An active-duty Army communications specialist admitted last week to participating in the theft and extortion scheme targeting AT&T and dozens of other major corporations. Prosecutors disclosed Wednesday that the soldier had conducted online searches about non-extradition countries and queried whether hacking constitutes treason, according to a government motion filed to prevent his release pending military discharge.

Cameron John Wagenius, 21, was apprehended on December 20 near Fort Cavazos in Texas and faced two counts of unlawfully transferring confidential phone records. Operating under the alias Kiberphant0m, Wagenius served as a communications specialist stationed at a U.S. Army installation in South Korea and functioned as part of a hacking trio engaged in extortion campaigns against multiple organizations.

The broader criminal operation exploited a widespread vulnerability in late 2023. Numerous firms had stored sensitive customer data on Snowflake's cloud platform using only basic username-and-password authentication, with no multi-factor protection enabled. Criminals obtained stolen Snowflake credentials from darknet marketplaces and systematically accessed repositories maintained by major global enterprises.

AT&T confirmed in July that attackers had obtained personal information and communications records affecting approximately 110 million subscribers—essentially its entire customer base. The telecommunications giant reportedly transferred $370,000 to a hacker in exchange for deletion of the stolen phone records. Beyond AT&T, more than 160 additional Snowflake users suffered data theft, encompassing TicketMaster, Lending Tree, Advance Auto Parts, and Neiman Marcus.

During November, Kiberphant0m posted portions of the stolen phone records on an English-language cybercrime forum while demanding payment to prevent full disclosure. Court documents indicate Wagenius pursued both public forum threats and private extortion attempts against AT&T, demanding $500,000 under threat of releasing the complete dataset.

On February 19, Wagenius entered guilty pleas to both counts without a formal plea agreement in place. His legal team requested that he be permitted to reside with his father while awaiting sentencing. However, government prosecutors countered that Wagenius represented a serious flight risk, citing his pre-arrest internet searches indicating an intent to escape U.S. jurisdiction.

According to prosecutors in Seattle, Wagenius's search history included queries such as:

  • "where can i defect the u.s government military which country will not hand me over"
  • "U.S. military personnel defecting to Russia"
  • "Embassy of Russia – Washington, D.C."

The government stated: "As discussed in the government's sealed filing, the government has uncovered evidence suggesting that the charged conduct was only a small part of Wagenius' malicious activity." Prosecutors noted that during November 2024, Wagenius communicated for more than two weeks with an email address he believed represented a foreign military intelligence service in an effort to sell stolen data. Shortly after concluding those communications, he performed a Google search for "can hacking be treason."

Investigators discovered a laptop screenshot indicating Wagenius possessed access to over 17,000 files containing passports, driver's licenses, and identification documents belonging to breach victims. Additionally, authorities located a fraudulent identification document bearing his photograph stored in one of his online accounts.

Prosecutors asserted that "Wagenius should also be detained because he presents a serious risk of flight, has the means and intent to flee, and is aware that he will likely face additional charges." The filing noted that Wagenius is undergoing separation from the Army, though his discharge had not yet been finalized at the time of the motion.

The government indicated that "until his discharge from the Army is finalized (which is expected to happen in early March), he may only be released directly to the Army." This procedural requirement provided an additional basis for rejecting his proposed release to his father.

Wagenius's interest in fleeing to another nation parallels that of his alleged co-conspirator John Erin Binns, a 25-year-old American indicted for a 2021 T-Mobile breach affecting at least 76.6 million customers. Binns has also been charged in connection with the Snowflake operation and extortion scheme. He remains detained in a Turkish prison. According to sources familiar with the investigation, Binns visited the Russian embassy in Turkey prior to his arrest to inquire about obtaining Russian citizenship.

Canadian law enforcement arrested a third suspected conspirator in late November 2024: Connor Riley Moucka, 25, from Kitchener, Ontario. Federal prosecutors have indicted both Moucka and Binns on charges including one count of conspiracy, ten counts of wire fraud, four counts of computer fraud and abuse, two counts of extortion related to computer fraud, and two counts of aggravated identity theft.

Less than a month before Wagenius's arrest, investigative reporting had documented Kiberphant0m's various Telegram and Discord accounts over time, demonstrating how the account holder had claimed to be an Army soldier stationed in South Korea.

Wagenius faces potential sentences of up to ten years in prison for each count, along with fines reaching $250,000 per offense.

Source: Krebs on Security