Table of Contents
The AT&T and Verizon hacker sentenced to 70 months in prison is a former US Army soldier, Cameron John Wagenius, 22.
A court also ordered $294,978 in restitution for a scheme that ran from April 2023 to December 2024, while he was on active duty.
He pleaded guilty to wire fraud conspiracy and extortion after stealing data from wireless carriers and other organizations.
AT&T and Verizon Hacker Sentenced: Key Takeaway
- A former US soldier got 70 months in prison and must pay $294,978 for stealing data from wireless carriers and extorting victims.
This section contains affiliate links; we may earn a commission at no cost to you.
This case began with stolen credentials and ended with leaked records. These tools help protect logins and personal data:
- 1Password: a password manager that keeps each account on a strong, unique password.
- Passpack: a password manager for storing and sharing credentials for teams and individuals.
- Optery: personal data removal, which reduces how much of your information is exposed online.
Who Is the AT&T and Verizon Hacker Sentenced in This Case?
A soldier who became a cybercriminal
Cameron John Wagenius is a 22 year old former Army soldier. According to SecurityWeek, he carried out his hacking while serving on active duty, from April 2023 until December 2024. Authorities arrested him in December 2024.
The timeline matters because it shows the activity lasted about a year and a half. It was not a single lapse in judgment but a sustained campaign that continued until law enforcement stepped in.
The alias kiberphant0m
Online, Wagenius used the alias “kiberphant0m.” Cybercriminals often work under handles on forums where stolen data, hacking tools and extortion threats circulate. The alias let him operate and build a reputation without using his real name.
He did not act alone. It is reports that he conspired with others to defraud at least 10 organizations.
Sentence and Charges
70 months in prison plus restitution
A US court sentenced Wagenius to 70 months in prison, which is just under six years. It also ordered him to pay $294,978 in restitution. Restitution is money a defendant must pay to compensate victims for their losses.
The restitution figure ties the penalty to the financial harm caused by the scheme, not only to the prison term.
Wire fraud conspiracy and extortion
Wagenius pleaded guilty to two charges: wire fraud conspiracy and extortion. Wire fraud conspiracy means agreeing with others to carry out a fraud that uses electronic communications. Extortion means demanding money or something else of value by threatening harm, which here meant threatening to publish stolen information.
Together, the charges describe both halves of the scheme: taking data and then using threats to profit from it.
Timeline of the case
November 2024: a public disclosure
In November 2024, Wagenius publicly disclosed confidential call detail records belonging to a government official. He also threatened to release more confidential records from AT&T and Verizon.
December 2024: arrest
Authorities arrested him in December 2024, the same month the hacking period ended.
February 2025: a court admission
In February 2025, Wagenius admitted in court to sharing confidential phone records.
July 2025: guilty plea
In July 2025, he pleaded guilty to wire fraud conspiracy and extortion.
September 2026: sentence reported
SecurityWeek reported the 70 month sentence on September 28, 2026.
How the Scheme Worked
Stealing credentials with SSH Brute
The conspiracy used a utility called SSH Brute and other tools to obtain system credentials. SSH, short for Secure Shell, is a common protocol for logging in to remote servers. A brute force tool tries many username and password combinations until one works, so weak or reused passwords are its main target.
A credential is the login information that proves a user is allowed into a system. Once an attacker holds valid credentials, they can often act like a normal user and avoid raising alarms.
Accessing systems and exfiltrating data
With those credentials, the conspirators accessed victim systems and exfiltrated data. Exfiltration means copying data out of a network without permission. The step turns a break in into a theft, and it gives the attackers leverage.
Extortion on private and public forums
The group extorted victims on both private and public forums. Their method was to threaten to publish the stolen information unless the victim paid. Posting threats in public adds pressure, because the victim’s customers, partners and regulators may see them.
Selling and reusing stolen data
The conspirators also sold stolen data through cybercrime forums. They used it for additional fraudulent activities as well. Stolen data therefore had several lives: it was leverage for ransom, an item for sale and a tool for more fraud.
A target of at least $1 million
SecurityWeek reports that the group attempted to extort at least $1 million from victim organizations. The source does not say how much was actually paid.
The Call Detail Records Leak
What call detail records are
Call detail records, often called CDRs, are logs that describe phone activity. They typically show who contacted whom, when and for how long, rather than what was said. Carriers such as AT&T and Verizon hold them for billing and network management.
That metadata can still be sensitive. It can reveal relationships, routines and movements, which is why a leak involving a government official drew attention.
Why the November 2024 disclosure stood out
Wagenius made confidential call detail records of a government official public, and he threatened further releases from AT&T and Verizon. The move signaled that the carriers held data the group was prepared to expose.
The disclosure also became part of the record. In February 2025, he admitted in court to sharing confidential phone records.
Accomplices and Related Cases
Connor Riley Moucka
Connor Riley Moucka, a Canadian national who used the alias “Judische,” is described as an accomplice. He pleaded guilty in August. SecurityWeek links him to hacking campaigns against AT&T, T-Mobile and Snowflake.
