Former U.S. Army Soldier Sentenced to 70 Months for Hacking and Extortion Scheme
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and communications companies between April 2023 and December 2024.
Cameron John Wagenius, 21, who used the online aliases “kiberphant0m” and “cyb3rph4nt0m,” was arrested in Texas in December 2024.
Former soldier pleaded guilty to hacking and extortion charges
Wagenius pleaded guilty in February 2025. He was initially indicted on two counts related to the illegal transfer of confidential phone records and hacking involving AT&T and Verizon.
In July 2025, Wagenius was indicted on additional charges, including aggravated identity theft, conspiracy to commit wire fraud, and extortion connected to computer fraud.
According to court documents, Wagenius and his accomplices stole victims’ network login credentials while he was serving on active duty in the U.S. Army. The group used the SSH Brute hacking tool, which they helped develop, to obtain the credentials. They also used Telegram to share stolen credentials and coordinate attacks.
Hackers threatened to publish stolen data on cybercrime forums
After stealing the data, Wagenius and his co-conspirators allegedly blackmailed victim organizations through private messages and public posts. Their extortion attempts included threats to publish stolen information on cybercrime forums such as BreachForums and XSS.is, according to the U.S. Department of Justice.
In other cases, the co-conspirators offered to sell the stolen information for thousands of dollars through posts on those forums. Authorities said they successfully sold at least some of the data and used it to conduct additional fraudulent activities, including SIM swapping.
Overall, Wagenius and his co-conspirators attempted to extort at least $1 million from organizations whose data had been stolen.
Wagenius ordered to pay nearly $295,000 in restitution
In addition to the 70-month prison sentence, Wagenius was ordered to pay $294,978 in restitution. The payment relates to his intrusion into a telecommunications company’s database, where he accessed confidential customer records and threatened to release the stolen data unless the company paid a ransom.
Accomplices linked to Snowflake data breach campaign
Two alleged accomplices, Connor Riley Muka, also known as “Wife” and “Judish,” and John Erin Binns, who used the aliases “irdev” and “j_irdev1337,” are accused of using Snowflake’s cloud services in November 2024 to breach more than 165 organizations and steal terabytes of data.
The attackers allegedly demanded ransom payments in exchange for deleting the stolen information and preventing its publication.
Muka was arrested in Canada on October 30, 2024, at the request of the United States. He admitted his role in the Snowflake hacking campaign in August 2026.
Data breaches associated with the Snowflake attack affected organizations including AT&T, Ticketmaster, Santander, Los Angeles Unified, QuoteWizard and LendingTree, Pure Storage, Advance Auto Parts, and Neiman Marcus.
Snowflake strengthens password and MFA requirements
Following the incidents and the resulting data breaches, Snowflake announced that multifactor authentication (MFA) would be enforced and that customers would be required to choose passwords of at least 14 characters.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



