Ex-Army Soldier Sentenced for Major Cybercrime Spree Targeting AT&T, Snowflake
A former U.S. Army soldier has been sentenced to 70 months in prison for a wide-ranging cybercrime spree that included attacks on AT&T and Snowflake, resulting in the theft of billions of records and millions in extortion payments.

Cameron John Wagenius, a former active-duty U.S. Army soldier, has been sentenced to 70 months in federal prison for orchestrating a significant cybercrime campaign that spanned years and targeted numerous major organizations. The Justice Department announced the sentencing on Friday, detailing Wagenius's involvement in a spree of attacks and extortion attempts that compromised sensitive data from companies like AT&T and Snowflake.
Wagenius, who pleaded guilty in July 2025, carried out these illicit activities even while serving on active duty at a Texas base. His criminal enterprise involved attempting to sell stolen sensitive information to a foreign intelligence service and expressing interest in defecting to Russia. Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division stated that Wagenius betrayed the trust placed in him as a soldier by conducting this extensive cybercrime campaign.
Authorities revealed that Wagenius attempted to extort over 10 organizations, seeking substantial sums of money. As part of his efforts to extort $500,000 from AT&T, he leaked stolen call records belonging to President Donald Trump, according to research from Unit 221B. While court filings did not name all alleged victims, they indicated Wagenius possessed non-content call detail records of a government official and family members of another former official.
The scope of the attacks became starkly evident with the compromise of AT&T's Snowflake environment in April, which led to the theft of six months of phone and text records for nearly all of its customers. Wagenius, along with co-conspirators Connor Moucka and John Erin Binns, exploited credentials and infiltrated cloud platforms used by companies in the U.S. and abroad. Moucka, extradited from Canada, pleaded guilty to his role in the widespread compromise of over 165 Snowflake customer environments, a major cyberattack in 2024.
Collectively, Wagenius, Moucka, and Binns are accused of stealing billions of sensitive records and receiving over $2.5 million in combined extortion payments. Victims named in connection with the broader attack spree include AT&T, Ticketmaster, Advance Auto Parts, and Santander. Researchers noted that some of the data found on Wagenius's devices at the time of his arrest originated from the Snowflake customer database compromises.
Wagenius, who operated online under aliases such as "kiberphant0m" and "cyb3rph4nt0m," utilized a tool he helped develop called SSH Brute to steal credentials. Prosecutors highlighted that his motivations extended beyond financial gain, including a desire for status within criminal hacking communities. The FBI noted the particular shock of a service member engaging in such privacy violations.
Following his arrest in December 2024, federal agents discovered Wagenius possessed thousands of stolen identification documents and significant amounts of cryptocurrency. Despite orders, he purchased a new laptop and used VPN software to conceal his activities from his barracks at Fort Cavazos, Texas, demonstrating a continued effort to evade detection.
Wagenius was ordered to pay nearly $295,000 in restitution for his crimes. The sentence aims to impose significant consequences and deter future cybercriminal activity, as emphasized by Charles Neil Floyd, first assistant attorney for the U.S. District Court for the Western District of Washington.
The sentencing of U.S. Army soldier Cameron Wagenius, also known as "Kiberphant0m," to 70 months in prison and nearly $300,000 in restitution marks a significant development in the cybercrime spree targeting AT&T and Snowflake. This article further details Wagenius's activities while incarcerated, including attempts to exploit vulnerabilities in the Bureau of Prisons' network and his use of AI tools to research CVEs and potential prison escapes, highlighting an ongoing insider threat even during detention.