prosecutors say he also tried to sell stolen data to a foreign intelligence service and researched defecting to Russia.

Wagenius worked with co-conspirators Connor Moucka and John Erin Binns to break into cloud environments, including Snowflake accounts used by AT&T and other firms, stealing customer data on a massive scale. AT&T confirmed that attackers accessed its Snowflake environment and stole six months of phone and text records for nearly all of its customers. In total, the group is accused of stealing billions of records and collecting more than $2.5 million in extortion payments from victims including AT&T, Ticketmaster, Advance Auto Parts and Santander.

The case highlights how stolen cloud credentials, rather than sophisticated exploits, were enough to compromise hundreds of organisations relying on the same third-party platform.

Summarised by CISO AI from CyberScoop. We link back to every original so you can read it yourself.