Security News

Former US Soldier Jailed Over Telecom Hacking and Extortion Spree

The Register · 28 Sept 2026
Key Takeaway Regularly rotate and monitor privileged network credentials, since stolen logins remain one of the most common ways attackers gain access and extort businesses.

Cameron John Wagenius, who served on active duty in South Korea and Texas, has been sentenced to 70 months in prison after pleading guilty to hacking telecom companies, stealing confidential records, and attempting large-scale extortion. Between April 2023 and December 2024, he conspired with three others to obtain login credentials for at least ten organisations' protected networks, using a custom hacking tool and trading stolen credentials through Telegram group chats.

The group stole hundreds of thousands of customer records and advertised the stolen data for sale or ransom across platforms including XSS, BreachForums, X, and Telegram. Some victims were threatened with public data leaks unless they paid, while other stolen records were used to commit fraud, including SIM swapping. Wagenius, operating under the alias "kiberphant0m," has also been linked to the 2024 Snowflake extortion campaign that affected major telecom providers.

A US District Judge condemned Wagenius's actions as motivated by greed and a desire for notoriety, ordering him to pay nearly $295,000 in restitution alongside his prison sentence. The case highlights how stolen credentials and weak access controls can be exploited at scale, even by attackers without deep technical resources.

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.