ThreatPaper
Data BreachExtortion & BlackmailHigh

Cameron Wagenius: the 'kiberphant0m' soldier gets 70 months for the Snowflake-linked telecom extortion spree

By Sethu Satheesh · 29 Sept 2026 · 10 min read

Threat Actor: Cameron John Wagenius ("kiberphant0m"), convicted · Target: U.S. and foreign telecommunications and technology companies (at least 10 charged victim organizations; wider Snowflake campaign)

Source: www.justice.gov


Executive Summary

On the numbers the Justice Department put on the record, Cameron John Wagenius was a 22-year-old U.S. Army soldier, most recently stationed in Texas, who spent the tail end of his active-duty service running an extortion campaign against telecommunications companies under the handle "kiberphant0m."1 On September 25, 2026, the U.S. District Court for the Western District of Washington sentenced him to 70 months in prison and ordered him to pay $294,978 in restitution.1

The conduct the sentence rests on is specific. Between April 2023 and December 18, 2024, Wagenius conspired with others to defraud at least 10 victim organizations by obtaining login credentials to their protected networks — using, among other tools, a credential-attack utility called "SSH Brute" that he helped develop — then threatening to release the stolen data unless the companies paid.1 He and his co-conspirators sought to extort at least $1 million.1 In November 2024 he went further into dangerous territory: he made two online posts disclosing stolen, non-content call detail records belonging to a government official and to family members of another former official, and threatened to release more unless he was paid.1 The Department also stated that Wagenius "sought to traffic stolen information to a foreign intelligence service" — an attempt, in the government's telling, rather than a completed sale.1

Wagenius's case is one thread of the larger 2024 Snowflake extortion campaign. Reporting ties him to Connor Moucka and John Erin Binns; together, per CyberScoop, the three were connected to the "widespread compromise of more than 165 Snowflake customer environments," from which they "stole billions of sensitive records and received more than $2.5 million in extortion payments combined."2 The Justice Department's own charges against Wagenius are narrower than that campaign-wide figure — at least 10 victim organizations and an attempt to extort at least $1 million — and the distinction matters: the 165-environment number describes the whole conspiracy, not one defendant's individual count.12

The detail that drew the most attention was who the leaked phone records belonged to. The Justice Department pointedly did not name the officials, describing only "a government official" and "family members of another former official."1 Reporting filled in the names the government left blank: CyberScoop reported that Wagenius "leaked stolen call records of President Donald Trump as part of multiple failed attempts to extort $500,000 from AT&T," and earlier KrebsOnSecurity reporting associated the AT&T call logs with both then-President-elect Trump and Vice President Kamala Harris.23 Those identities are journalist-sourced; the indictment neither confirms nor denies them.

Verification of Claims

  1. Claim: Wagenius was sentenced to 70 months and ordered to pay $294,978 in restitution. → Verified → The Justice Department's sentencing announcement states the 70-month prison term and the $294,978 restitution order, imposed in the Western District of Washington.1

  2. Claim: Wagenius pleaded guilty and the sentence reflects a conviction, not an accusation. → Verified → Per DOJ, Wagenius pleaded guilty on March 5, 2025, to two counts of unlawful transfer of confidential phone records information, and on July 15, 2025, to conspiracy to commit wire fraud, extortion in relation to computer fraud, and aggravated identity theft. He is a convicted defendant, which is why he is named here.1

  3. Claim: The leaked call records belonged to Donald Trump and Kamala Harris. → Assessed, not confirmed → DOJ deliberately did not name the officials, referring only to "a government official" and "family members of another former official." CyberScoop reported the records included those of President Donald Trump, tied to a failed $500,000 extortion attempt against AT&T; earlier KrebsOnSecurity reporting associated the AT&T call logs with both Trump and Vice President Kamala Harris. The Trump identification is on stronger footing than the Harris one, and both are journalist-sourced rather than confirmed by the indictment.123

