News

An Active-Duty US Soldier Spent 20 Months Hacking Telecoms and Selling Data to Enemies. He Just Got 5 Years 10 Months.

Former US Soldier Sentenced for 70 Months for Hacking and Extortion

Cameron John Wagenius, a 22-year-old former US Army soldier, was sentenced to 70 months in federal prison on September 25, 2026.

Cameron John Wagenius, a 22-year-old former US Army soldier, was sentenced to 70 months in federal prison on September 25, 2026. From April 2023 to December 2024, while on active duty, he used a hacking tool he helped develop, called SSH Brute, to breach at least 10 telecommunications companies, steal confidential call records, and attempt to extort over $1 million from victim organizations. He also sought to sell stolen data to a foreign intelligence service and posted confidential call records belonging to a sitting US government official online.

On September 25, 2026, a federal judge in the Western District of Washington sentenced him to 70 months in prison, nearly six years,ย  and ordered him to pay $294,978 in restitution. Wagenius is 22 years old.

The Alias, the Tool, and How He Operated

Wagenius operated online as “kiberphant0m.” Under that identity, he worked with a network of co-conspirators through Telegram group chats, coordinating credential theft, discussing network access, and distributing stolen data.

The tool at the center of his operations was one he helped build: SSH Brute, a program designed to brute-force login credentials for SSH (Secure Shell) connections, the protocol administrators use to access servers remotely. By repeatedly trying credential combinations at scale, SSH Brute gave Wagenius and his conspirators a way into protected corporate networks without exploiting a specific software vulnerability.

Once inside, they extracted data, then extorted the victim companies. Some extortion was private, direct demands to organisations threatening to release their data. Some was public, on BreachForums and XSS.is, criminal forums where stolen data is listed, discussed, and sold, in moves designed to maximise pressure and demonstrate credibility within those communities.

This distinction matters. First Assistant US Attorney Floyd noted that Wagenius “was also motivated by a desire to achieve status within criminal hacking communities.” Financial gain was real, the conspirators attempted to extort over $1 million total and successfully sold at least some stolen data. But the public forum posts also served as reputation-building in the underground. Getting listed on BreachForums as someone who has data from major telecoms is currency in that world, as we’ve covered in looking at how dark web credential markets and criminal forums operate.

The Posts That Got Him Caught

The operation might have continued longer if Wagenius had stayed quiet. He didn’t.

In November 2024, he made two public online posts disclosing stolen confidential non-content call detail records. One set of records belonged to a sitting US government official. Another involved family members of a different former official. The DOJ press release doesn’t name them, but reporting from 404 Media and others following the broader investigation identified the government official’s records as those of Vice President JD Vance, with family members of Secretary of State Marco Rubio also affected.

The DOJ also notes that the text of one post “suggested that Wagenius was motivated by a desire to retaliate for the then-recent arrest of another cybercriminal”, believed to refer to Connor Riley Moucka, also known as “Waifu” or “Judische,” who had been arrested in late October 2024 and was a significant figure in the same overlapping criminal network.

The public nature of those posts is what accelerated the investigation. FBI Assistant Director Brett Leatherman noted the agency “moved quickly to identify, locate, and arrest Cameron Wagenius” within weeks of the extortion threats becoming public.

What “Non-Content Call Records” Actually Meansย  and Why They’re Dangerous

Wagenius was charged specifically with unlawfully transferring confidential phone records information. The records in question were “call detail records”, not the content of calls, but metadata about them: who called whom, when, how long, and from where.

It’s worth explaining why this matters. The legal distinction between content (what was said) and metadata (who communicated) has historically given metadata less legal protection under US law. But from an intelligence perspective, call metadata on a senior government official is enormously valuable. It reveals who they communicate with regularly, the timing of their calls before major decisions, which foreign numbers they contacted, and patterns that can be used for targeting or influence operations.

That’s precisely why the DOJ press release specifically highlights that Wagenius “sought to traffic stolen information to a foreign intelligence service”, a detail buried after the financial extortion numbers but arguably the most serious element of the whole case. The financial crimes were serious. Trying to sell an active-duty soldier’s access to foreign intelligence is categorically different.

The AT&T and Snowflake Connection

Wagenius’s individual case sits inside a broader wave of criminal activity that defined 2024’s telecom security landscape. The co-conspirator network he operated within overlapped with the group behind the massive AT&T data breach in summer 2024, which was connected to credential theft through the Snowflake cloud platform and affected dozens of major corporations, including Ticketmaster, Advance Auto Parts, and LendingTree.

This connection shows why the supply chain and credential-theft ecosystem we’ve covered throughout 2026 is so interconnected. Individual actors operate across multiple criminal campaigns simultaneously. The same Telegram channels that distributed Wagenius’s stolen telecom credentials were likely also handling credentials from other campaigns. Identifying and sentencing one actor doesn’t close the network, but it disrupts it.

