HomeSecurityKiberphant0m: 70 months in prison for breaches of telecommunications companies

Kiberphant0m: 70 months in prison for breaches of telecommunications companies

70 months in prison was sentenced Former US Army soldier Cameron John Wagenius to for his participation in a campaign of cyberattacks and extortion against at least 10 technology and telecommunications companies in the US. The illegal activities spanned from April 2023 to December 2024 and included the interception of access credentials, the theft of sensitive data and the demand for ransom with threats of releasing the information.

Kiberphant0m Cameron Wagenius condemns AT&T Verizon data breach

Wagenius, who was just 21 years old at the time of the prosecution, used the online aliases “kiberphant0m” and “cyb3rph4nt0m.” He was arrested in Texas in December 2024 and subsequently pleaded guilty to offenses related to illegal access to telecommunications systems and exploitation of stolen data.

In addition to the prison sentence, the court ordered the payment of $294,978. The case highlights the dangers that arise when stolen credentials are used to breach corporate systems and create a broader blackmail mechanism.

How the cybercrime network operated

According to court documents cited by the US Department of Justice, Wagenius participated in the attacks while serving in the US Army. Together with accomplices, he allegedly obtained login credentials for the target companies' networks using a hacking tool called "SSH Brute", which he helped develop.

See also: Verizon DBIR 2026: Vulnerability Exploitation Outpaces Credential Theft

This method is part of a broader category of attacks that attempt to gain access to systems by exploiting weak or exposed authentication mechanisms. When an account is compromised, attackers can, depending on the access rights, gain access to customer records, internal databases, or other critical information.

The accomplices also allegedly used Telegram to exchange stolen credentials and coordinate their actions. The use of instant messaging apps facilitates collaboration between different members of a criminal group, without this implying that the platform itself is responsible for the illegal activities.

CEVA Logistics customer data breach Steam hardware

Blackmail with threats of data disclosure

After obtaining the information, Wagenius and his accomplices allegedly demanded money from the companies they had breached. The threats were made both privately and through online cybercrime-related forums, including BreachForums and XSS.is.

According to the Department of Justice, the perpetrators threatened to release the data if victims did not pay a ransom. In other cases, they offered the stolen information for sale for thousands of dollars, and were able to sell at least some of the material.

In total, the group attempted to extract at least $1 million. This amount refers to the demands of the perpetrators and should not be confused with the compensation awarded to Wagenius.

This practice is a typical example of data extortion: criminals do not necessarily need to disrupt a company's systems to cause financial damage. They only need to obtain information that could expose customers, cause legal consequences, or damage the company's reputation.

See also: AT&T, T-Mobile and Verizon team up to eliminate dead zones

The connection to the Snowflake attacks

The Wagenius case is linked to a broader wave of cyberattacks that have hit organizations using 's cloud storage Snowflake platform . Two individuals named in the same case, Connor Riley Moucka , known as "Waifu" and "Judische," and John Erin Binns , known as "irdev" and "j_irdev1337," were charged with participating in attacks on customers of the service.

In August 2026, Moucka pleaded guilty to his role in a campaign that led to the breach of more than 165 organizations, the theft of billions of records, and the extortion of victims.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Among the organizations affected by incidents in the broader campaign were AT&T, Ticketmaster, Santander, Advance Auto Parts and Neiman Marcus. The attacks had consequences for a large number of consumers, as the data stolen included sensitive customer information.

The case highlights that attacks on cloud environments do not always require the exploitation of an unknown vulnerability in the platform itself. In the campaign against Snowflake customers, researchers identified the use of stolen credentials, which were obtained, among other things, through phishing malware. Accounts without multi-factor authentication enabled were particularly vulnerable.

SIM swapping: How stolen data can be exploited

Another aspect of the case concerns the use of stolen information in scams SIM swapping. This is a technique in which an attacker manages to transfer a victim's mobile phone number to a SIM card that he controls, usually by deceiving the telecommunications provider or exploiting weaknesses in identification procedures.

Once they gain control of the number, they can receive calls and SMS messages intended for the rightful owner. This may allow them to intercept one-time passwords and attempt to access email, social media, or financial accounts.

Cyberphant0m - SecNews.gr

For this reason, the protection of telecommunications records is not only about the privacy of subscribers. It is also directly linked to the security of other digital services that use the phone number as a means of account recovery or identity verification.

See also: Verizon launches Lite home internet for areas with limited coverage

Business security courses

The case highlights the need for multi-layered protection of corporate systems. Using strong and unique passwords is a key measure, but it is not enough when credentials have already been stolen from infected devices or leaked on criminal forums.

Snowflake announced changes to its security policies in 2024, requiring MFA to be enabled by default for users on new accounts and a minimum length of 14 characters for new or modified passwords.

Businesses also need to restrict access rights, monitor unusual connections, and promptly revoke credentials that may have been exposed. Encryption, event logging, and a tested incident response plan can limit the consequences of a breach.

Wagenius' conviction sends a clear message about the legal consequences of cyberattacks. At the same time, the case shows that tackling cybercrime requires both prosecuting perpetrators and systematically strengthening the security of organizations that manage the data of millions of people.

source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS