The United States Department of Justice has handed down the Cameron Wagenius hacking sentence: 70 months in federal prison, plus $294,978 in restitution, for a campaign that targeted at least ten US technology and telecommunications companies between April 2023 and December 2024. Wagenius, 22 at sentencing, is a former US Army soldier who was most recently stationed in Texas and went by the online handles ‘kiberphant0m’ and ‘cyb3rph4nt0m’.
He was arrested in Texas in December 2024 and pleaded guilty in February 2025 to hacking AT&T and Verizon after being charged on two counts of unlawfully transferring confidential phone records. A second guilty plea, entered in July 2025, covered multiple counts of aggravated identity theft, conspiracy to commit wire fraud, and extortion related to computer fraud.
How the Cameron Wagenius Hacking Scheme Worked
According to court documents, Wagenius and his accomplices stole login credentials for victims’ networks using an SSH brute-force hacking tool he helped develop. Stolen credentials were transferred and attacks were coordinated via Telegram. Once inside, the group had considerable reach: daily.dev reports that Wagenius used compromised Snowflake accounts to pull call and text metadata for over 100 million AT&T customers, a figure that underlines just how much damage a single set of stolen credentials can enable.
The extortion phase was conducted both privately and on public cybercrime forums, including BreachForums and XSS.is, where the group threatened to post stolen data unless victims paid up. In other instances, conspirators openly offered stolen data for sale for thousands of dollars a time. The Justice Department stated that Wagenius and his co-conspirators attempted to extort at least $1 million from victim data owners in total, successfully selling at least some of the stolen material and using other portions to conduct SIM-swapping fraud.
There was also a more alarming dimension to Wagenius’s conduct before his arrest. According to CyberScoop, he attempted to sell stolen sensitive data to a foreign intelligence service and had sought information online about defecting to Russia. That detail was not part of his formal charges but paints a picture of someone who had moved well beyond opportunistic cybercrime.
Accomplices and the Wider Snowflake Campaign
Wagenius did not operate alone. Two accomplices, Connor Riley Moucka (known online as ‘Waifu’ and ‘Judische’) and John Erin Binns (known as ‘irdev’ and ‘j_irdev1337’), were accused in November 2024 of breaching and stealing terabytes of data from more than 165 organisations by exploiting accounts on the Snowflake cloud storage platform and demanding ransom payments to delete the stolen information and not leak it online.
Moucka was arrested on 30 October 2024 in Canada at the request of the United States and pleaded guilty to his role in the Snowflake hacking campaign in August 2026. The data breaches linked to those Snowflake attacks affected hundreds of millions of people, with the customer bases of AT&T, Ticketmaster, Santander, Los Angeles Unified, QuoteWizard/LendingTree, Pure Storage, Advance Auto Parts, and Neiman Marcus all caught in the fallout.
In response to the incidents, Snowflake announced it would enforce multi-factor authentication and require customers to choose passwords of at least 14 characters. Whether that counts as barn-door-after-the-horse territory is a reasonable question when the affected customer count runs into nine figures.
The 70-month Cameron Wagenius hacking sentence is the clearest judicial statement yet on the case. Wagenius’s restitution order covers the specific harm to telecom companies whose databases he accessed and whose customers’ records he stole and used as leverage. His co-conspirators’ proceedings continue.

