Ex-soldier sentenced to nearly six years for tech and telecom extortion spree

Cameron John Wagenius, a former U.S. Army soldier, was sentenced to 70 months in prison for hacking and extorting at least 10 technology and telecom companies between April 2023 and December 2024. He pleaded guilty to charges including unlawful transfer of phone records, aggravated identity theft, wire fraud conspiracy, and computer-fraud extortion, and must pay $294,978 in restitution. Prosecutors said he and accomplices used stolen credentials, Telegram, and public forums to demand ransoms and sell data.
Cameron John Wagenius, 21, used online handles including kiberphant0m and cyb3rph4nt0m. He was arrested in Texas in December 2024 while serving in the Army. He admitted in 2025 to charges tied to AT&T and Verizon records, identity theft, wire fraud conspiracy, and computer-fraud extortion. Prosecutors said he helped create an SSH brute-force tool, shared stolen credentials via Telegram, and threatened to publish data on BreachForums and XSS.is.
Authorities said he and co-conspirators sought at least $1 million from victims and sometimes sold stolen data, which also enabled SIM-swapping fraud. Two alleged accomplices, Connor Riley Moucka and John Erin Binns, were linked to Snowflake cloud breaches affecting over 165 organizations. Snowflake later required MFA and longer passwords.
The case may reinforce concerns that stolen phone records and cloud data can expose millions of customers to fraud, identity theft, and SIM-swapping. Telecom and technology users could face greater risk when credentials are reused or accounts lack MFA. Companies may face pressure to adopt stronger authentication and monitor third-party cloud access. Because extortion can continue across borders and online forums, law enforcement cooperation and victim notification may shape public trust.