INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Former US Soldier Sentenced for Hacking AT&T and Verizon
| 2026-09-28 12:36 CRITICAL LOW LAW ENFORCEMENT
Executive Summary
AI-generated
A former US soldier, Cameron John Wagenius, has been sentenced to 70 months in prison for hacking into AT&T and Verizon systems and leaking the call detail records of a government official. The incident occurred between April 2023 and December 2024 while Wagenius was on active duty. He conspired with others, including Canadian national Connor Riley Moucka, also known as Judische, to defraud at least 10 organizations by obtaining credentials for their systems using the SSH Brute utility. This case highlights the growing threat of cybercrime in the US and its potential impact on sensitive government information.
Technical Mitigations AI-generated
• Implementing robust SSH key management and limiting access to authorized personnel can prevent the use of tools like the SSH Brute utility for credential exploitation.
• Regularly monitoring system logs and implementing intrusion detection systems (IDS) can help identify suspicious activity, such as unauthorized login attempts or data exfiltration.
• Utilizing multi-factor authentication (MFA) and rate limiting on sensitive resources can make it more difficult for attackers to gain access using brute-force attacks or other methods.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
a•••••.ka
xs•••••.is
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
SysUpdateSysUpdate
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
defensedefense
governmentgovernment
telecommunicationstelecommunications
Incident Timeline
April 2023
A former U.S. Army soldier hacked and extorted at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024.
Click on any entity below to view its context and source!
general_metric
10 tech
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024.
industry
Technology
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024.
industry
Telecommunications
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024.
organisation
U.S. Army
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024.
October 30, 2024
A former US soldier was arrested in Canada on October 30, 2024, at the request of the United States and subsequently pleaded guilty to his role in the Snowflake hacking campaign.
Click on any entity below to view its context and source!
target_region
United States
Moucka
was arrested
on October 30, 2024, in Canada at the request of the United States and
pleaded guilty
to his role in the Snowflake hacking campaign in August 2026.
source_region
Canada
Moucka
was arrested
on October 30, 2024, in Canada at the request of the United States and
pleaded guilty
to his role in the Snowflake hacking campaign in August 2026.
organisation
Snowflake
Moucka
was arrested
on October 30, 2024, in Canada at the request of the United States and
pleaded guilty
to his role in the Snowflake hacking campaign in August 2026.
November 2024
A former US soldier, identified as Wagenius using the online moniker "kiberphant0m", and conspirators used Snowflake cloud storage services to breach over 165 organizations.
Click on any entity below to view its context and source!
industry
Government
According to court documents, in November 2024, Wagenius publicly disclosed the confidential call detail records of a government official and threatened to release additional confidential records.
victims
165 organizations
"Waifu" and "Judische") and John Erin Binns (aka "irdev" and "j_irdev1337"),
were accused in November 2024
of breaching and stealing terabytes of data from more than 165 organizations using the services of Snowflake cloud storage company and demanding ransom payments to delete the stolen information and not leak it online.
organisation
SSH Brute
Wagenius was using the online moniker “kiberphant0m” and conspired with others to defraud at least 10 organizations by obtaining credentials for their systems using the SSH Brute utility and other tools.
victims
10 organizations
Wagenius was using the online moniker “kiberphant0m” and conspired with others to defraud at least 10 organizations by obtaining credentials for their systems using the SSH Brute utility and other tools.
financial
$1 conspirators
According to the court documents, the conspirators attempted to extort at least $1 million from the victim organizations.
December 2024
A former US Army soldier, Cameron John Wagenius, was arrested in December 2024 and sentenced to 70 months in prison for hacking at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024.
Click on any entity below to view its context and source!
general_metric
10 tech
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024.
industry
Technology
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024.
industry
Telecommunications
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024.
organisation
U.S. Army
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024.
organisation
cyb3rph4nt0
21-year-old Cameron John Wagenius (also known online as 'kiberphant0m' and 'cyb3rph4nt0m' ) was arrested in Texas in December 2024.
February 2025
A former US soldier pleaded guilty in February 2025 to hacking AT&T and Verizon.
Click on any entity below to view its context and source!
tactic
Extortion
In February 2025, he
admitted in court
to sharing confidential phone records, and
in July 2025 pleaded guilty
to wire fraud conspiracy and extortion charges.
He pleaded guilty
in February 2025
to hacking AT&T and Verizon after being charged on two counts of unlawfully transferring confidential phone records, and
in July 2025
to multiple counts of aggravated identity theft, conspiracy to commit wire fraud, and extortion related to computer fraud.
organisation
AT&T
He pleaded guilty
in February 2025
to hacking AT&T and Verizon after being charged on two counts of unlawfully transferring confidential phone records, and
in July 2025
to multiple counts of aggravated identity theft, conspiracy to commit wire fraud, and extortion related to computer fraud.
July 2025
A former US soldier pleaded guilty to hacking AT&T and Verizon in February 2025, later pleading guilty to additional charges related to wire fraud conspiracy and extortion.
Click on any entity below to view its context and source!
tactic
Extortion
In February 2025, he
admitted in court
to sharing confidential phone records, and
in July 2025 pleaded guilty
to wire fraud conspiracy and extortion charges.
He pleaded guilty
in February 2025
to hacking AT&T and Verizon after being charged on two counts of unlawfully transferring confidential phone records, and
in July 2025
to multiple counts of aggravated identity theft, conspiracy to commit wire fraud, and extortion related to computer fraud.
organisation
AT&T
He pleaded guilty
in February 2025
to hacking AT&T and Verizon after being charged on two counts of unlawfully transferring confidential phone records, and
in July 2025
to multiple counts of aggravated identity theft, conspiracy to commit wire fraud, and extortion related to computer fraud.
organisation
Judische
His conspirators include Canadian national Connor Riley Moucka, also known as Judische, and US citizen John Erin Binns, who were involved in hacking
AT&T
,
T-Mobile
, and the
Snowflake hacking campaign
that affected hundreds of organizations.
organisation
US Court
Related:
Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Related:
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Related:
Ukrainian Extradited to US Faces Charges in Jabber Zeus Cybercrime Case
Related:
North Korea Suspected in $351 Million Bitget Crypto Heist
threat_actor
ShinyHunters
Related:
Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Related:
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Related:
Ukrainian Extradited to US Faces Charges in Jabber Zeus Cybercrime Case
Related:
North Korea Suspected in $351 Million Bitget Crypto Heist
organisation
PeopleSoft
Related:
Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Related:
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Related:
Ukrainian Extradited to US Faces Charges in Jabber Zeus Cybercrime Case
Related:
North Korea Suspected in $351 Million Bitget Crypto Heist
organisation
US Faces Charges
Related:
Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Related:
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Related:
Ukrainian Extradited to US Faces Charges in Jabber Zeus Cybercrime Case
Related:
North Korea Suspected in $351 Million Bitget Crypto Heist
financial
$351 Bitget Crypto Heist
Related:
Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Related:
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Related:
Ukrainian Extradited to US Faces Charges in Jabber Zeus Cybercrime Case
Related:
North Korea Suspected in $351 Million Bitget Crypto Heist
financial
$294,978 Wagenius
In addition to the 70-month prison term, Wagenius was ordered to pay $294,978 in restitution.
August 2026
Moucka was arrested in Canada on October 30, 2024, at the request of the United States.
Click on any entity below to view its context and source!
target_region
United States
Moucka
was arrested
on October 30, 2024, in Canada at the request of the United States and
pleaded guilty
to his role in the Snowflake hacking campaign in August 2026.
source_region
Canada
Moucka
was arrested
on October 30, 2024, in Canada at the request of the United States and
pleaded guilty
to his role in the Snowflake hacking campaign in August 2026.
organisation
Snowflake
Moucka
was arrested
on October 30, 2024, in Canada at the request of the United States and
pleaded guilty
to his role in the Snowflake hacking campaign in August 2026.
2026/09/28
A former US soldier was sentenced to 70 months in prison for hacking into AT&T and Verizon systems, extorting victims by threatening to release stolen data on cybercrime forums.
