In a federal courtroom in Seattle, a chapter of modern cybercrime history closed as 22-year-old Cameron John Wagenius—a U.S. Army soldier stationed in South Korea who operated under the chilling moniker "Kiberphant0m"—was sentenced to 70 months in federal prison.
Wagenius’s descent from an active-duty service member entrusted with secret security clearances to an international cyber extortionist stands as one of the most unusual and alarming insider threat cases in recent memory. Operating within a loose confederation of sophisticated threat actors, Wagenius exploited basic authentication lapses to breach cloud storage giant Snowflake, subsequently harvesting the mobile call and text metadata of more than 100 million AT&T customers, alongside troves of data from a dozen other global telecommunications firms.
Despite orchestrating high-profile cyberattacks that compromised sensitive metadata belonging to top-tier political figures—including then President-elect Donald Trump and then Vice President Kamala Harris—and attempting to leverage stolen U.S. National Security Agency (NSA) schematics, Wagenius’s illicit enterprise was ironically unprofitable. Federal prosecutors revealed that despite the staggering volume of stolen data, his total direct earnings from the scheme amounted to a paltry $1,500.
Compounding his federal charges, court documents unsealed during his sentencing hearing revealed that Wagenius remained active even while incarcerated. Utilizing clever social engineering and artificial intelligence "prompt injection" techniques through fellow inmates’ email accounts, he attempted to map security vulnerabilities within the Bureau of Prisons (BOP) network, research privilege escalation exploits, and even investigate prison escape methodologies.
This comprehensive report examines the anatomy of the Kiberphant0m enterprise, the collaborative inter-agency manhunt that brought him down, the network of co-conspirators tied to the Snowflake data breaches, and the ongoing implications for national security and corporate cybersecurity.
Detailed Chronology: From Barracks to Federal Indictment
1. The Ingress: Exploiting Cloud Misconfigurations
The roots of the Kiberphant0m case trace back to vulnerabilities associated with cloud-based data storage provider Snowflake. In mid-2024, threat actors identified corporate accounts that lacked multi-factor authentication (MFA) and relied on exposed credentials.
Operating from his U.S. Army base in South Korea, Wagenius—leveraging his secret security clearance and technical acumen—gained unauthorized access to several large Snowflake client databases. This access served as a foundational springboard, enabling the group to exfiltrate vast repositories of sensitive enterprise data. Snowflake has since mandated MFA across all user accounts in response to the campaign.
2. Extortion and the AT&T Breach
By October 2024, Wagenius stepped into the public spotlight of underground cybercrime forums. Operating as Kiberphant0m, he proudly claimed responsibility for stealing call and text metadata—including source numbers, destination numbers, timestamps, and call durations—for tens of millions of AT&T customers.
His targets were not limited to AT&T. Investigators discovered that Kiberphant0m had targeted more than a dozen telecommunications companies worldwide, including Verizon’s specialized Push-to-Talk business. Rather than quietly selling the data on dark web marketplaces, the group engaged in aggressive public extortion, threatening to leak the proprietary archives unless ransom demands were met.
3. Detection, Identification, and Arrest
The turning point for the investigation arrived in late November 2024, when security journalist Brian Krebs published findings indicating that the individual operating as Kiberphant0m was likely a U.S. soldier stationed on the Korean peninsula.
The public disclosure galvanized federal law enforcement. Less than a month after the report, federal authorities arrested Wagenius. He was hit with two separate federal indictments in Seattle and quickly chose to plead guilty to all counts, initiating a cooperative relationship with prosecutors that ultimately factored into his sentencing memos.
4. The Sentencing Hearing
At his sentencing hearing in Seattle, U.S. District Judge imposed a term of 70 months (nearly six years) in federal prison, alongside an order to pay $294,978 in restitution to victims. Prosecutors emphasized that despite his cooperation, the severe nature of the offenses—combining insider threats, critical infrastructure compromise, and national security data—demanded a substantial deterrent sentence.
Supporting Context & Metrics: The Co-Conspirators and the Digital Footprint
The Kiberphant0m enterprise was not a solo operation. Federal prosecutors detailed a tightly knit web of international cybercriminals who collaborated to weaponize the Snowflake data breaches.
+--------------------------------------------------------------------------+
THE SNOWFLAKE EXTORTION NETWORK
+--------------------------------------------------------------------------+
[Cameron John Wagenius] a.k.a. "Kiberphant0m"
|-- Role: Active-duty U.S. soldier in South Korea; orchestrated telecom hacks.
|-- Status: Sentenced to 70 months in federal prison.
[Kenneth Schuchman] (Vancouver, Washington)
|-- Role: Assisted in victim extortion efforts; former Satori IoT botnet operator.
|-- Status: Prosecuted for cybercriminal history.
[Conor Riley Moucka] a.k.a. "Judische" (Kitchener, Ontario)
|-- Role: Core participant in Snowflake data thefts and extortion.
|-- Status: Arrested in 2024; pleaded guilty in August 2026.
[John Erin Binns] (American, residing in Turkey)
|-- Role: Linked to Snowflake thefts; also wanted for the 2021 T-Mobile breach.
|-- Status: International fugitive.
