Incident
Published 2026-09-28
Verified 2026-09-28

Former US soldier Cameron Wagenius (kiberphant0m) sentenced 70 months for hacking/extorting ≥10 tech & telecom firms

U.S. Department of Justice (OPA press release linked from BleepingComputer, 28 September 2026) reports that former U.S. Army soldier Cameron John Wagenius (21; online kiberphant0m / cyb3rph4nt0m) was sentenced to 70 months in prison and ordered to pay $294,978 restitution for hacking and extorting at least ten U.S. technology and telecommunications companies between April 2023 and December 2024 while on active duty. Court narrative (via BleepingComputer/DoJ): Wagenius and conspirators used an SSH brute-force tool he helped develop, moved stolen credentials on Telegram, and threatened to publish data on BreachForums / XSS.is or sold it; attempted extortion totaled at least $1 million; stolen data also used for SIM-swapping and other fraud. Prior guilty pleas: February 2025 (AT&T / Verizon confidential phone-records transfers) and July 2025 (aggravated identity theft, conspiracy to commit wire fraud, extortion related to computer fraud). Accomplices Connor Riley Moucka (“Waifu”/“Judische”) and John Erin Binns (“irdev”) were separately accused in the Snowflake-linked campaign affecting customers of AT&T, Ticketmaster, Santander and others; Moucka pleaded guilty August 2026. Primary: DoJ OPA; wire: BleepingComputer 28 Sep.

Product
n/a (criminal sentencing — telecom/tech network intrusion and extortion)
Versions
n/a
Exploited in Australia?
unknown
Patch to
No product patch — enforce MFA and long passwords on cloud data platforms (Snowflake-class); monitor SSH brute-force tooling; treat BreachForums/XSS.is extortion posts and Telegram credential relays as incident triggers; rotate exposed customer/telecom credentials

Primary: U.S. Department of Justice — former US soldier sentenced for hacking and extortion scheme · BleepingComputer — US soldier gets 70 months for extorting 10 tech/telecom firms (28 Sep 2026)

breaches identity cloud