Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Former US Soldier Who Hacked AT&T and Verizon Pleads Guilty

Cameron John Wagenius pleaded guilty to charges related to hacking into US telecommunications companies.

Hacker pleads guilty

A former US soldier accused of hacking into AT&T and Verizon systems and leaking presidential call logs pleaded guilty to fraud and identity theft charges, the US Department of Justice announced.

According to court documents, the individual, Cameron John Wagenius, 21, engaged in hacking and extortion activities between April 2023 and December 2024, while on active duty with the US Army.

Using the nickname ‘kiberphant0m’, Wagenius and his co-conspirators aimed to defraud at least 10 organizations after obtaining login credentials for their networks.

The credentials, documents presented in court show, were obtained using a hacking tool called SSH Brute and through other means. The miscreants used Telegram group chats to share the stolen login information and to discuss obtaining access to the victims’ networks.

The hackers exfiltrated data from the compromised networks and extorted the victims, both via private communication and on public forums, threatening to publish the stolen information on cybercrime portals such as BreachForums and XSS.is.

According to court documents, the suspects also offered the data for sale on these forums, and successfully sold some of it. Furthermore, they used the data in other fraud schemes, such as SIM swapping.

Advertisement. Scroll to continue reading.

The former US Army soldier and his co-conspirators attempted to extort over $1 million from the victim companies, the DoJ says.

Wagenius, who was arrested in December 2024, pleaded guilty to wire fraud conspiracy and extortion charges, which carry maximum penalties of 20 and five years in prison, and to identity theft charges, for which he could be sentenced to a mandatory two-year prison sentence, consecutive to any other prison time.

Previously, he pleaded guilty to sharing confidential phone records, in connection with these attacks.

The victim organizations have not been named, but investigative journalist Brian Krebs revealed that Wagenius was selling phone records stolen from AT&T and Verizon, and was likely involved in the Snowflake hacking campaign that affected hundreds of organizations.

Wagenius’ co-conspirators include Canadian national Connor Riley Moucka, also known as Judische, who was arrested in late October 2024 in connection to the Snowflake account hacking, and John Erin Binns, who was involved in the AT&T hack and previously took credit for the 2021 T-Mobile hack. Binns was arrested in Turkey in May 2024.

Related: Man Who Hacked Organizations to Advertise Security Services Pleads Guilty

Related: Iranian Man Pleads Guilty to Role in Baltimore Ransomware Attack

Related: US Student to Plead Guilty Over PowerSchool Hack

Related: Suspected Scattered Spider Hacker Pleads Guilty

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Cyera has appointed Naveen Palavalli as Chief Marketing Officer.

Connie Devine has been promoted to Chief Information Security Officer at Phillips 66.

Jeff Lunglhofer becomes Chief Security Officer at Coinbase, replacing Philip Martin.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.