Key Co-Conspirators
- Kenneth Schuchman (28, Vancouver, Washington): Prosecutors noted that Schuchman assisted Wagenius in coordinating extortion attempts against victim companies. Schuchman is no stranger to federal law enforcement; in 2019, he pleaded guilty to operating the Satori botnet, a massive infrastructure of compromised Internet-of-Things (IoT) devices used to launch crippling distributed denial-of-service (DDoS) attacks.
- Conor Riley Moucka a.k.a. "Judische" (Kitchener, Ontario): Arrested in 2024 in connection with the Snowflake data thefts, Moucka pleaded guilty in August 2026. Following Moucka’s arrest, an agitated Kiberphant0m attempted "re-extortion" tactics, leaking high-profile data archives online.
- John Erin Binns (American living in Turkey): Also wanted for his alleged role in the massive 2021 T-Mobile data breach that exposed personal details of at least 76 million customers, Binns remains an international fugitive connected to the broader Snowflake extortion ecosystem.
The Anatomy of Re-Extortion and National Security Fallout
Desperate to salvage financial returns after AT&T and other corporate victims balked—even after an initial Bitcoin ransom payment of $370,000 was funneled to the extortion group—Kiberphant0m escalated his threats. Following Moucka’s arrest, Wagenius published files on hacker forums claiming to contain:
- AT&T call logs belonging to then President-elect Donald Trump and then Vice President Kamala Harris.
- Sensitive engineering schematics allegedly stolen from the U.S. National Security Agency (NSA).
The Financial Paradox
In one of the most striking ironies of modern cybercrime, the federal sentencing memo highlighted that despite compromising critical infrastructure, exfiltrating records of over 100 million people, and threatening national security institutions, Wagenius generated a grand total of approximately $1,500 from selling the stolen data. The financial failure underscores how opportunistic, low-tier threat actors often assume catastrophic legal and societal liabilities for minimal monetary gain.
Official Statements: An Unprecedented Insider Threat
The convergence of military intelligence, national security clearances, and cyber extortion prompted an unprecedented multi-agency task force. The investigation was jointly spearheaded by the Defense Criminal Investigative Service (DCIS)—the criminal investigative arm of the Department of Defense Office of Inspector General—alongside the FBI, the Army Criminal Investigative Division (CID), and the U.S. Secret Service.
Paul Russell, Resident Agent in Charge at DCIS, emphasized the unique shockwave the case sent through federal intelligence and law enforcement communities:
"We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data," Russell stated. "That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with."
The combination of an active-duty military deployment overseas, access to classified networks, and commercial cybercriminal pursuits forced defense agencies to re-evaluate how internal clearances intersect with digital hygiene and external online personas.
Future Outlook: Incarceration, AI Prompt Injection, and Cyber Posture
While Wagenius’s criminal enterprise has resulted in a nearly six-year federal prison sentence, his behavior while awaiting sentencing demonstrates that technical aptitude and malicious intent do not dissipate behind bars.
Jailhouse AI Exploits and Prompt Injection
According to federal sentencing memos filed on September 19, Wagenius violated Bureau of Prisons (BOP) computer use policies while incarcerated. Desperate to probe the digital defenses of his captors, he utilized other inmates’ email accounts to relay crafted queries to commercial artificial intelligence (AI) tools.
To bypass safety filters designed to prevent AI models from generating malicious exploit code—a technique known as prompt injection—Wagenius framed his requests within hypothetical scenarios, such as writing a book. His digital inquiries included:
- Asking for CVE (Common Vulnerabilities and Exposures) identifiers, privilege escalation pathways, and working scripts for Windows 10 Enterprise without omitted code.
- Requesting a step-by-step breakdown and exploit code for CVE-2023-45208, a command injection vulnerability affecting D-Link networking devices.
- Inquiring how to construct improvised radio antennas using commissary items to extend reception inside a prison facility.
- Researching prison escape methodologies.
While prosecutors confirmed there was no evidence that Wagenius successfully deployed these vulnerabilities against BOP systems—with Wagenius claiming his research was intended to help secure BOP infrastructure—the incident highlights the persistent risks posed by digitally native offenders who view locked systems as puzzles waiting to be solved.
Lessons for Corporate and National Security
The Kiberphant0m case serves as a watershed moment for several industries:
- Mandatory Multi-Factor Authentication: The Snowflake breaches demonstrated that perimeter security collapses without strict, non-bypassable MFA policies across all employee and corporate accounts.
- Insider Threat Monitoring: Defense and intelligence branches must adapt continuous evaluation frameworks that monitor digital footprints, underground forum participation, and anomalous data-handling behaviors among personnel holding security clearances.
- AI Safety Boundaries: The exploitation of commercial AI tools by incarcerated hackers underscores the ongoing arms race in LLM (Large Language Model) guardrails, proving that malicious actors will continuously refine prompt-injection techniques to extract actionable exploit code.
As Wagenius begins his 70-month sentence, federal law enforcement continues to hunt remaining co-conspirators like John Erin Binns, ensuring that the fallout from the Kiberphant0m cyber extortion campaign will reverberate across international courts for years to come.