Click on any entity below to view its context and source!
organisation
AT&T
Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon.
organisation
Verizon
A former US soldier was sentenced to 70 months in prison for hacking into AT&T and Verizon systems and leaking the call detail records of a government official.
organisation
BreachForums
The extortion attempts included threats to post the stolen data on cybercrime forums such as BreachForums and XSS.is," the
Justice Department said
.
organisation
Justice Department
The extortion attempts included threats to post the stolen data on cybercrime forums such as BreachForums and XSS.is," the
Justice Department said
.
organisation
Army
The individual, Cameron John Wagenius, 22, a former Army soldier, allegedly hacked into wireless carriers’ databases to retrieve sensitive information and extort the victims, documents presented in court show.
organisation
SSH Brute
According to
court documents
, while on active duty with the U.S. Army, Wagenius and his accomplices stole login credentials for the victim's networks using the SSH Brute hacking tool he helped develop.
organisation
the U.S. Army
According to
court documents
, while on active duty with the U.S. Army, Wagenius and his accomplices stole login credentials for the victim's networks using the SSH Brute hacking tool he helped develop.
financial
$294,978 Wagenius
"
In addition to the 70-month prison sentence, Wagenius was ordered to pay $294,978 in restitution for hacking into telecom companies' databases, accessing sensitive customer records, and extorting the companies under threat of releasing stolen data unless they paid ransoms.
financial
$1 conspirators
In total, Wagenius and his co-conspirators attempted to extort at least $1 million from victim data owners.
organisation
Telegram
They also used Telegram to transfer stolen credentials and plan their attacks.
organisation
SIM
They successfully sold at least some of this stolen data and also used stolen data to perpetuate other frauds, including SIM-swapping.
organisation
QuoteWizard/LendingTree
Ticketmaster
,
Santander
,
Los Angeles Unified
,
QuoteWizard/LendingTree
,
Pure Storage
,
Advance Auto Parts
, and
Neiman Marcus
.
organisation
Neiman
Ticketmaster
,
Santander
,
Los Angeles Unified
,
QuoteWizard/LendingTree
,
Pure Storage
,
Advance Auto Parts
, and
Neiman Marcus
.
organisation
MFA
After these incidents led to massive data breaches, Snowflake
announced
it would enforce multi-factor authentication (MFA) and require customers to choose passwords at least 14 characters long.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tactical Metrics
Metrics
financial
351,000,000
Bitget Crypto Heist
Click for context!
Related:
Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Related:
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Related:
Ukrainian Extradited to US Faces Charges in Jabber Zeus Cybercrime Case
Related:
North Korea Suspected in $351 Million Bitget Crypto Heist
Metrics
victims
10
Organizations
Wagenius was using the online moniker “kiberphant0m” and conspired with others to defraud at least 10 organizations by obtaining credentials for their systems using the SSH Brute utility and other tools.
Metrics
financial
294,978
Financial Impact / Stolen Funds
In addition to the 70-month prison term, Wagenius was ordered to pay $294,978 in restitution.
"
In addition to the 70-month prison sentence, Wagenius was ordered to pay $294,978 in restitution for hacking into telecom companies' databases, accessing sensitive customer records, and extorting the companies under threat of releasing stolen data unless they paid ransoms.
Metrics
financial
1,000,000
Financial Impact / Stolen Funds
According to the court documents, the conspirators attempted to extort at least $1 million from the victim organizations.
In total, Wagenius and his co-conspirators attempted to extort at least $1 million from victim data owners.
Metrics
victims
165
Organizations
"Waifu" and "Judische") and John Erin Binns (aka "irdev" and "j_irdev1337"),
were accused in November 2024
of breaching and stealing terabytes of data from more than 165 organizations using the services of Snowflake cloud storage company and demanding ransom payments to delete the stolen information and not leak it online.
Intelligence Sources
SecurityWeek
2026-09-28
BleepingComputer
2026-09-28
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T06:20
Comprehensive Tactical Telemetry
Highly Correlated Entities
21x
organisation
Identified Entity
AT&T
entity
10x
timeline
Temporal Reference
70 months
date
3x
industry
Targeted Sector
Government
sector
2x
target region
Target Country
United States
country
2x
source region
Origin Country
Korea, Democratic People's Republic of
country
2x
victims
Organizations
10
organizations
2x
financial
Financial Impact / Stolen Funds
294,978
wagenius
Contextual Telemetry
Context Block
7 METRICS
malware
Malware Payload
SysUpdate
tool
source region
Origin Region
DPRK
region
threat actor
APT Group
ShinyHunters
actor
financial
Bitget Crypto Heist
351,000,000
bitget crypto heist
tactic
Cyber Operation Type
Extortion
tactic
general metric
Tech
10
tech
general metric
Characters
14
characters
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.