# Army Soldier Sentenced to Nearly Six Years for Massive Telecom Data Theft and Extortion Campaign
A 22-year-old enlisted member of the U.S. Army has been handed down a 70-month federal prison sentence following his guilty plea to a sweeping cybercrime scheme that compromised data belonging to more than 100 million customers of a major American telecommunications provider.
## The Rise of an Insider Threat
Cameron John Wagenius was serving at a U.S. Army installation in South Korea when he adopted the online alias “Kiberphant0m” and embarked on a criminal spree that would eventually span multiple countries, dozens of companies, and sensitive government data. His operation centered on exploiting poorly secured accounts belonging to users of a widely used cloud data storage platform that had failed to require multi-factor authentication (MFA) at the time of the intrusions.
Working alongside three co-conspirators, Wagenius managed to download enormous troves of call and text message metadata — including source and destination phone numbers, timestamps, and call durations — from one of the nation’s largest wireless carriers alone. He later bragged about his exploits on underground cybercrime forums, claiming he had breached telecommunications providers across the globe, including a prominent push-to-talk communications business operated by another major carrier.
## Extortion and Escalation
Rather than simply selling the stolen information, Wagenius chose a path of extortion, publicly threatening to release the data of victim companies unless they paid him. In a particularly audacious move following the arrest of one of his co-conspirators, Wagenius posted what he claimed were call records belonging to then President-elect Donald Trump and then Vice President Kamala Harris. He also reportedly leaked schematics allegedly obtained from a federal national security agency and continued to threaten further disclosures.
## A Rare Insider Threat Unravels
Investigators from the Defense Criminal Investigative Service (DCIS), the FBI, the Army’s Criminal Investigative Division, and the U.S. Secret Service all contributed to the case. Officials described Wagenius as a particularly unusual threat because of his active-duty military status, his security clearance, and the sheer scale of his ambitions.
“The fact that an active duty service member with a security clearance was building hacking tools and trafficking in stolen data is not something we encounter regularly,” said Paul Russell, the resident agent in charge for DCIS at the time of the arrest. “When we got wind of this, every agency involved took it extremely seriously.”
## Arrest, Guilty Plea, and Sentencing
Wagenius was taken into custody in late 2025 after independent investigative reporting connected the alias Kiberphant0m to his real identity. He was charged in two separate federal indictments and subsequently pleaded guilty to all counts in both cases.
At his sentencing hearing in Seattle, Washington, Judge imposed a nearly six-year prison term and ordered Wagenius to pay $294,978 in restitution to the victims he harmed.
## Troubling Prison Conduct
Prosecutors revealed that even while incarcerated and awaiting sentencing, Wagenius continued to seek out ways to exploit computer systems. According to the government’s sentencing memorandum, he used another inmate’s email account to interact with commercial artificial intelligence tools, crafting prompts designed to bypass the tools’ safety filters.
He specifically asked AI systems to supply details about known vulnerabilities in Windows 10 Enterprise, requested working exploit code for a command injection flaw in networking equipment, and even inquired about building improvised radio antennas from items available in a prison commissary. He also asked his contacts to research methods of escaping custody.
Wagenius reportedly framed many of these requests as research for a book he was allegedly writing. Prosecutors acknowledged that there is no evidence Wagenius successfully exploited any of the vulnerabilities he studied while in custody.
## Modest Financial Returns
Despite the staggering quantity of personal data he stole, Wagenius’s cybercrime enterprise proved remarkably unprofitable. Government records indicate he earned approximately $1,500 in total from his illicit activities — a figure that stood in stark contrast to the enormous harm inflicted on his victims.
“This individual may not have made much money from his crimes, but the damage he intended to cause and the harm he actually inflicted on countless individuals, businesses, and government entities was significant,” prosecutors noted in their sentencing memorandum.
## Remaining Charges for Co-Conspirators
Two of Wagenius’s alleged accomplices continue to face prosecution. One was arrested in 2024 and pleaded guilty earlier this year, while the other — an American national reportedly residing overseas — remains a fugitive wanted in connection with both the Snowflake data thefts and a separate 2021 breach that exposed the personal information of tens of millions of additional individuals.
—
## Frequently Asked Questions (FAQ)
**Who is Cameron John Wagenius?**
Cameron John Wagenius is a 22-year-old former U.S. Army soldier who was stationed in South Korea. He operated under the cybercriminal alias “Kiberphant0m” and pleaded guilty to multiple counts related to hacking, data theft, and extortion.
**What data was stolen?**
Wagenius stole call and text message metadata — such as phone numbers involved in communications, timestamps, and call durations — from more than 100 million customers of a major U.S. telecommunications provider, along with data from other companies around the world.
**How did he carry out the attacks?**
Wagenius exploited accounts on a popular cloud storage service that had exposed login credentials and lacked mandatory multi-factor authentication (MFA). He worked with co-conspirators to access and download massive datasets from numerous companies.
**What is multi-factor authentication (MFA), and why does it matter?**
MFA is a security measure that requires users to verify their identity through more than one method — such as a password combined with a code sent to a mobile device. Enabling MFA significantly reduces the risk of unauthorized access, even if login credentials are compromised.
**Did Wagenius make a lot of money from his crimes?**
No. Despite the enormous scale of the data he stole, Wagenius earned only about $1,500 from his extortion efforts, according to government records.
**Were any government officials affected?**
Yes. After one of his co-conspirators was arrested, Wagenius publicly posted what he claimed were call records belonging to then President-elect Donald Trump and then Vice President Kamala Harris, along with documents he claimed were stolen from a federal national security agency.
**What happened while Wagenius was in prison?**
While awaiting sentencing, Wagenius reportedly violated Bureau of Prisons computer policies by using another inmate’s email account to query commercial AI tools about software vulnerabilities, exploit techniques, improvised radio equipment, and prison escape methods.
**Is Wagenius still a danger from inside prison?**
Government documents indicate that there is no evidence Wagenius successfully exploited any vulnerabilities while incarcerated. He claimed his inquiries were solely for the purpose of reporting potential weaknesses to the Bureau of Prisons.
**What are the co-conspirators facing?**
One co-conspirator pleaded guilty in August 2026 after being arrested in 2024. Another — an American man living in Turkey — remains at large and is wanted in connection with both the Snowflake data thefts and a 2021 breach at another major U.S. telecommunications company.
**What was the final sentence?**
Wagenius was sentenced to 70 months (approximately 5 years and 10 months) in federal prison and ordered to pay $294,978 in restitution to his victims.
—
## Conclusion
The case of Cameron John Wagenius serves as a sobering reminder of the risks posed by insider threats — individuals who have authorized access to sensitive systems and information but choose to exploit that access for criminal gain. Even a seemingly sophisticated operation, one that compromised data on a massive scale, can yield disappointing financial returns while causing lasting damage to millions of innocent people.
It also highlights the critical importance of fundamental cybersecurity practices like multi-factor authentication, which, if properly enforced, can serve as a strong barrier against unauthorized access to sensitive data. The fact that Wagenius’s co-conspirators still face charges underscores the broader collaborative effort required to hold cybercriminals accountable, no matter where they operate or how they attempt to evade justice.
For military organizations, the case reinforces the need for rigorous vetting, ongoing monitoring, and swift action when service members are suspected of engaging in criminal or cyber activities — particularly those who hold security clearances and have access to classified information.
Thank you for reading