Snowflake is a cloud data platform used by many companies to store and analyze information. Campaigns aimed at it are significant because one compromised platform can lead to data from many customers.
John Erin Binns
John Erin Binns, a US citizen, was involved in the same hacking campaigns, according to the source. SecurityWeek does not detail his current legal status.
The trio shows how modern cybercrime can involve people in different countries who cooperate through online forums.
Official Statements
CyberScoop, reporting on the case, quotes Assistant Attorney General A. Tysen Duva saying Wagenius spent more than a year and a half betraying the trust placed in him as a soldier. That framing puts his military service at the center of the government’s case.
CyberScoop also reports the Justice Department’s view of the wider group. It says the conspirators together stole billions of records, received more than $2.5 million in extortion payments, and that Wagenius was directly involved in more than $1 million in attempted extortions. Readers should treat those totals as figures attributed to prosecutors in that report. They do not appear in the SecurityWeek article.
The Record also covered the sentence in its own report on the case.
Implications of a Military Hacker Targeting Telecom Data
The facts of this case point to several lessons for defenders. The points below are analysis based on the reported facts.
Implications for telecom carriers and their customers
Wireless carriers sit on large stores of data that criminals value, including call detail records. When attackers reach those systems, the harm extends beyond the company to its customers and to anyone whose activity appears in the records.
The leak of a government official’s records shows that even metadata can become a lever for pressure. Carriers must therefore protect logs with the same care as content.
Implications for organizations facing extortion
The scheme combined data theft with public threats and sales on forums. That pattern means a victim cannot solve the problem by restoring systems alone, because the attacker already holds a copy of the data.
Organizations should plan for the case where stolen data is used as leverage. That planning includes legal advice, communications plans and an incident response process. Our overview of what cyber incident response involves explains the basics.
Implications for credential security
Tools such as SSH Brute rely on weak or exposed passwords. Strong unique passwords, multi factor authentication and limits on repeated login attempts make that route far harder.
Credential attacks remain common. For a related example, see our report on password spraying attacks against Citrix NetScaler.
Implications for deterrence and law enforcement
A 70 month sentence and a restitution order send a message that hacking and extortion carry real penalties, including for people with military training or service records. The case also shows investigators can trace activity across forums, aliases and several years.
Related prosecutions point the same way. See our coverage of the Raccoon infostealer operator sentenced and the trail of Scattered Spider suspects. SecurityWeek also covered the guilty plea of the owner of the Rydox marketplace.
Implications for individuals
Most people cannot stop a carrier breach, but they can limit the damage. A password manager reduces the risk of reused logins. Removing personal information from data broker sites reduces what criminals can combine with leaked records. <div style=”background-color:#f3f3f3; border-left:10px solid #1a5fb4; padding:16px; border-radius:6px;”>
This section contains affiliate links; we may earn a commission at no cost to you.
Organizations that hold sensitive data can strengthen their defenses with these tools:
- CyberUpgrade: cybersecurity compliance and management for teams formalizing their controls.
- Auvik: network monitoring and management that helps teams see what is happening on their networks.
- Tresorit: encrypted cloud storage for keeping sensitive files protected.
Looking Forward
Wagenius’s sentence closes a case that ran from the hacking period in 2023 through his arrest in December 2024, his plea in July 2025 and the sentence reported in September 2026.
The scheme relied on stolen credentials, data theft and extortion, and it touched wireless carriers and at least 10 organizations.
Other people named in the wider campaigns have their own cases. Defenders should focus on the basics the case highlights: protect credentials, watch for data leaving the network and prepare for extortion before it happens.
Questions Worth Answering
Who was sentenced?
- Cameron John Wagenius, a 22 year old former US Army soldier who used the alias “kiberphant0m.”
How long is the sentence?
- The court sentenced him to 70 months in prison and ordered $294,978 in restitution.
What did he plead guilty to?
- He pleaded guilty to wire fraud conspiracy and extortion in July 2025.
When did the hacking take place?
- The hacking ran from April 2023 to December 2024, while he was on active duty.
How did the group get into systems?
- They used a utility called SSH Brute and other tools to obtain system credentials.
What did the group do with stolen data?
- They exfiltrated it, threatened to publish it, sold it on cybercrime forums and used it for further fraud.
How much did they try to extort?
- They attempted to extort at least $1 million from victim organizations.
What did he leak in November 2024?
- He publicly disclosed confidential call detail records of a government official and threatened to release more from AT&T and Verizon.
Who else was involved?
- Connor Riley Moucka, who pleaded guilty, and John Erin Binns, both linked to campaigns against AT&T, T-Mobile and Snowflake.
Sources:
- Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon, SecurityWeek
- Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies, CyberScoop
- Former US soldier gets nearly six year sentence for hacking, extorting telecoms, The Record