Former US Soldier Sentenced for Hacking and Extortion

Ex-US Soldier 'kiberphant0m' Jailed for Hacking Telecom Giants

MEDIUM
September 28, 2026
5m read
Threat ActorPolicy and ComplianceData Breach

Related Entities

Threat Actors

kiberphant0m

Organizations

U.S. Army

Products & Tech

Other

Cameron John WageniusAT&T Verizon BreachForumsXSS.isSSH Brute

Full Report

Executive Summary

Cameron John Wagenius, a 22-year-old former U.S. Army soldier, has been sentenced to 70 months in federal prison for orchestrating a significant cybercrime campaign. Operating under the aliases 'kiberphant0m' and 'cyb3rph4nt0m', Wagenius targeted at least 10 U.S. companies, including major telecommunications providers like AT&T, stealing sensitive customer and business data. The attacks, conducted between April 2023 and December 2024 while he was on active duty, involved exploiting vulnerabilities and stolen credentials, including attacks related to the 2024 Snowflake data breaches. Wagenius and his co-conspirators attempted to extort over $1 million from their victims and even tried to sell stolen data to a foreign intelligence service. The sentence includes nearly $295,000 in restitution and highlights a severe breach of trust by a member of the armed forces.


Threat Overview

The cybercrime campaign led by Cameron John Wagenius was extensive and sophisticated. While on active duty in South Korea and at Fort Cavazos, Texas, he engaged in a conspiracy to hack into corporate networks, steal data, and extort his victims.

Attack Methodology:

  • Initial Access: The group gained access by stealing login credentials. They developed and used a custom tool named 'SSH Brute' for brute-forcing SSH servers (T1110.001 - Password Guessing). They also exploited weaknesses related to the Snowflake cloud data platform, which was the vector for a series of major breaches in 2024.
  • Data Theft: Once inside the networks, they exfiltrated hundreds of thousands of sensitive records. This included customer PII, non-content call and text history, and other proprietary telecommunication data (T1530 - Data from Cloud Storage Object).
  • Extortion: The group then contacted the victim companies, demanding over $1 million in total. They threatened to leak the stolen data on notorious cybercrime forums like BreachForums and XSS.is if the ransom was not paid (T1658 - Extortion).

Technical Analysis

The operation demonstrates several key TTPs:

  • T1078 - Valid Accounts: The core of the campaign relied on obtaining and using legitimate credentials to access corporate systems and cloud environments like Snowflake.
  • T1110 - Brute Force: The development and use of the 'SSH Brute' tool shows a commitment to this common but often effective access method.
  • T1213 - Data from Information Repositories: The attackers specifically targeted and exfiltrated data from large databases and cloud storage repositories.
  • Insider Threat (by association): While Wagenius was an external threat to the companies, his status as a U.S. soldier committing these crimes represents a form of insider threat to the military, abusing his position and access for criminal gain.

His attempt to sell data to a foreign intelligence service elevates the case from simple cybercrime to an act with potential national security implications.

Impact Assessment

The impact on the victim organizations was significant, involving financial costs, reputational damage, and regulatory scrutiny. The theft of sensitive customer PII and call data from telecommunications giants like AT&T and Verizon constitutes a major privacy breach. The restitution order of nearly $300,000 likely only covers a fraction of the total cost incurred by the victims for incident response, legal fees, and customer notifications. For the U.S. Army, the actions of one of its soldiers engaging in such widespread criminal activity while on active duty represent a serious security and disciplinary failure.

IOCs — Directly from Articles

No specific file hashes, IP addresses, or domains were listed as Indicators of Compromise in the source articles.

Cyber Observables — Hunting Hints

To detect activity similar to the 'kiberphant0m' campaign, organizations should monitor for:

Type
log_source
Value
SSH server logs
Description
Monitor for a high volume of failed login attempts from a single IP address, indicative of a brute-force attack.
Type
log_source
Value
Cloud data platform logs (e.g., Snowflake)
Description
Audit for unusual or excessive data access patterns, especially large data exports initiated by a single user account.
Type
user_account_pattern
Value
Compromised user accounts
Description
Monitor for user accounts logging in from multiple, geographically disparate locations in a short time (impossible travel).
Type
other
Value
Dark Web monitoring
Description
Proactively monitor cybercrime forums like BreachForums for mentions of your company's name or data.

Detection & Response

  1. Cloud Security Posture Management (CSPM): For platforms like Snowflake, use CSPM tools to detect misconfigurations, excessive permissions, and anomalous data access patterns. This aligns with D3FEND Resource Access Pattern Analysis (D3-RAPA).
  2. Brute-Force Protection: Implement account lockout policies after a set number of failed login attempts on all external-facing services, including SSH. D3FEND Account Locking (D3-AL) is a key control.
  3. Threat Intelligence: Subscribe to threat intelligence services that monitor dark web forums to get early warnings if your company's data appears for sale.

Mitigation

  1. Strong Password Policies and MFA: Enforce strong, unique passwords and, most importantly, mandate MFA for all accounts, especially those with access to sensitive data platforms like Snowflake. This is the most effective defense against credential-based attacks.
  2. Limit Public Exposure: Reduce the attack surface by ensuring that services like SSH are not exposed to the public internet unless absolutely necessary. If required, access should be restricted to known, trusted IP addresses.
  3. Cloud Data Governance: Implement strict data governance and access controls within cloud data platforms. Use role-based access control (RBAC) to enforce the principle of least privilege.

Timeline of Events

1
April 1, 2023
Cameron Wagenius begins his cybercrime campaign.
2
December 18, 2024
The cybercrime campaign conducted by Wagenius ends.
3
September 28, 2026
Cameron Wagenius is sentenced to 70 months in federal prison.
4
September 28, 2026
This article was published

MITRE ATT&CK Mitigations

Enforce MFA on all accounts, especially for access to sensitive cloud data platforms, to prevent unauthorized access even with compromised credentials.

Mapped D3FEND Techniques:

Implement strong password policies to make brute-force and password guessing attacks more difficult.

Mapped D3FEND Techniques:

Implement account lockout policies to thwart brute-force attacks against SSH and other services.

Mapped D3FEND Techniques:

D3FEND Defensive Countermeasures

The attacks involving the Snowflake cloud platform were largely enabled by compromised credentials. Implementing mandatory multi-factor authentication (MFA) for all users accessing the Snowflake environment would have been a powerful mitigating control. Even with valid usernames and passwords obtained through other means, the attackers would have been blocked without the second authentication factor. This should be applied not just to Snowflake but to all critical corporate resources, especially cloud-based data warehouses and administrative portals. This single control is the most effective way to prevent unauthorized access resulting from credential theft, which was a cornerstone of Wagenius's operation.

The development and use of the 'SSH Brute' tool indicates a reliance on brute-force or password-guessing attacks. A fundamental defense against this is a robust account lockout policy. For any externally exposed authentication service, such as SSH, configure a policy to temporarily lock an account after a small number of failed login attempts (e.g., 5 attempts within 5 minutes). This dramatically increases the time and resources required for a successful brute-force attack, often making it impractical. This policy should be paired with strong alerting to notify security teams of repeated failed logins, which can serve as an early indicator of a targeted attack.

Timeline of Events

1
April 1, 2023

Cameron Wagenius begins his cybercrime campaign.

2
December 18, 2024

The cybercrime campaign conducted by Wagenius ends.

3
September 28, 2026

Cameron Wagenius is sentenced to 70 months in federal prison.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

insider threatextortionhackingtelecomSnowflakedata theftsentencing

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.