U.S. Army Soldier Behind Massive AT&T Snowflake Breach Sentenced to Nearly Six Years in Federal Prison

Executive Overview

A 22-year-old U.S. Army soldier who led a double life as an international cybercriminal was sentenced in a Seattle federal court to 70 months in prison and ordered to pay nearly $300,000 in restitution. Cameron John Wagenius, who operated under the online moniker "Kiberphant0m" while stationed on an active U.S. military base in South Korea, previously pleaded guilty to multiple federal charges stemming from a destructive extortion campaign that compromised cloud database environments, exposed private records of over 100 million telecommunications customers, and jeopardized sensitive national security assets.

Wagenius was a central figure in a high-profile cybercrime ring that systematically targeted corporate clients of the cloud storage provider Snowflake. Operating with a Secret security clearance, Wagenius exploited compromised credentials to infiltrate cloud environments, stealing sensitive call and text message metadata from major telecommunications providers, including AT&T and Verizon’s Push-to-Talk service.

Following his breach of AT&T—which saw the telecom giant pay a $370,000 Bitcoin ransom to his criminal ring—Wagenius escalated his tactics by launching re-extortion attempts. In a bid to maximize leverage, he leaked sensitive metadata allegedly belonging to high-ranking political figures, including then-President-elect Donald Trump and then-Vice President Kamala Harris, along with proprietary schematics linked to the National Security Agency (NSA).

Despite pleading guilty early in his legal proceedings, federal prosecutors revealed that Wagenius continued his illicit cyber activities while incarcerated awaiting sentencing. Utilizing the Federal Bureau of Prisons (BOP) email system via proxy inmates, Wagenius executed sophisticated "prompt injection" attacks against commercial artificial intelligence tools to research zero-day vulnerabilities, local privilege escalation exploits, prison escape methodologies, and improvised radio equipment. His sentencing highlights the risks posed by technically proficient insider threats within the armed forces and the challenges of managing cyber risks in institutional environments.


Detailed Chronology

[Early–Mid 2024] ──> Wagenius ("Kiberphant0m") breaches Snowflake accounts using compromised credentials lacking MFA.
[October 2024]   ──> Mass exfiltration of 100M+ AT&T call/text logs; extortion campaign launches across cyber forums.
[Nov–Dec 2024]   ──> KrebsOnSecurity ties "Kiberphant0m" to U.S. soldier in South Korea; joint-agency arrest follows.
[Mid–Late 2025]  ──> Awaiting trial in BOP custody, Wagenius uses AI prompt injections to seek exploits and escape plans.
[August 2026]    ──> Co-conspirator Conor Riley Moucka ("Judische") pleads guilty in federal court.
[September 2026] ──> Wagenius is sentenced in Seattle to 70 months in prison and $294,978 in restitution.

2024: Infiltration, Exfiltration, and Extortion

While stationed with the U.S. Army in South Korea, Wagenius adopted the persona "Kiberphant0m." Operating in tandem with an international network of cybercriminals, he targeted corporate accounts hosted on Snowflake’s cloud storage platform. The primary vectors were accounts that relied on single-factor authentication and whose administrative credentials had been exposed through prior info-stealer malware campaigns.

By mid-2024, Wagenius had exfiltrated massive datasets from more than a dozen global telecommunications entities. In October 2024, he publicly announced on illicit dark web forums that he had acquired the call and text metadata—including originating and terminating phone numbers, connection timestamps, and call durations—for over 100 million AT&T subscribers. The syndicate demanded substantial ransom payments in cryptocurrency in exchange for deleting the exfiltrated data and withholding it from public leak sites.

November–December 2024: High-Profile Leaks and Federal Arrest

After AT&T paid a $370,000 Bitcoin ransom to the extortion ring, Wagenius broke honor among thieves and initiated a secondary extortion campaign. Following the arrest of key co-conspirator Conor Riley Moucka in late 2024, Wagenius posted snippets of stolen data on public hacker forums. These leaks included metadata logs belonging to prominent political leaders, including Donald Trump and Kamala Harris, as well as technical schematics allegedly belonging to the NSA.

In late November 2024, independent investigative reporting indicated that "Kiberphant0m" was an active-duty American soldier stationed overseas. The Defense Criminal Investigative Service (DCIS), alongside the FBI, the U.S. Army Criminal Investigative Division (CID), and the U.S. Secret Service, launched an expedited joint operation. In December 2024, Wagenius was arrested in South Korea, extradited to the United States, and charged across two separate federal indictments. He subsequently entered a guilty plea to all counts.

