D-Link, Verizon, Snowflake, AT&T and Microsoft: U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

D-Link, Verizon, Snowflake, AT&T and Microsoft: U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

U.S. Army Soldier Sentenced to Nearly Six Years for Massive Telecom Data Breaches and Extortion Scheme

A U.S. Army soldier, Cameron Wagenius (22), was sentenced to 70 months in federal prison and ordered to pay $294,978 in restitution after pleading guilty to hacking into multiple telecommunications companies, stealing call and text metadata for over 100 million customers, and attempting to extort victims including AT&T and Verizon.

Operating under the alias "Kiberphant0m", Wagenius, stationed at a U.S. Army base in South Korea, breached telecom providers worldwide, including AT&T, Verizon’s Push-to-Talk service, and others. In October 2024, he claimed to have stolen metadata such as phone numbers, timestamps, and call durations from tens of millions of AT&T customers. Following AT&T’s payment of a $370,000 Bitcoin ransom, Wagenius escalated threats, posting alleged call logs of then-President-elect Donald Trump and Vice President Kamala Harris, alongside purported NSA schematics, on hacker forums.

Despite the high-value data, Wagenius’s extortion efforts yielded only $1,500 in profits. Investigators noted his use of AI prompt injection attacks, where he deceived commercial AI tools into generating exploit code for vulnerabilities, including Windows 10 privilege escalation flaws and a three-year-old D-Link command injection bug (CVE-2023-45208). He also researched prison escape methods and antenna construction while incarcerated, using another inmate’s email to bypass restrictions.

The case drew urgent attention from federal agencies, including the FBI, U.S. Secret Service, Army Criminal Investigative Division (CID), and the Defense Criminal Investigative Service (DCIS), due to Wagenius’s secret security clearance and access to military systems. While awaiting sentencing, he was caught probing Bureau of Prisons (BOP) networks for vulnerabilities, though prosecutors found no evidence he exploited them.

Wagenius worked with at least three co-conspirators, including Conor Brian Fitzpatrick (Judische), arrested in 2024, and Jordan Schuchman, a repeat cybercriminal previously convicted in 2019. Two others remain charged in connection with Snowflake data thefts, where hackers exploited weak credentials to access millions of records.

The sentencing underscores the growing threat of insider attacks and the proliferation of AI-assisted cybercrime, even as Wagenius’s financial gains fell far short of the damage inflicted on victims.

