News / Cybersecurity
Former U.S. Soldier Sentenced to 70 Months for Hacking and Extorting Telecom Giants Published on 28 September 2026 by Christ-loisele (3 min read)
Cameron John Wagenius, a former U.S. military member, was sentenced for targeting AT&T, Verizon, and Snowflake between 2023 and 2024. His methods, including extortion and selling data to foreign services, highlight increased risks for critical infrastructures.
A criminal network exploiting vulnerabilities in Snowflake
Cameron John Wagenius, a former U.S. Army soldier stationed in South Korea and at Fort Cavazos (Texas), orchestrated between April 2023 and December 2024 a hacking campaign targeting telecommunications companies and Snowflake customers, a major cloud player. According to The Record , he collaborated with two accomplices: Connor Riley Moucka (extradited from Canada) and John Erin Binns (arrested in Turkey in May 2024), to exploit vulnerabilities in Snowflake configurations and steal thousands of sensitive call records, including metadata from over 100 million AT&T customers, as KrebsOnSecurity specifies.
The hackers used the SSH Brute tool to obtain credentials, then threatened to publish the data on forums like BreachForums or XSS.is , while demanding ransoms of at least 1 million dollars, according to the Justice Department . Wagenius also attempted to sell this information to an email address he believed was linked to a foreign military intelligence service, revealing a geopolitical dimension to his activities.
He even sought to sell stolen information to a foreign military intelligence service, turning a cyberattack into a national security threat.
Illustration: Lawing Tech
Methods revealing digital radicalization
Wagenius’s court documents and Google searches, including terms like ‘can hacking be treason’ or ‘U.S. military personnel defecting to Russia’ , suggest an ideological drift during his active period, as The Record highlights. His pseudonym, kiberphant0m , and his online exchanges requesting exploit scripts (CVE) or advice on building antennas in prison betray an obsession with cybercrime and a desire to bypass security systems, even from detention.
His arrest in December 2024, following an alert from KrebsOnSecurity in November 2025, allowed authorities to dismantle a network that also targeted tech companies through SIM-swapping attacks and fraud, according to BleepingComputer . Prosecutors emphasize that he betrayed the trust placed in him as an active military member, as summarized by Assistant Attorney General A. Tysen Duva : ‘He even sought to traffic stolen information to a foreign intelligence service’ .
What this changes here
For Beninese or West African businesses and administrations using cloud platforms like Snowflake or sensitive telecommunications infrastructures, this case underscores that configuration flaws, often underestimated, can serve as entry points for malicious actors. Extortion methods involving threats of publication on specialized forums, as described by BleepingComputer , could inspire local groups to replicate these schemes, especially since the ransoms demanded (up to 1 million dollars) remain accessible to less-equipped cybercriminals.
Moreover, the Wagenius case highlights the risks associated with digital radicalization among technical profiles: a former military personnel or an employee from a critical sector, frustrated or driven by extreme ideologies, could target local entities with in-depth knowledge of systems. Beninese authorities, such as the National Agency for Information Systems Security (ANSSI-Benin) , should strengthen security audits on privileged access and cloud configurations, while companies should prepare for extortion campaigns targeting business or personal data.
Finally, the sale of data to foreign services, even if aborted, demonstrates that African infrastructures could become secondary targets for criminal networks seeking to bypass international sanctions. Increased vigilance over data leaks and suspicious behavior among employees (such as unusual Google searches) would be necessary to prevent similar scenarios.
Sources