US Soldier Jailed Nearly Six Years Over AT&T and Verizon Data Extortion
Cameron John Wagenius, a US Army soldier stationed in South Korea, has been sentenced to 70 months in federal prison and ordered to pay nearly $300,000 in restitution after pleading guilty to hacking multiple telecommunications companies. Operating under the alias 'Kiberphant0m', Wagenius and alleged co-conspirators accessed cloud storage accounts on the Snowflake platform that had exposed credentials and lacked multi-factor authentication protection.
Using this access, the group stole call and text metadata, including source and destination numbers, timestamps and call duration, for tens of millions of AT&T customers, and claimed to have breached more than a dozen telecom firms worldwide, including Verizon's Push-to-Talk business. Kiberphant0m then publicly extorted victim companies, threatening to leak the stolen data unless paid. Investigative reporting linked the persona to a US soldier in South Korea, leading to Wagenius's arrest and guilty plea. Prosecutors say he was assisted by Kenneth Schuchman, previously convicted for operating the Satori IoT botnet used in large-scale denial-of-service attacks.
Snowflake has since made multi-factor authentication mandatory across all customer accounts following this incident, but the case highlights how a single set of exposed credentials without MFA can lead to massive downstream data breaches affecting millions of end users.