krebsonsecurity.com 25 Sept 2026, 21:44 UTC

US soldier jailed for stealing call data from 100 million AT&T customers

CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown
Threat Actor
Kiberphant0m

A US Army soldier who admitted hacking several telecommunications companies and stealing mobile call and text metadata linked to more than 100 million AT&T customers has been sentenced to 70 months in federal prison. Cameron John Wagenius, 22, was also ordered to pay US$294,978 in restitution.

While stationed at a US Army base in South Korea, he used the cybercriminal name “Kiberphant0m” and worked with alleged co-conspirators to obtain data from Snowflake customers whose exposed credentials were not protected by multi-factor authentication. He claimed to have targeted more than a dozen telecoms worldwide, including Verizon’s Push-to-Talk business, and attempted to extort companies by threatening to publish the stolen information.

Prosecutors said Wagenius was assisted by Kenneth Schuchman, while Conor Riley Moucka pleaded guilty in August 2026 and John Erin Binns remains wanted in connection with related cases. Wagenius also admitted re-extorting victims and posted material he claimed included call logs belonging to Donald Trump and Kamala Harris, as well as National Security Agency schematics. The investigation involved the FBI, Army Criminal Investigation Division, Defense Criminal Investigative Service and Secret Service.

While awaiting sentencing, Wagenius allegedly used other inmates’ email accounts to ask an AI tool for Windows 10 privilege-escalation CVEs and working exploit code, and for guidance on CVE-2023-45208, a command-injection flaw in D-Link networking devices. Prosecutors said they found no evidence that he deployed vulnerabilities against Bureau of Prisons systems. Despite the scale of the thefts, they said he made only about US$1,500 from selling stolen data.

View full article

Article by CyberSIXT