September 2025: In-Prison Jailbreaking and Escalate Attempt

While detained in a federal correctional facility awaiting his sentencing hearing, Wagenius bypassed local network restrictions by convincing fellow inmates to allow him access to their BOP email accounts. In September 2025, federal investigators discovered that Wagenius was sending structured queries to external associates, instructing them to feed specific prompts into commercial generative AI platforms.

These prompts sought actionable code for Windows 10 Enterprise privilege escalation vulnerabilities, detailed exploit chains for CVE-2023-45208 (a command injection flaw in D-Link networking hardware), instructions on manufacturing radio antennas using commissary items, and blueprints for prison escape tactics. To bypass safety filters embedded within the commercial AI systems, Wagenius instructed his external proxies to frame the queries as research for a fictional novel he was authoring—a technique known in cybersecurity as "prompt injection."

September 2026: Federal Sentencing Hearing

On September 19, 2026, federal prosecutors filed a comprehensive sentencing memorandum in the U.S. District Court for the Western District of Washington at Seattle. While acknowledging Wagenius’s early plea and initial cooperation, the government emphasized his persistent, post-arrest security violations within the federal prison system. The judge handed down a 70-month federal prison sentence coupled with a mandatory restitution order of $294,978.


Supporting Context & Metrics

The Extortion Syndicate and Snowflake Attack Vector

The breach did not stem from a structural compromise of Snowflake’s underlying cloud infrastructure itself, but rather from widespread credential hygiene failures among its enterprise clients. Attackers leveraged historical credentials harvested by info-stealer malware (such as RedLine, Vidar, and Lumma) to access corporate Snowflake instances that failed to enforce Multi-Factor Authentication (MFA).

The impact across the target telecommunications firms was massive:

Metric / Dimension Detail / Quantifiable Value
Primary Target AT&T (alongside 12+ global telecoms including Verizon Push-to-Talk)
Affected Individuals > 100 Million Customers
Exfiltrated Data Types Call/Text Metadata (Source/Destination, Timestamps, Duration)
Initial AT&T Ransom Paid $370,000 in Bitcoin (BTC)
Wagenius Net Profit ~ $1,500
Court-Ordered Restitution $294,978
Federal Prison Sentence 70 Months (5 Years, 10 Months)

Despite the vast operational scope and the $370,000 ransom secured by the broader ring, federal filings revealed that Wagenius personally derived minimal financial gain from the enterprise, earning approximately $1,500 from direct data sales. Nevertheless, the systemic financial, operational, and reputational damage inflicted on victim companies and subscribers was extensive.

       [ Malicious Credentials Harvested ]
                      │
                      ▼
       [ Cloud Database Access (No MFA) ]
                      │
                      ▼
       [ Mass Exfiltration of Telecom Records ]
                      │
   ┌──────────────────┴──────────────────┐
   ▼                                     ▼
[ Ransoms Paid ]             [ Re-Extortion & Leaks ]
($370k Bitcoin)              (Political Records & NSA Data)

Profile of Key Co-Conspirators

Wagenius operated within a network of experienced cybercriminals, illustrating the convergence of botnet operators, credential brokers, and extortive threat actors:

  • Kenneth Schuchman (28, Vancouver, WA): A veteran cybercriminal who previously pleaded guilty in 2019 for creating and operating the "Satori" IoT botnet, which hijacked hundreds of thousands of router devices to launch large-scale Distributed Denial-of-Service (DDoS) attacks. Schuchman assisted Wagenius in managing communications and extortion strategies against corporate victims.
  • Conor Riley Moucka, a.k.a. "Judische" (Kitchener, Ontario): A primary operator in the Snowflake exfiltration campaign. Moucka was arrested by Canadian authorities in late 2024 and formally pleaded guilty to federal charges in August 2026.
  • John Erin Binns: An American citizen residing in Turkey who remains wanted by U.S. federal law enforcement. Binns was previously indicted for his involvement in the massive 2021 T-Mobile cyber attack that exposed the personally identifiable information (PII) of over 76 million customers.

Mechanics of the In-Prison Prompt Injection

While held in federal custody, Wagenius utilized a multi-layered prompt injection scheme to bypass AI safety guardrails. Commercial Large Language Models (LLMs) are hardcoded with system instructions designed to prevent the generation of malicious code, jailbreak scripts, or escape plans.

Inmate (Wagenius) ──> BOP Email System ──> Outside Recipient ──> Generative AI Tool 
                                                                       │
                                  (Framed as "Book Research")          │
                                                                       ▼
Inmate Receives Exploit Code <── Output Returned <── AI Bypasses Safety Filters

Wagenius attempted to circumvent these constraints through structural context-switching:

  1. Persona Adoption: Directing the model to act within the context of assisting a fictional author or security researcher writing a book on penal cyber-defenses.
  2. Explicit Vulnerability Requests: Requesting complete, fully functional, unredacted privilege escalation scripts for Windows 10 Enterprise systems.
  3. Exploit Generation: Asking for working step-by-step exploit code targeting CVE-2023-45208, a legacy vulnerability allowing remote attackers to execute arbitrary commands on network hardware.
  4. Hardware Modifications: Inquiring about physics-based modifications to extend radio frequency reception using common materials available in prison commissaries.

Although federal investigators found no evidence that Wagenius successfully executed local network breaches inside the correctional facility, his attempts demonstrated a persistent intent to bypass system restrictions.


Official Statements

The involvement of an active-duty military member holding a Secret security clearance triggered an immediate, high-priority investigation across multiple federal defense and law enforcement branches.

Paul Russell, Resident Agent in Charge at the Defense Criminal Investigative Service (DCIS)—the federal law enforcement arm of the U.S. Department of Defense Office of Inspector General—emphasized the unprecedented

nature of the case:

"We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data. That doesn’t happen every day, and so when that hits, it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with."

Addressing Wagenius’s actions while incarcerated, federal prosecutors wrote in their official sentencing memorandum:

"According to records from BOP, in or around September 2025, Wagenius used another inmate’s email system to request that the email recipient prompt a commercial AI tool to provide information about ‘[w]hat CVE’s are there for Windows 10 Enterprise privilege escalation and bypasses’ and to ‘[p]rovide the CVE’s and a real world working script for each CVE . . . without omitted code.’

In several instances, Wagenius framed the AI queries as being posed in connection to a book he was writing. This is a common method of ‘prompt injection,’ in which attackers feed specially crafted, deceptive inputs into commercial AI tools that are programmed to avoid outputting malicious code that can be used to exploit computer vulnerabilities. While Wagenius was not particularly financially successful as a cybercriminal, he both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government."


Future Outlook

Re-Evaluating Military Clearance and Insider Threat Monitoring

The conviction of Wagenius highlights critical gaps in off-duty monitoring for military personnel serving in sensitive technical positions overseas. Expect the Department of Defense (DoD) to review screening protocols for service members with access to classified networks who display technical proficiency in offensive cyber tactics. The incident may spur real-time continuous threat-monitoring systems across military networks, tracking off-duty digital activity, dark-web handles, and unauthorized software deployments on deployed installations.

Security Reconfigurations Across Cloud Environments

The fallout from the broader Snowflake data theft campaign has permanently altered baseline security requirements for enterprise cloud customers. Following the exposure of millions of records across multiple corporate targets, Snowflake mandated Multi-Factor Authentication across all user accounts globally. Enterprise security teams are increasingly treating identity verification as a non-negotiable perimeter defense, shifting away from single-factor authentication models to mitigate credential-stuffing attacks.

       [ Legacy Cloud Model ]                   [ Post-Breach Standard ]
┌──────────────────────────────────┐      ┌──────────────────────────────────┐
│ Single-Factor Password Access    │ ───> │ Mandatory MFA Architecture       │
│ Optional Identity Controls       │      │ Zero-Trust Identity Verification │
│ Unmonitored API Endpoint Access  │      │ Continuous Behavioral Analytics  │
└──────────────────────────────────┘      └──────────────────────────────────┘

AI Safety Regulations and Correctional Facility Cyber Defense

Wagenius’s attempt to leverage commercial artificial intelligence systems from behind bars highlights an emerging challenge for correctional facilities and AI developers. As access to digital tools and email portals expands across state and federal prisons, administrators face new security risks:

  • Strict Content Filtering: Federal facilities are expected to implement contextual AI detection filters to inspect inmate outbound emails for prompt injection signatures and exploit terminology.
  • Refined LLM Guardrails: Developers of commercial AI platforms face growing pressure to harden models against adversarial "jailbreaking" tactics, ensuring that narrative framing (e.g., claiming to write a novel) cannot be used to bypass safety protocols prohibiting the generation of exploit scripts.

Pending Judicial Proceedings

With Wagenius now sentenced to serve 70 months in federal custody, attention turns to his remaining co-conspirators. Conor Riley Moucka awaits sentencing following his August 2026 guilty plea, while U.S. law enforcement continues to pursue the extradition or capture of John Erin Binns. The resolution of these cases will mark the end of one of the most widespread cloud-based extortion rings operating in recent years.

Leave a Reply

Your email address will not be published. Required fields are marked *