Cameron John Wagenius, a 22-year-old former U.S. Army soldier, has been sentenced to 70 months in federal prison for orchestrating a significant cybercrime campaign. Operating under the aliases 'kiberphant0m' and 'cyb3rph4nt0m', Wagenius targeted at least 10 U.S. companies, including major telecommunications providers like AT&T, stealing sensitive customer and business data. The attacks, conducted between April 2023 and December 2024 while he was on active duty, involved exploiting vulnerabilities and stolen credentials, including attacks related to the 2024 Snowflake data breaches. Wagenius and his co-conspirators attempted to extort over $1 million from their victims and even tried to sell stolen data to a foreign intelligence service. The sentence includes nearly $295,000 in restitution and highlights a severe breach of trust by a member of the armed forces.
The cybercrime campaign led by Cameron John Wagenius was extensive and sophisticated. While on active duty in South Korea and at Fort Cavazos, Texas, he engaged in a conspiracy to hack into corporate networks, steal data, and extort his victims.
Attack Methodology:
The operation demonstrates several key TTPs:
His attempt to sell data to a foreign intelligence service elevates the case from simple cybercrime to an act with potential national security implications.
The impact on the victim organizations was significant, involving financial costs, reputational damage, and regulatory scrutiny. The theft of sensitive customer PII and call data from telecommunications giants like AT&T and Verizon constitutes a major privacy breach. The restitution order of nearly $300,000 likely only covers a fraction of the total cost incurred by the victims for incident response, legal fees, and customer notifications. For the U.S. Army, the actions of one of its soldiers engaging in such widespread criminal activity while on active duty represent a serious security and disciplinary failure.
No specific file hashes, IP addresses, or domains were listed as Indicators of Compromise in the source articles.
To detect activity similar to the 'kiberphant0m' campaign, organizations should monitor for:
Enforce MFA on all accounts, especially for access to sensitive cloud data platforms, to prevent unauthorized access even with compromised credentials.
Mapped D3FEND Techniques:
Implement strong password policies to make brute-force and password guessing attacks more difficult.
Implement account lockout policies to thwart brute-force attacks against SSH and other services.
The attacks involving the Snowflake cloud platform were largely enabled by compromised credentials. Implementing mandatory multi-factor authentication (MFA) for all users accessing the Snowflake environment would have been a powerful mitigating control. Even with valid usernames and passwords obtained through other means, the attackers would have been blocked without the second authentication factor. This should be applied not just to Snowflake but to all critical corporate resources, especially cloud-based data warehouses and administrative portals. This single control is the most effective way to prevent unauthorized access resulting from credential theft, which was a cornerstone of Wagenius's operation.
The development and use of the 'SSH Brute' tool indicates a reliance on brute-force or password-guessing attacks. A fundamental defense against this is a robust account lockout policy. For any externally exposed authentication service, such as SSH, configure a policy to temporarily lock an account after a small number of failed login attempts (e.g., 5 attempts within 5 minutes). This dramatically increases the time and resources required for a successful brute-force attack, often making it impractical. This policy should be paired with strong alerting to notify security teams of repeated failed logins, which can serve as an early indicator of a targeted attack.
Cameron Wagenius begins his cybercrime campaign.
The cybercrime campaign conducted by Wagenius ends.
Cameron Wagenius is sentenced to 70 months in federal prison.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.