From Army Barracks to Federal Penitentiary: The Rise and Fall of ‘Kiberphant0m’

Main Facts
A federal court in Seattle has sentenced 22-year-old Cameron John Wagenius, a former U.S. Army soldier, to 70 months—nearly six years—in federal prison. Wagenius, who operated under the chilling online moniker "Kiberphant0m," pleaded guilty to multiple felony counts stemming from a massive cybercrime and extortion campaign. His actions compromised the sensitive call and text metadata of more than 100 million AT&T customers and targeted dozens of other major telecommunications providers worldwide.
In addition to his prison term, Wagenius was ordered to pay $294,978 in restitution to victims. Despite the staggering scale of the data he and his co-conspirators accessed—which included sensitive logs from high-profile figures and critical infrastructure—prosecutors noted a startling irony: Wagenius earned a meager $1,500 in total profit from his illicit exploits.
The case highlights a dangerous convergence of insider threats, cloud misconfigurations, and international cyber extortion. Operating from an active-duty U.S. military base in South Korea, Wagenius held a secret security clearance, making his transformation into a rogue cybercriminal a high-priority target for a multi-agency federal task force.
Chronology of a Cybercrime Campaign
The unraveling of the "Kiberphant0m" persona maps a rapid trajectory from tactical forum boasting to federal indictment and conviction:
- The Breaches Begin (Early-to-Mid 2024): Exploiting exposed credentials and accounts lacking multi-factor authentication (MFA) on cloud data storage provider Snowflake, Wagenius and his co-conspirators download massive volumes of proprietary corporate data from several major enterprise clients.
- October 2024: Hiding behind the "Kiberphant0m" alias, Wagenius takes to dark web and cybercrime forums to brag about stealing call and text metadata for tens of millions of AT&T customers. He expands his campaign, targeting over a dozen international telecommunications firms—including Verizon’s Push-to-Talk business—and launching public extortion schemes.
- Late November 2024: Cybersecurity journalist Brian Krebs publishes an investigative report warning that the elusive "Kiberphant0m" is likely an active-duty U.S. soldier stationed in South Korea.
- December 2024: Following the public exposure, federal law enforcement fast-tracks its investigation. Wagenius is arrested and hit with two separate federal indictments. He swiftly pleads guilty to all counts.
- September 2025: While incarcerated and awaiting sentencing in a federal holding facility, Wagenius attempts to bypass Bureau of Prisons (BOP) computer use policies. Using fellow inmates’ email accounts, he employs prompt injection techniques on commercial AI tools to research Windows privilege escalation exploits, D-Link router vulnerabilities, and prison escape logistics.
- August 2026: Co-conspirator Conor Riley Moucka (known as "Judische") pleads guilty in Canada for his role in the Snowflake-related extortions.
- Today: Wagenius receives his 70-month prison sentence in Seattle, concluding a high-profile chapter in modern cyber threat mitigation.
Supporting Data and The Co-Conspiracy Web
Wagenius did not act in a vacuum. Federal prosecutors detail a tightly knit network of digital accomplices with extensive criminal backgrounds:
- Kenneth Schuchman (28, Vancouver, Washington): Described as a key assistant in the extortion plots, Schuchman is no stranger to law enforcement. In 2019, he pleaded guilty to operating the notorious "Satori" botnet—a vast weaponized network of hacked Internet-of-Things (IoT) devices responsible for crippling distributed denial-of-service (DDoS) attacks.
- Conor Riley Moucka ("Judische," Kitchener, Ontario): Arrested in Canada in 2024, Moucka played a central role in the Snowflake data thefts and subsequent extortion attempts before pleading guilty in August 2026.
- John Erin Binns (American living in Turkey): Wanted in connection with the massive 2021 T-Mobile data breach that exposed personal data for at least 76 million customers, Binns remains a fugitive linked to the broader orbit of these cybercriminal networks.
