A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024.

Cameron John Wagenius, 21, who operated online under the handles ‘kiberphant0m’ and ‘cyb3rph4nt0m,’ was arrested in Texas in December 2024. He pleaded guilty in February 2025 to hacking AT&T and Verizon after being charged with unlawfully transferring confidential phone records, and in July 2025 to additional counts of aggravated identity theft, conspiracy to commit wire fraud, and extortion related to computer fraud.

According to court documents, Wagenius, while on active duty, and his accomplices stole login credentials for victim networks using an SSH brute-forcing tool he helped develop. The group used Telegram to exchange stolen credentials and coordinate attacks.

Public and private extortion

Once data was stolen, the Justice Department said Wagenius and his conspirators extorted victim organizations both privately and in public forums, threatening to post the stolen data on cybercrime sites such as BreachForums and XSS.is. In some cases they instead offered the data for sale directly on those forums, successfully monetizing at least some of it. Stolen records were also reused to facilitate further fraud, including SIM-swapping attacks. In total, the group attempted to extort at least $1 million from victims.

Along with the 70-month sentence, Wagenius was ordered to pay $294,978 in restitution for breaching telecom company databases, accessing sensitive customer records, and demanding ransom payments under threat of public data leaks.

Ties to the Snowflake breach campaign

Two of Wagenius’s accomplices, Connor Riley Moucka (known as ‘Waifu’ and ‘Judische’) and John Erin Binns (known as ‘irdev’ and ‘j_irdev1337’), were accused in November 2024 of breaching and stealing terabytes of data from more than 165 organizations that used Snowflake’s cloud storage service, then demanding ransoms to prevent leaks. Moucka was arrested in Canada on October 30, 2024, at the request of U.S. authorities and pleaded guilty to his role in the Snowflake campaign in August 2026.

The Snowflake-linked breaches affected hundreds of millions of people across customers including AT&T, Ticketmaster, Santander, Los Angeles Unified, QuoteWizard/LendingTree, Pure Storage, Advance Auto Parts, and Neiman Marcus. In response, Snowflake began enforcing multi-factor authentication and requiring passwords of at least 14 characters for customer accounts.