Source: https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions/

D-Link TPRM report: https://www.rankiteo.com/company/dlink-corp

Verizon TPRM report: https://www.rankiteo.com/company/verizon

Snowflake TPRM report: https://www.rankiteo.com/company/snowflake-computing

AT&T TPRM report: https://www.rankiteo.com/company/att

Microsoft TPRM report: https://www.rankiteo.com/company/microsoft-security

"id": "snovermicattdli1790382515",
"linkid": "snowflake-computing, verizon, microsoft-security, att, dlink-corp",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Tens of millions',
                        'industry': 'Telecommunications',
                        'location': 'United States',
                        'name': 'AT&T',
                        'size': 'Large',
                        'type': 'Telecommunications Company'},
                       {'industry': 'Telecommunications',
                        'location': 'United States',
                        'name': 'Verizon (Push-to-Talk service)',
                        'size': 'Large',
                        'type': 'Telecommunications Company'},
                       {'customers_affected': 'Over 100 million (combined)',
                        'industry': 'Telecommunications',
                        'location': 'Global',
                        'name': 'Other unnamed telecom providers',
                        'type': 'Telecommunications Company'}],
 'attack_vector': 'AI prompt injection attacks, Exploitation of known '
                  'vulnerabilities (e.g., CVE-2023-45208), Privilege '
                  'escalation flaws in Windows 10',
 'data_breach': {'data_exfiltration': 'Yes (posted on hacker forums)',
                 'number_of_records_exposed': 'Over 100 million',
                 'personally_identifiable_information': 'Phone numbers, call '
                                                        'metadata',
                 'sensitivity_of_data': 'High (included alleged call logs of '
                                        'high-profile individuals and NSA '
                                        'schematics)',
                 'type_of_data_compromised': 'Call and text metadata (phone '
                                             'numbers, timestamps, call '
                                             'durations)'},
 'date_publicly_disclosed': '2024-10',
 'description': 'A U.S. Army soldier, Cameron Wagenius (22), was sentenced to '
                '70 months in federal prison and ordered to pay $294,978 in '
                'restitution after pleading guilty to hacking into multiple '
                'telecommunications companies, stealing call and text metadata '
                'for over 100 million customers, and attempting to extort '
                'victims including AT&T and Verizon. Wagenius used AI prompt '
                'injection attacks to exploit vulnerabilities and escalated '
                'threats by posting alleged call logs of high-profile '
                'individuals and NSA schematics.',
 'impact': {'brand_reputation_impact': 'Significant reputational damage to '
                                       'telecom providers due to data exposure '
                                       'and extortion threats',
            'data_compromised': 'Call and text metadata (phone numbers, '
                                'timestamps, call durations) for over 100 '
                                'million customers',
            'financial_loss': '$294,978 (restitution ordered) + $370,000 '
                              '(Bitcoin ransom paid by AT&T)',
            'identity_theft_risk': 'High (exposure of phone numbers and call '
                                   'metadata)',
            'legal_liabilities': 'Federal charges, restitution, and regulatory '
                                 'scrutiny',
            'operational_impact': 'Extortion attempts disrupted operations, '
                                  'potential compromise of high-profile '
                                  'communications (e.g., President-elect '
                                  'Donald Trump, Vice President Kamala Harris)',
            'systems_affected': 'Telecommunications providers (AT&T, Verizon '
                                'Push-to-Talk, others), Bureau of Prisons '
                                '(BOP) networks (probed but not exploited)'},
 'initial_access_broker': {'entry_point': 'Exploitation of known '
                                          'vulnerabilities (e.g., '
                                          'CVE-2023-45208), AI prompt '
                                          'injection attacks',
                           'high_value_targets': 'Telecom providers, '
                                                 'high-profile individuals '
                                                 '(e.g., President-elect '
                                                 'Donald Trump, Vice President '
                                                 'Kamala Harris)'},
 'investigation_status': 'Closed (sentencing completed)',
 'lessons_learned': 'Growing threat of insider attacks, proliferation of '
                    'AI-assisted cybercrime, risks of weak credentials and '
                    'unpatched vulnerabilities, need for enhanced monitoring '
                    'of individuals with security clearances',
 'motivation': 'Financial gain, Extortion, Notoriety',
 'post_incident_analysis': {'corrective_actions': 'Sentencing of perpetrator, '
                                                  'restitution ordered, '
                                                  'federal investigations into '
                                                  'co-conspirators, potential '
                                                  'policy changes for '
                                                  'monitoring individuals with '
                                                  'security clearances',
                            'root_causes': 'Insider threat (U.S. Army soldier '
                                           'with security clearance), '
                                           'exploitation of unpatched '
                                           'vulnerabilities, use of AI tools '
                                           'for malicious purposes, weak '
                                           'credentials (implied by Snowflake '
                                           'data thefts linked to '
                                           'co-conspirators)'},
 'ransomware': {'data_exfiltration': 'Yes',
                'ransom_demanded': '$370,000 (Bitcoin)',
                'ransom_paid': '$370,000 (Bitcoin)'},
 'recommendations': 'Strengthen AI tool security to prevent prompt injection '
                    'attacks, enforce strict access controls for sensitive '
                    'systems, monitor and audit individuals with security '
                    'clearances, patch known vulnerabilities promptly, enhance '
                    'incident response plans for extortion and data breaches',
 'references': [{'source': 'U.S. Department of Justice'}],
 'regulatory_compliance': {'legal_actions': 'Federal charges, 70-month prison '
                                            'sentence, restitution of '
                                            '$294,978'},
 'response': {'law_enforcement_notified': 'FBI, U.S. Secret Service, Army '
                                          'Criminal Investigative Division '
                                          '(CID), Defense Criminal '
                                          'Investigative Service (DCIS)'},
 'stakeholder_advisories': 'Federal agencies (FBI, U.S. Secret Service, Army '
                           'CID, DCIS) issued advisories on insider threats '
                           'and AI-assisted cybercrime risks',
 'threat_actor': 'Cameron Wagenius (Kiberphant0m), Conor Brian Fitzpatrick '
                 '(Judische), Jordan Schuchman, and two unnamed '
                 'co-conspirators',
 'title': 'U.S. Army Soldier Sentenced for Massive Telecom Data Breaches and '
          'Extortion Scheme',
 'type': 'Data Breach, Extortion, Insider Threat',
 'vulnerability_exploited': ['CVE-2023-45208 (D-Link command injection bug)',
                             'Windows 10 privilege escalation flaws']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.