The Extortion Escalation and National Security Risks
The syndicate’s tactics turned increasingly reckless following the initial arrests. Even after AT&T reportedly paid a $370,000 Bitcoin ransom to quiet the extortionists, Kiberphant0m engaged in "re-extortion." Seeking to maximize leverage, the hacker published call logs allegedly belonging to then-President-elect Donald Trump and then-Vice President Kamala Harris on hacker forums. Furthermore, the group threatened to release classified schematics allegedly stolen from the U.S. National Security Agency (NSA).
Despite these severe threats, the financial return for Wagenius was remarkably low. While the stolen data held immense theoretical black-market value, Wagenius walked away with a paltry $1,500 in actual cash sales.
Official Responses and Insider Threat Dynamics
The exposure of an active-duty soldier with a secret clearance engaging in high-level cyberattacks triggered an immediate, high-alert response from the U.S. defense and intelligence apparatus.
Paul Russell, a resident agent in charge at the Defense Criminal Investigative Service (DCIS)—the criminal investigative arm of the Department of Defense Office of Inspector General—noted the rarity of the case.
"We don’t often get leads where there’s an active-duty soldier with a secret clearance who’s creating hacking tools and trafficking in data," Russell remarked. "That doesn’t happen every day, and so when that hits, it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with."
The multi-agency task force that brought Wagenius to justice included the DCIS, the Federal Bureau of Investigation (FBI), the Army Criminal Investigative Division (CID), and the U.S. Secret Service.
Institutional Misconduct Behind Bars
Wagenius’s digital audacity did not cease upon his arrest. A sentencing memo filed by federal prosecutors in Seattle on September 19 revealed that while incarcerated and awaiting trial, Wagenius attempted to probe the computer networks of the Bureau of Prisons (BOP).
According to BOP records, Wagenius covertly used other inmates’ email accounts to query commercial Artificial Intelligence tools. Bypassing safety guardrails through sophisticated "prompt injection"—framing his queries around a fictional book he claimed to be writing—Wagenius attempted to extract:
- Specific Common Vulnerabilities and Exposures (CVEs) related to Windows 10 Enterprise privilege escalation.
- Working, un-redacted exploit scripts for D-Link networking vulnerabilities (specifically CVE-2023-45208).
- Instructions on building improvised prison radio antennae using commissary items.
- Direct research into prison escape methodologies.
When confronted by authorities, Wagenius claimed he was merely researching vulnerabilities to hand over to the BOP as a security favor. Prosecutors, however, maintained that no evidence suggested he successfully deployed these exploits within the prison system, though his behavior underscored an unyielding compulsion for digital intrusion.
Implications for Enterprise Security and National Defense
The sentencing of Cameron Wagenius serves as a stark warning regarding modern digital vulnerabilities, supply chain dependencies, and internal security protocols.
- The Cloud Configuration Crisis: The entire enterprise breach sequence hinged on misconfigured cloud storage accounts utilizing Snowflake that failed to enforce multi-factor authentication (MFA). While Snowflake has since mandated MFA across all accounts, the incident underscores how a single administrative oversight can grant unauthorized actors access to records belonging to tens of millions of individuals.
- The Insider Threat Paradigm Shift: Traditional military and corporate vetting processes are traditionally built to catch espionage or physical sabotage. The Wagenius case proves that personnel with low-level or mid-level security clearances can leverage commercial collaboration tools, encrypted communication channels, and cloud vulnerabilities to inflict global disruption from a barracks workstation.
- The Weaponization of Generative AI: The sentencing memo sheds light on an alarming trend: incarcerated or restricted hackers utilizing prompt injection techniques to weaponize public AI models. By framing malicious code requests as hypothetical literary exercises, bad actors are increasingly using AI chatbots as virtual tutors for privilege escalation and exploit development.
Ultimately, while "Kiberphant0m" imagined himself a master extortionist capable of shaking down multinational telecommunications giants and international governments, his story concludes as a cautionary tale of low financial reward, swift international cooperation, and a nearly six-year federal prison sentence.
