Army Soldier Gets 70 Months for AT&T Hack, Then Tried to Hack the Prison
Cameron Wagenius pleaded guilty to stealing call records for more than 100 million AT&T customers. Behind bars, he used other inmates' email accounts to prompt AI tools for exploit code.

Key points
- Cameron John Wagenius, a 22-year-old U.S. Army soldier stationed in South Korea, was sentenced in Seattle to 70 months in federal prison and ordered to pay $294,978 in restitution.
- Prosecutors said he stole mobile call and text metadata for more than 100 million AT&T customers in 2024, working under the handle "Kiberphant0m."
- While awaiting sentencing, he used other inmates' email accounts to prompt commercial AI tools for exploit code, including for CVE-2023-45208, a command injection flaw in a D-Link repeater.
- Despite AT&T reportedly paying a $370,000 Bitcoin ransom to his extortion group, Wagenius personally earned roughly $1,500 from selling stolen data.
- Two alleged co-conspirators tied to the underlying Snowflake account thefts still face charges; a third, Kenneth Schuchman of Vancouver, Washington, assisted the extortion effort.
A U.S. Army soldier who broke into a string of telecom companies and walked off with the call records of more than 100 million AT&T customers was sentenced today in Seattle to 70 months in federal prison.
Cameron John Wagenius, 22, pleaded guilty earlier this year to charges in two federal indictments. He was stationed at a U.S. Army base in South Korea when he ran the online persona "Kiberphant0m." Restitution was set at $294,978.
The underlying theft was not sophisticated. Wagenius and three alleged co-conspirators pulled customer data from accounts on Snowflake, a cloud storage service, that had exposed passwords and no multi-factor authentication, the extra login step that blocks stolen passwords from being reused. Snowflake has since made that step mandatory. We reported on Conor Riley Moucka's guilty plea in that same campaign on 5 August.
The stolen AT&T records were metadata: source and destination phone numbers, timestamps and call durations, not the content of any call. Kiberphant0m bragged about the theft on cybercrime forums in October 2024 and claimed to have hit more than a dozen telecoms worldwide, including Verizon's Push-to-Talk service.
How was the soldier caught?
Investigators were tipped off that an active-duty soldier with a secret clearance was involved. KrebsOnSecurity publicly identified Kiberphant0m as a U.S. Soldier in South Korea in late November 2025, and Wagenius was arrested within weeks.
The Defense Criminal Investigative Service worked the case alongside the FBI, the Army Criminal Investigative Division and the Secret Service. "We don't often get leads where there's an active duty soldier with a secret clearance who's creating hacking tools and trafficking in data," DCIS resident agent in charge Paul Russell told KrebsOnSecurity.
After the arrest of co-conspirator Conor Riley Moucka in 2024, and after AT&T had reportedly paid a $370,000 Bitcoin ransom, Kiberphant0m posted what he claimed were AT&T call logs for then-President-elect Donald Trump and then-Vice President Kamala Harris, plus schematics he said were stolen from the National Security Agency.
What did he do from inside prison?
He kept researching hacking, using other inmates' email accounts to bounce prompts to commercial AI tools. A sentencing memo filed 19 September by federal prosecutors lays out the sequence.
| Date (2025) | Activity described in the memo |
|---|---|
| Around September | Asked for CVEs and working scripts for Windows 10 Enterprise privilege escalation |
| Less than a week later | Asked for step-by-step exploitation of CVE-2023-45208, with code |
| Same month | Asked how to build an antenna from prison commissary items |
| Same month | Asked for research on escaping prison |
CVE-2023-45208 is a three-year-old command injection flaw in a D-Link networking device that lets someone within radio range run commands as the top-level "root" user by broadcasting a crafted Wi-Fi network name.
Wagenius framed some of the AI queries as research for a book he was writing. Prosecutors called that a form of prompt injection, meaning wording a request in a way that tricks the AI's safety filters into producing content they normally refuse.
The government told the court it has no evidence Wagenius actually deployed anything against Bureau of Prisons systems. He told investigators he was only looking for flaws to report back to the BOP.
One detail is worth sitting with. Wagenius stole data valuable enough to draw a six-figure ransom from AT&T and personally netted about $1,500. The harm was real and the payday was not. That gap, between the damage a young insider can do and what he walks away with, is the part of this case that should worry the telecom sector and the Pentagon equally.