The case also reinforces what we saw in the Ransom Cartel conviction of Maksim Silnikau. Persistent attribution and international cooperation are reaching actors who previously assumed they were untouchable.

The “Betrayal of Trust” Framing the DOJ Is Emphasising

Multiple DOJ officials specifically framed this case as a breach of military trust, and the language is deliberate.

AAG Duva: “Cameron Wagenius spent more than a year and a half betraying the trust placed in him as an active duty soldier by carrying out a sweeping cybercrime campaign.”

FBI SAC Herrington: “It is especially shocking that a member of our armed forces, sworn to defend Americans and their Constitutional rights, would engage in such a violation of privacy.”

This framing serves a purpose beyond the specific case. Active-duty military personnel receive security clearances, access to sensitive military networks, and training that in theory includes awareness of insider threat risks. A soldier who uses that position, including potentially the credibility and access that come with it, as cover for a criminal enterprise running on Telegram and BreachForums is a specific category of insider threat that national security frameworks explicitly try to prevent.

Wagenius’s crimes ran from April 2023 to December 18, 2024, 20 months of active criminal operation while drawing a military salary and working within the Army.

What Happens Now

Wagenius pleaded guilty in two separate proceedings: conspiracy to commit wire fraud, extortion related to computer fraud, and aggravated identity theft in July 2025; and two counts of unlawful transfer of confidential phone records in March 2025. He has been cooperating since those pleas.

The conspiracy charges leave open the question of his unnamed co-conspirators. Several individuals from the broader network, which includes both the AT&T/Snowflake breach and the telecom extortion campaigns, have been identified in separate proceedings. The case file suggests investigators used Wagenius’s cooperation to map the broader network, which is typical in these plea agreements.

For anyone whose data may have moved through these criminal channels, telecom customers, people with records at AT&T and connected providers, our guide on what to do when your data is on the dark web covers the practical response steps.

Quick Answers

Who is Cameron John Wagenius?

A 22-year-old former US Army soldier who operated as “kiberphant0m” online. He was sentenced to 70 months in federal prison on September 25, 2026.

What did he do?

From April 2023 to December 2024, while on active duty, he hacked at least 10 telecommunications companies using a tool he helped develop called SSH Brute, stole confidential records, and attempted to extort over $1 million from victim organisations.

Was a senior official’s data stolen?

Yes. He publicly posted confidential call detail records belonging to a sitting US government official (reported to be Vice President JD Vance) and family members of another former official.

Did he try to sell data to a foreign government?

Yes. The DOJ confirmed he “sought to traffic stolen information to a foreign intelligence service,” though the release does not identify which service.

What is SSH Brute?

A hacking tool Wagenius helped develop that automatically tries large volumes of login credential combinations against SSH connections, used to gain unauthorized access to company servers.

Muhammad Anas

Written by Muhammad Anas

Contributing writer at DarkWebDecoded.com covering dark web security, scam alerts, and privacy tools.

๐Ÿ“‹ Latest Articles

View all →
BLACKNET-00 Claims Cyberattack on SriLankan Airlines and Theft of Internal Data
News

SriLankan Airlines: A New Ransomware Group Is Claiming It Stole Engine Records, Flight Databases, and Staff Credentials

BLACKNET-00 claims to have breached SriLankan Airlines and extracted credentials for flight operations systems, internal databases, employee records,…

Sep 29, 2026
6 min read
Flink data breach LPG Group
News

Flink Was Breached And Now Hackers Are Emailing Its Customers for Ransom Too

LPG Group breached Flink using compromised employee login credentials and accessed an internal system containing names, email addresses,…

Sep 28, 2026
6 min read
LLM-Jacking
News

LLM-Jacking: The Dark Web Is Now Selling AI Access at 97% Off

Google’s Threat Intelligence Group has warned of a surge in two related AI-access attacks: credential theft targeting AI…

Sep 28, 2026
6 min read
Fraudsters Are Using Vacant Homes to Steal Your Mail. Here's the Full Playbook.
News

Fraudsters Are Using Vacant Homes to Steal Your Mail. Here’s the Full Playbook.

Threat actors are identifying vacant homes using platforms like Zillow and Rightmove, registering for USPS Informed Delivery at…

Sep 27, 2026
7 min read
A New AI System Reads the Dark Web the Way Human Analysts Do Across Text and Images at Once
News

A New AI System Reads the Dark Web the Way Human Analysts Do Across Text and Images at Once

Researchers at G.H. Raisoni University published a study in Neural Computing and Applications this week describing a multimodal…

Sep 27, 2026
6 min read
Fujitsu and KELA Are Bringing Dark Web Intelligence to Japan's Corporate Security Front Line
News

Fujitsu and KELA Are Bringing Dark Web Intelligence to Japan’s Corporate Security Front Line

Fujitsu Limited launched a three-component cybersecurity service on September 25, 2026, combining dark web monitoring, attack surface management,…

Sep 25, 2026
6 min read
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted