INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
U.S. Soldier Sentenced for Extortion of AT&T and Verizon
| 2026-09-25 21:44 HIGH LOW RANSOMWARE & EXTORTION LAW ENFORCEMENT
Executive Summary
AI-generated
A U.S. Army soldier, Cameron John Wagenius, 22, stationed at a base in South Korea, adopted the cybercriminal persona "Kiberphant0m" and was likely behind hacking into multiple telecommunications companies worldwide, including Verizon's Push-to-Talk business, to steal mobile call and text metadata for over 100 million AT&T customers in 2024. The attack worked by exploiting cloud data storage service Snowflake that did not enforce multi-factor authentication, allowing Kiberphant0m to download sensitive credentials. As of September 25, 2026, Wagenius has been sentenced to nearly six years in federal prison and ordered to pay $294,978 in restitution for his crimes, which also included re-extorting victims and threatening national security secrets.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2023-45208 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
• Pre-compromise (ATT&CK mitigation for Botnet): This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
SoldierSoldier
CVE-2023-45208CVE-2023-45208
Target & Sectors
KR
governmentgovernment
telecommunicationstelecommunications
defensedefense
Incident Timeline
October 2024
Threat actor Kiberphant0m publicly extorted AT&T and Verizon's Push-to-Talk business in October 2024 by claiming to have stolen metadata from tens of millions of customers.
Click on any entity below to view its context and source!
organisation
Verizon’s Push
Kiberphant0m claimed to have hacked into more than dozen telecommunications companies worldwide, including Verizon’s Push-to-Talk business, and publicly extorted these companies in exchange for a promise not to publish the stolen data.
September 2025
The U.S. soldier, Wagenius, used a command injection vulnerability in D-Link networking devices to extort money from AT&T and other telecom providers via email requests for exploit code and scripts.
Click on any entity below to view its context and source!
tactic
Privilege Escalation
“According to records from BOP, in or around September 2025, Wagenius used another inmate’s email system to request that the email recipient prompt a commercial AI tool to provide information about “[w]hat CVE’s are there for Windows 10 Enterprise privilege escalation and bypasses” and to “[p]rovide the CVE’s and a real world working script for each CVE . . .
infrastructure
Windows
“According to records from BOP, in or around September 2025, Wagenius used another inmate’s email system to request that the email recipient prompt a commercial AI tool to provide information about “[w]hat CVE’s are there for Windows 10 Enterprise privilege escalation and bypasses” and to “[p]rovide the CVE’s and a real world working script for each CVE . . .
organisation
CVE
“According to records from BOP, in or around September 2025, Wagenius used another inmate’s email system to request that the email recipient prompt a commercial AI tool to provide information about “[w]hat CVE’s are there for Windows 10 Enterprise privilege escalation and bypasses” and to “[p]rovide the CVE’s and a real world working script for each CVE . . .
organisation
Windows 10 Enterprise
“According to records from BOP, in or around September 2025, Wagenius used another inmate’s email system to request that the email recipient prompt a commercial AI tool to provide information about “[w]hat CVE’s are there for Windows 10 Enterprise privilege escalation and bypasses” and to “[p]rovide the CVE’s and a real world working script for each CVE . . .
general_metric
10 privilege escalation
“According to records from BOP, in or around September 2025, Wagenius used another inmate’s email system to request that the email recipient prompt a commercial AI tool to provide information about “[w]hat CVE’s are there for Windows 10 Enterprise privilege escalation and bypasses” and to “[p]rovide the CVE’s and a real world working script for each CVE . . .
organisation
Wagenius’s
Incredibly, despite the enormous financial value of the data stolen from AT&T and other telecom providers, Wagenius’s extortion efforts were largely unsuccessful.
organisation
CVE-2023-45208
The memo states that less than a week later, Wagenius used a different inmate’s email account and requested that the email recipient prompt an AI tool to “[p]rovide the step by step for
CVE-2023-45208
, code for this if any, and if no code exists make some, make sure to describe everything in detail.”
late November 2025
KrebsOnSecurity warned that Kiberphant0m was likely a U.S. soldier stationed in South Korea in late November 2025.
Click on any entity below to view its context and source!
target_region
Korea, Republic of
In late November 2025, KrebsOnSecurity warned that Kiberphant0m
was likely a U.S. soldier stationed in South Korea
.
organisation
KrebsOnSecurity
In late November 2025, KrebsOnSecurity warned that Kiberphant0m
was likely a U.S. soldier stationed in South Korea
.
November 2025
A U.S. soldier was sentenced to 70 months in prison for his role as a co-conspirator with Wagenius and Schuchman in operating the Satori botnet, which was used for DDoS attacks targeting IoT devices.
Click on any entity below to view its context and source!
organisation
IoT
In 2019, Schuchman
pleaded guilty to operating the
Satori
botnet
, a vast collection of hacked Internet-of-Things (IoT) devices that was used for large-scale distributed denial-of-service (DDoS) attacks.
organisation
Snowflake
Two other alleged co-conspirators of Wagenius are still facing charges in connection with the Snowflake data thefts;
Conor Riley Moucka
, a.k.a.
