Interestana
Home/News/US Soldier Sentenced for AT&T, Verizon Data Extortion
Krebs on Security••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

US Soldier Sentenced for AT&T, Verizon Data Extortion

US Soldier Sentenced for AT&T, Verizon Data Extortion

U.S. Army soldier Cameron John Wagenius, 22, was sentenced to 70 months in federal prison on March 18, 2026, for hacking into multiple telecommunications companies and stealing mobile call and text metadata for over 100 million AT&T customers in 2024. He was also ordered to pay nearly $300,000 in restitution to victims. Wagenius, stationed at a U.S. Army base in South Korea, operated under the cybercriminal persona “Kiberphant0m.” He collaborated with three alleged co-conspirators to download data from several large customers of the cloud data storage service Snowflake. These companies had exposed credentials and did not enforce multi-factor authentication, a security measure that Snowflake has since mandated on all accounts. In October 2024, Kiberphant0m boasted on cybercrime forums about acquiring the call and text metadata, including source and destination numbers, timestamps, and duration, for tens of millions of AT&T customers. He claimed to have infiltrated more than a dozen telecommunications companies globally, including Verizon’s Push-to-Talk business, and publicly extorted these entities with threats of publishing the stolen data. In late November 2025, KrebsOnSecurity reported that Kiberphant0m was likely a U.S. soldier stationed in South Korea. Shortly thereafter, Wagenius was apprehended and charged in two separate federal indictments, subsequently pleading guilty to all counts in both cases. During his sentencing hearing in Seattle, Wagenius received a sentence of nearly six years and was mandated to pay $294,978 in restitution. Federal prosecutors indicated that Kenneth Schuchman, a 28-year-old from Vancouver, Washington, with a history of cybercriminal activity, assisted Wagenius in his extortion attempts. Schuchman had previously pleaded guilty in 2019 to operating the Satori botnet, a large network of compromised Internet-of-Things (IoT) devices utilized for extensive distributed denial-of-service attacks. The investigation into Wagenius's activities revealed a pattern of exploiting unsecured cloud data and leveraging it for financial gain through extortion. The scale of the data breach, affecting over 100 million AT&T customers, highlights significant vulnerabilities in data security practices within the telecommunications sector and the cloud storage industry. The involvement of a serving U.S. soldier underscores the complex and evolving nature of cyber threats, with individuals in positions of trust potentially exploiting their access for illicit purposes. The restitution amount ordered reflects the financial impact of the data theft and extortion attempts on the victim companies. The case also brings attention to the ongoing efforts by law enforcement to track and prosecute individuals involved in large-scale cybercrime, even when operating from overseas.

Original source — read the full reporting at the publisher:

Read on Krebs on Security

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next