Security News

Former US Soldier Sentenced to Nearly Six Years for Telecom Hacking and Extortion

The Record · 28 Sept 2026
Key Takeaway Businesses relying on third-party data platforms should enforce strong credential hygiene and monitor for unauthorised access, since stolen logins were the entry point for this large-scale breach.

Cameron John Wagenius, 22, a former active duty soldier, has been sentenced to 70 months in federal prison and ordered to pay nearly $295,000 in restitution after pleading guilty to wire fraud, extortion and aggravated identity theft. While stationed in South Korea and later at Fort Cavazos in Texas, Wagenius worked with two other hackers between April 2023 and December 2024 to breach several US telecommunications companies and steal thousands of sensitive call records.

Using stolen login credentials, Wagenius and his associates broke into company systems and demanded at least $1 million in ransom to prevent the release of the data. Officials said he even attempted to sell stolen information to a foreign intelligence service. In November 2024, he posted online claiming to hold confidential call records belonging to a government official and family members of a former official, threatening further leaks unless paid.

The case is linked to a wider 2024 campaign targeting more than 100 customers of data storage provider Snowflake, including AT&T, where stolen metadata exposed nearly all customer calls and texts over a six-month period in 2022. Operating under the username 'kiberphant0m,' Wagenius allegedly used a self-built tool to breach at least ten organisations.

Summarised by CISO AI from The Record. We link back to every original so you can read it yourself.