ThreatPaper
Weak Evidence

Wagenius breached 165 Snowflake customer environments

Assessment

The figure of 'more than 165 Snowflake customer environments' describes the entire 2024 Snowflake extortion campaign, which reporting attributes jointly to Wagenius, Connor Moucka and John Erin Binns, along with a combined figure of more than $2.5 million in extortion payments. The Justice Department's charges against Wagenius specifically are narrower: at least 10 victim organizations and an attempt to extort at least $1 million. Attributing the full 165-environment total to Wagenius alone overstates his individual charged role by conflating one defendant with a three-person conspiracy. The 165 number is real, but it is a campaign figure, not a Wagenius figure.

Where this claim appeared

CyberScoop · 2026-09-26

https://cyberscoop.com/cameron-wagenius-att-snowflake-attacks-sentenced/

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

Cameron Wagenius: the 'kiberphant0m' soldier gets 70 months for the Snowflake-linked telecom extortion spree

Think this assessment is wrong? Report an error.