Verizon
Incident posture
Timeline
Summary
A former US soldier was sentenced to 70 months in prison for hacking into the systems of AT&T and Verizon and leaking the call detail records of a government official. Using the online alias “kiberphant0m,” he conspired with others to obtain credentials via SSH brute force tools, accessed victim networks, exfiltrated data, and attempted to extort at least one million dollars from multiple organizations. The stolen information was sold on cybercrime forums and used for further fraud. He pleaded guilty to wire fraud conspiracy and extortion, was ordered to pay restitution, and his accomplices, including a Canadian national and a US citizen, also faced guilty pleas related to the same hacking campaign.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Cameron John Wagenius, a 22‑year‑old former United States Army soldier, engaged in hacking activities against wireless carriers from April 2023 through December 2024 while still on active duty. He used the online alias “kiberphant0m” and collaborated with accomplices to obtain credentials for target systems employing the SSH Brute utility and other tools. With those credentials the group accessed the databases of AT&T and Verizon, exfiltrated call detail records and other sensitive data, and then attempted to extort the victim organizations by threatening to publish the stolen information. In November 2024 Wagenius publicly disclosed the confidential call detail records of a government official and warned that additional records would be released unless demands were met.
Wagenius was arrested in December 2024 following an investigation that linked the disclosed records to his online persona. In February 2025 he admitted in court to sharing the confidential phone records, and in July 2025 he pleaded guilty to wire fraud conspiracy and extortion charges. The court sentenced him to 70 months of imprisonment and ordered him to pay $294,978 in restitution for the harm caused. Beyond the prison term, the judgment reflected the scale of the attempted extortion, which prosecutors said sought at least $1 million from the compromised organizations.
His conspirators included Canadian national Connor Riley Moucka, known online as Judische, and United States citizen John Erin Binns. Moucka, Binns and Wagenius were implicated in intrusions against AT&T, T‑Mobile and in the broader Snowflake hacking campaign that affected hundreds of organizations. Connor Riley Moucka pleaded guilty in August 2025 for his role in the conspiracy, while the case against John Erin Binns proceeded according to the judicial schedule. The combined actions of the group resulted in data theft, extortion attempts, and the sale of stolen information on cybercrime forums, leading to court‑ordered restitution and prison sentences.
Sources
Sources available to members: 1 source.