Threats & Adversaries · Credential Theft
Cameron John Wagenius, the former US soldier known as kiberphant0m, was sentenced to 70 months in prison for hacking AT&T and Verizon and leaking call detail records, court documents said. The case also ties him to attempts to extort at least 10 organizations and to the AT&T/T-Mobile/Snowflake-linked cluster.
According to the court record, Wagenius was active from April 2023 to December 2024 while on active duty. He and others used SSH Brute and other tools to steal credentials, then used those logins to enter victim systems, exfiltrate data, and threaten publication on private and public forums. Once credentials were in hand, the same access pattern could move across organizations, turning one compromise into a wider extortion campaign.
The sentence closes the prosecution, but the record leaves a broader lesson for telecom and identity teams: the story was not one leaked carrier file, but a months-long credential-theft operation that crossed victims and kept producing exposure wherever reused access still worked.
1 source · 5h ago
SecurityWeek
Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Cameron John Wagenius was sentenced to 70 months in prison for stealing information from the wireless carriers.
originalPart of the PlainSec briefing for 2026-09-28
Every edition of this story: Former Soldier Sentenced in Carrier Credential Campaign