  4. Claim: Wagenius tried to sell stolen data to a foreign intelligence service. → Verified as an attempt (per DOJ) → The Justice Department stated Wagenius "sought to traffic stolen information to a foreign intelligence service." The government's language describes an attempt; it does not assert a completed sale, and the service is not named.1

Timeline

Date Actor Event Source
April 2023 Wagenius ("kiberphant0m") Start of the conspiracy period charged by DOJ 1
2024 (mid) Wagenius, Moucka, Binns Snowflake customer-environment compromises across the broader campaign 2
November 2024 Wagenius Posts stolen call detail records of officials; threatens release unless paid 1
December 18, 2024 — End of the charged conspiracy period 1
December 2024 FBI Wagenius arrested in Texas 2
March 5, 2025 Wagenius Pleads guilty to two counts of unlawful transfer of confidential phone records 1
July 15, 2025 Wagenius Pleads guilty to wire-fraud conspiracy, extortion, aggravated identity theft 1
September 25, 2026 W.D. Washington Sentenced to 70 months and $294,978 restitution 1

Attack Anatomy

Credential access — "SSH Brute" and stolen logins

Wagenius and co-conspirators obtained login credentials for victims' protected networks, using among other tools a credential-attack utility called "SSH Brute" that Wagenius helped develop (T1110). Stolen credentials were shared through Telegram group chats.1

Access and data theft from cloud data stores

The broader campaign centred on unauthorized access to Snowflake customer environments using valid-but-stolen credentials for accounts that lacked multi-factor authentication (T1078), from which large volumes of records were taken from the cloud data warehouses (T1530).2

Extortion

Having taken the data, the conspirators threatened to release it unless paid — seeking at least $1 million from Wagenius's victim organizations, and in November 2024 publicly posting stolen official call records with a ransom demand (T1657).1

Loading diagram...

Accused

  • Defendant: Cameron John Wagenius, 22, a former U.S. Army soldier most recently stationed in Texas, who operated online as "kiberphant0m."1 He is named here because he is a convicted defendant — he pleaded guilty and has been sentenced — not merely accused.1
  • Conduct: Conspiring to hack telecommunications companies' databases, access sensitive records, and extort the companies by threatening to release the stolen data, between April 2023 and December 18, 2024, against at least 10 victim organizations.1
  • Wider conspiracy: Reporting ties Wagenius to Connor Moucka and John Erin Binns in the 2024 Snowflake extortion campaign — collectively linked to the compromise of more than 165 Snowflake customer environments and over $2.5 million in extortion payments. Those two are referred to here only as reported; the campaign-wide figures are not the measure of Wagenius's individual charges.2
  • Aggravating detail: DOJ stated Wagenius sought to traffic stolen information to a foreign intelligence service, and that in November 2024 he posted stolen call detail records of officials with a ransom threat.1

MITRE ATT&CK techniques (verified on attack.mitre.org):

ID Technique
T1110 Brute Force
T1078 Valid Accounts
T1530 Data from Cloud Storage
T1657 Financial Theft

Technical Indicators

case:
  defendant: "Cameron John Wagenius, 22 (alias 'kiberphant0m')"
  court: "U.S. District Court, Western District of Washington"
  sentence: "70 months imprisonment"
  restitution_usd: 294978
  conspiracy_period: "April 2023 - 2024-12-18"
  victim_orgs_charged: "at least 10"
  extortion_sought_usd: "at least 1,000,000"
tooling:
  - "SSH Brute (credential-attack tool Wagenius helped develop)"
  - "Telegram group chats (transfer of stolen credentials)"
wider_campaign_context:
  - "Snowflake customer-environment compromises (2024)"
  - "reported co-conspirators: Connor Moucka, John Erin Binns"
  - ">165 Snowflake customer environments; >$2.5M extortion (combined, per reporting)"
network_iocs: "None published in the court record reviewed; this is a sentencing, not a fresh intrusion. Snowflake-campaign IOCs live in the vendor reporting (e.g. Mandiant UNC5537), not in this DOJ release."

This paper is the legal response: a completed federal prosecution. Wagenius pleaded guilty in two tranches — March 5, 2025 (two counts of unlawful transfer of confidential phone records information) and July 15, 2025 (conspiracy to commit wire fraud, extortion in relation to computer fraud, and aggravated identity theft) — and was sentenced on September 25, 2026, to 70 months and $294,978 in restitution.1 The FBI and the Defense Criminal Investigative Service (DCIS) investigated; the U.S. Army's Criminal Investigation Division, the U.S. Attorney's Office for the Western District of Texas, and the National Security Cyber Section assisted.1 The involvement of the National Security Cyber Section and the "foreign intelligence service" element mark this as more than an ordinary extortion case in the government's eyes.1

Impact Assessment

  • Confirmed (per DOJ): A former active-duty soldier conducted, from April 2023 to December 2024, a credential-theft and extortion campaign against at least 10 telecommunications and technology victim organizations, sought at least $1 million, posted stolen official call records with a ransom threat, and sought to traffic stolen data to a foreign intelligence service — resulting in a 70-month sentence and $294,978 restitution.1
  • Reported (not in the indictment): The leaked call records included President Trump's (CyberScoop) and, per earlier KrebsOnSecurity reporting, records associated with Trump and Vice President Harris; Wagenius acted alongside Moucka and Binns in a campaign compromising 165+ Snowflake environments for $2.5M+ combined.23
  • Unknown / unstated: The identities of the officials as a matter of court record; whether the foreign-intelligence trafficking attempt reached any recipient; and the full victim list, which DOJ summarised as "at least 10" rather than enumerating.1

Lessons and Defensive Recommendations

For enterprises (especially SaaS and cloud data platforms):

  • The Snowflake campaign that this case belongs to succeeded overwhelmingly against accounts without multi-factor authentication, accessed with valid stolen credentials. MFA on every account that touches a cloud data warehouse — enforced, not optional — is the single control that would have blunted the whole campaign. Treat credential-only access to a data platform as an unacceptable default.
  • Monitor cloud data stores for anomalous bulk export. The theft here was "log in with stolen creds, pull records at scale"; export-volume and access-pattern alerting on your data warehouse is the detection that catches it when prevention fails.

For telecommunications carriers:

  • Non-content call detail records are extortion-grade data. The reason this case reached the National Security Cyber Section is that CDRs of officials are leverage. Hold them with the same rigor as content, and assume any third-party or cloud system that stores them is a target.

For readers:

  • Keep the individual and the campaign separate. Wagenius's own charged conduct is "at least 10 victim organizations" and "at least $1 million sought"; the widely-cited "165 environments" and "$2.5 million" are the combined campaign with Moucka and Binns. And keep the officials' identities in the category they belong to — reported by journalists, not established by the indictment.

Sources

Footnotes

  1. Former U.S. Soldier Sentenced for Hacking and Extortion Scheme That Exposed Sensitive Data of U.S. Government Official — U.S. Department of Justice, Office of Public Affairs, September 25, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29

  2. Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies — CyberScoop, September 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9

  3. US soldier gets 70 months in prison for extorting 10 tech, telecom firms — BleepingComputer, September 2026 ↩ ↩2 ↩3

Topics: #kiberphant0m#cameron-wagenius#snowflake#telecom-extortion#call-detail-records#att#doj#national-security-cyber-section
Original Incident Report →

Related Research

ShinyHunters says it vished McKesson employees, took over Okta sessions, and pulled a terabyte from Salesforce and Snowflake between 20 and 25 August 2026. McKesson has confirmed exfiltration of patient data and nothing about how.

Data BreachExtortion & BlackmailSocial Engineering

Three men who worked in incident response ran BlackCat attacks. One of them was simultaneously negotiating on behalf of ransomware victims — and passing the attackers his own clients' insurance limits.

RansomwareInsider ThreatExtortion & Blackmail

A financially motivated threat actor (UNC5537) compromised Snowflake customer instances across 165+ organizations by credential stuffing against accounts lacking MFA, exfiltrating terabytes of sensitive data, and conducting mass extortion — the largest cloud data warehouse compromise to date.

Data BreachExtortion & Blackmail