August 2026
A U.S. soldier with secret clearance was arrested and pleaded guilty to extortion charges after attempting to learn about vulnerabilities in Bureau of Prisons computer systems while incarcerated.
Click on any entity below to view its context and source!
tactic
Data Breach
“Judische,” of Kitchener, Ontario was arrested in 2024 and
pleaded guilty in August 2026
; and
John Erin Binns
, an American man currently living in Turkey who is also wanted for
a 2021 data breach at T-Mobile
that exposed the personal information of at least 76 million customers.
source_region
United States
“Judische,” of Kitchener, Ontario was arrested in 2024 and
pleaded guilty in August 2026
; and
John Erin Binns
, an American man currently living in Turkey who is also wanted for
a 2021 data breach at T-Mobile
that exposed the personal information of at least 76 million customers.
organisation
T-Mobile
“Judische,” of Kitchener, Ontario was arrested in 2024 and
pleaded guilty in August 2026
; and
John Erin Binns
, an American man currently living in Turkey who is also wanted for
a 2021 data breach at T-Mobile
that exposed the personal information of at least 76 million customers.
victims
76 customers
“Judische,” of Kitchener, Ontario was arrested in 2024 and
pleaded guilty in August 2026
; and
John Erin Binns
, an American man currently living in Turkey who is also wanted for
a 2021 data breach at T-Mobile
that exposed the personal information of at least 76 million customers.
organisation
BOP
notes that while Wagenius pleaded guilty almost immediately and has been remarkably cooperative, he recently got caught trying to find security vulnerabilities in the BOP’s computer network.
Sept. 19
Federal prosecutors filed a sentencing memo on September 19, resulting in the U.S. soldier receiving 70 months in prison for extorting money from AT&T and Verizon employees.
Click on any entity below to view its context and source!
organisation
PDF
A
sentencing memo
(PDF) filed Sept. 19 by federal prosecutors in Seattle
2026/09/25
A U.S. Army soldier was sentenced to 70 months in federal prison and ordered to pay nearly $300,000 in restitution for hacking into multiple telecommunications companies and stealing mobile call and text metadata from over 100 million AT&T customers in 2024.
Click on any entity below to view its context and source!
industry
Telecommunications
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million
AT&T
customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.
organisation
U.S. Army
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million
AT&T
customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.
victims
100 AT&T customers
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million
AT&T
customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.
financial
$300,000 today
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million
AT&T
customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.
financial
$294,978 prison
At his sentencing hearing in Seattle today, Wagenius was sentenced to nearly six years in federal prison, and ordered to pay $294,978 in restitution.
2026/09/25
A U.S. soldier, posing as the cybercriminal persona "Kiberphant0m", downloaded sensitive data from customers of Snowflake without their knowledge using exposed credentials that lacked multi-factor authentication.
Click on any entity below to view its context and source!
organisation
AT&T
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions.
organisation
Verizon Extortions
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions.
organisation
MFA
Working with three alleged co-conspirators, Kiberphant0m downloaded data from several large customers of the cloud data storage service
Snowflake
that had exposed credentials and did not enforce multi-factor authentication (Snowflake has since mandated MFA on all accounts).
Tactical Metrics
Metrics
victims
100,000,000
At&T Customers
Click for context!
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million
AT&T
customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.
Metrics
financial
300,000
Today
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million
AT&T
customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.
Metrics
victims
76,000,000
Customers
“Judische,” of Kitchener, Ontario was arrested in 2024 and
pleaded guilty in August 2026
; and
John Erin Binns
, an American man currently living in Turkey who is also wanted for
a 2021 data breach at T-Mobile
that exposed the personal information of at least 76 million customers.
Metrics
infrastructure
Windows
Affected Product
“According to records from BOP, in or around September 2025, Wagenius used another inmate’s email system to request that the email recipient prompt a commercial AI tool to provide information about “[w]hat CVE’s are there for Windows 10 Enterprise privilege escalation and bypasses” and to “[p]rovide the CVE’s and a real world working script for each CVE . . .
Metrics
financial
294,978
Prison
At his sentencing hearing in Seattle today, Wagenius was sentenced to nearly six years in federal prison, and ordered to pay $294,978 in restitution.
Intelligence Sources
Krebs On Security
2026-09-25
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
Krebs On Security
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:15
Comprehensive Tactical Telemetry
Highly Correlated Entities
16x
organisation
Identified Entity
KrebsOnSecurity
entity
11x
timeline
Temporal Reference
late November 2025
date
5x
attribution
Attributing Entity
the
Bureau of Prisons
authority
5x
tactic
Cyber Operation Type
Botnet
tactic
3x
industry
Targeted Sector
Telecommunications
sector
Contextual Telemetry
Context Block
10 METRICS
target region
Target Country
Korea, Republic of
country
victims
At&T Customers
100,000,000
at&t customers
financial
Today
300,000
today
source region
Origin Country
United States
country
victims
Customers
76,000,000
customers
infrastructure
Affected Product
Windows
software
general metric
Privilege Escalation
10
privilege escalation
financial
Prison
294,978
prison
vulnerability
Exploited CVE
CVE-2023-45208
cve
malware
Malware Payload
Soldier
tool
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.