<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/us-soldier-sentenced-to-70-months-for-hacking-at-t-verizon-and-extorting-telecom-firms-cqrxtjljd" -->

---
title: US soldier sentenced to 70 months for hacking AT&T,...
description: Cameron John Wagenius, a U.S. Army soldier known online as kiberphant0m, was sentenced to 70 months in federal prison and ordered to pay $294,978 in...
canonical: https://daily.dev/posts/us-soldier-sentenced-to-70-months-for-hacking-at-t-verizon-and-extorting-telecom-firms-cqrxtjljd
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: US soldier sentenced to 70 months for hacking AT&T, Verizon and extorting telecom firms | daily.dev
og:description: Cameron John Wagenius, a U.S. Army soldier known online as kiberphant0m, was sentenced to 70 months in federal prison and ordered to pay $294,978 in...
og:url: https://daily.dev/posts/us-soldier-sentenced-to-70-months-for-hacking-at-t-verizon-and-extorting-telecom-firms-cqrxtjljd
og:image: https://api.daily.dev/og/posts/CqRxTjLjd.png
og:image:alt: US soldier sentenced to 70 months for hacking AT&T, Verizon and extorting telecom firms
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# US soldier sentenced to 70 months for hacking AT&T, Verizon and extorting telecom firms

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 0 upvotes · 0 comments

## Summary

Cameron John Wagenius, a U.S. Army soldier known online as kiberphant0m, was sentenced to 70 months in federal prison and ordered to pay $294,978 in restitution for hacking and extorting at least 10 tech and telecom companies between April 2023 and December 2024. He and accomplices built a custom SSH brute-forcer to steal credentials, then used them to access MFA-less Snowflake accounts, pulling call and text metadata for over 100 million AT&T customers. He extorted victims via Telegram, threatening leaks on BreachForums and XSS.is, attempting over $1 million in extortion but netting only around $1,500. The case ties into the broader Snowflake breach campaign involving Connor Riley Moucka and John Erin Binns that also hit Ticketmaster and Santander, prompting Snowflake to make MFA mandatory. While awaiting sentencing, he was caught using other inmates' email accounts to prompt AI tools for exploit code targeting Windows privilege escalation CVEs and a D-Link vulnerability, framing it as book research.

## Content

Cameron John Wagenius, a former U.S. Army soldier who operated online as "kiberphant0m," was sentenced to 70 months in federal prison and ordered to pay $294,978 in restitution for hacking and extorting at least 10 U.S. tech and telecom companies between April 2023 and December 2024.

## What he did

Wagenius and accomplices used a self-developed SSH brute-forcing tool to steal login credentials, then accessed Snowflake cloud accounts that lacked multi-factor authentication. Through those accounts, he stole call and text metadata from over 100 million AT&T customers, among other victims.

He coordinated the operation via Telegram and threatened to publish stolen data on forums like BreachForums and XSS.is unless companies paid up. In total, he attempted to extort over $1 million across his targets. Despite the scale of the operation, he reportedly earned only around $1,500 from actually selling stolen data.

Beyond the telecom records, he also threatened to leak NSA schematics and call logs belonging to political figures.

## The Snowflake connection

The case ties into the broader Snowflake data-theft campaign that affected hundreds of millions of people across AT&T, Ticketmaster, Santander, and other organizations. Wagenius's co-conspirators in that campaign were Connor Riley Moucka and John Erin Binns, both of whom face separate charges. Following the breaches, Snowflake moved to enforce mandatory MFA and stricter password requirements.

## Trying to find exploits from jail

While awaiting sentencing, Wagenius was caught using fellow inmates' email accounts to prompt AI tools for working exploit code. He was looking for Windows privilege escalation exploits and a D-Link command injection vulnerability (CVE-2023-45208), framing the requests as research for a book he claimed to be writing. It didn't work, but it's a notable example of someone attempting to use AI tools as a jailbreak workaround from inside an actual jail.

## Questions this post answers

### Why did Snowflake make multi-factor authentication mandatory for all accounts?

Snowflake required MFA and tightened password requirements after attackers used stolen credentials from an SSH brute-forcing tool to access customer accounts that lacked MFA protection. This exposure was exploited in a wide campaign, including by Cameron Wagenius, who used compromised Snowflake accounts to pull call and text metadata for over 100 million AT&T customers.

_Track how cloud platforms like Snowflake tighten authentication defaults after breaches on daily.dev._

### How did attackers access AT&T customer data through Snowflake accounts?

Attackers used a custom SSH brute-forcing tool to steal login credentials, then used those credentials to log into Snowflake cloud accounts that had no multi-factor authentication enabled. From those accounts, they extracted call and text metadata for more than 100 million AT&T customers, later using the stolen data to extort the company and threaten public leaks.

_Developers securing cloud data platforms can follow breach patterns like this one on daily.dev._

## Similar posts on daily.dev

- [Man gets six years for hacking 750 women's Snapchat accounts](https://daily.dev/posts/man-gets-six-years-for-hacking-750-women-s-snapchat-accounts-kqhkwsac8) · BleepingComputer · 0 upvotes · 0 comments
- [Rogue techie pleads guilty in $862K employer attack](https://daily.dev/posts/rogue-techie-pleads-guilty-in-862k-employer-attack-bbys5oseo) · The Register · 0 upvotes · 0 comments
- [DraftKings hacker 'Snoopy' sentenced to 18 months in prison](https://daily.dev/posts/draftkings-hacker-snoopy-sentenced-to-18-months-in-prison-cxgj8kyvy) · BleepingComputer · 1 upvotes · 0 comments
- [Inside the story of the US defense contractor who leaked hacking tools to Russia](https://daily.dev/posts/inside-the-story-of-the-us-defense-contractor-who-leaked-hacking-tools-to-russia-epgltufkf) · TechCrunch · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#authentication](https://daily.dev/tags/authentication), [#data-breach](https://daily.dev/tags/data-breach), [#snowflake](https://daily.dev/tags/snowflake)

[View this post on daily.dev](https://daily.dev/posts/us-soldier-sentenced-to-70-months-for-hacking-at-t-verizon-and-extorting-telecom-firms-cqrxtjljd)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"US soldier sentenced to 70 months for hacking AT&T, Verizon and extorting telecom firms","url":"https://daily.dev/posts/us-soldier-sentenced-to-70-months-for-hacking-at-t-verizon-and-extorting-telecom-firms-cqrxtjljd","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/us-soldier-sentenced-to-70-months-for-hacking-at-t-verizon-and-extorting-telecom-firms-cqrxtjljd"},"datePublished":"2026-09-28T08:23:59.338Z","dateModified":"2026-09-28T14:40:20.171Z","description":"Cameron John Wagenius, a U.S. Army soldier known online as kiberphant0m, was sentenced to 70 months in federal prison and ordered to pay $294,978 in...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d45553870c88f04f875072f4ad78d649?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d45553870c88f04f875072f4ad78d649?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/us-soldier-sentenced-to-70-months-for-hacking-at-t-verizon-and-extorting-telecom-firms-cqrxtjljd","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,authentication,data-breach,snowflake","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"US soldier sentenced to 70 months for hacking AT&T, Verizon and extorting telecom firms"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/us-soldier-sentenced-to-70-months-for-hacking-at-t-verizon-and-extorting-telecom-firms-cqrxtjljd#faq","mainEntity":[{"@type":"Question","name":"Why did Snowflake make multi-factor authentication mandatory for all accounts?","acceptedAnswer":{"@type":"Answer","text":"Snowflake required MFA and tightened password requirements after attackers used stolen credentials from an SSH brute-forcing tool to access customer accounts that lacked MFA protection. This exposure was exploited in a wide campaign, including by Cameron Wagenius, who used compromised Snowflake accounts to pull call and text metadata for over 100 million AT&T customers. Track how cloud platforms like Snowflake tighten authentication defaults after breaches on daily.dev."}},{"@type":"Question","name":"How did attackers access AT&T customer data through Snowflake accounts?","acceptedAnswer":{"@type":"Answer","text":"Attackers used a custom SSH brute-forcing tool to steal login credentials, then used those credentials to log into Snowflake cloud accounts that had no multi-factor authentication enabled. From those accounts, they extracted call and text metadata for more than 100 million AT&T customers, later using the stolen data to extort the company and threaten public leaks. Developers securing cloud data platforms can follow breach patterns like this one on daily.dev."}}]}
```

