FR
live

US soldier sentenced to 70 months for extorting ten telecom firms

On 28 September 2026, Cameron John Wagenius, aka kiberphant0m, was sentenced to 70 months in prison for hacking and extorting at least ten technology and telecommunications companies from his military base. The case is a reminder that insider threat and SSH brute-forcing remain an entry path as effective as any zero-day.

A long aisle of dark telecom server racks, a single amber ethernet cable snaking across the floor to a rack door left slightly ajar.

28 September 2026. Cameron John Wagenius, 21, a former US Army soldier, is sentenced to 70 months in prison for hacking and extorting at least ten technology and telecommunications companies between April 2023 and December 2024. December 2024. He is arrested in Texas. 28 September 2026. He is also ordered to pay $294,978 in restitution. Why it matters: the hacker, known online as kiberphant0m and cyb3rph4nt0m, operated from active duty, stealing credentials through SSH brute-forcing — a reminder that an insider threat needs no zero-day to break a carrier.

A soldier on active duty, not an organised crime syndicate

The profile defies the organised-gang stereotype. Wagenius was on active duty when he and accomplices stole credentials to their victims’ networks. He pleaded guilty in February 2025 to hacking AT&T and Verizon — two counts of unlawfully transferring confidential phone records — and again in July 2025 to aggravated identity theft, conspiracy to commit wire fraud, and extortion related to computer fraud.

The case shows a reality security teams know well but the media underplays: insider threat is not always a disgruntled employee in the building. It is also an individual with legitimate access to infrastructure — here, a military base — who decides to monetise technical skills against outside targets. The line between “trusted staff” and “attacker” comes down to an individual choice, not a badge.

The playbook: SSH brute-forcing and Telegram

The technique described by the Department of Justice is simple and ruthless. Wagenius and his accomplices stole credentials using an SSH brute-forcing tool he helped develop, then used Telegram to transfer the stolen credentials and coordinate their attacks.

That is the most instructive part for a defender. SSH brute-forcing targets administration interfaces and remote services exposed with weak or reused passwords. Unlike a zero-day, it relies on no software vulnerability: it exploits a failed authentication hygiene. An SSH key, MFA, or source-IP restriction is usually enough to neutralise it. The tool does not need to be sophisticated to succeed when the target leaves the door open.

Telegram is the hub here: both the channel for moving credentials and the planning tool. For an analyst, it is a reminder that the traces of an intrusion live as much in encrypted messaging as in network logs — and that coordination between attackers often precedes the attack itself.

For defenders, that shifts the detection target. Credential-theft campaigns like this one leave a trail in authentication logs long before the extortion email arrives: repeated failed SSH logins, then a successful one from an unexpected source, then a flurry of account queries and bulk exports. Watching for that sequence is cheaper than responding to the leak notice that follows it — and it is a signal a human analyst, unlike a signature-based detector, can read in minutes.

The extortion ecosystem

Once data was stolen, Wagenius and his accomplices extorted victims “both privately and in public forums”, threatening to post the data on BreachForums and XSS.is. They also offered the data for sale for thousands of dollars, sold at least some of it, and reused the stolen data for other fraud, including SIM-swapping. In total, they attempted to extort at least $1 million.

Two of his accomplices, Connor Riley Moucka (aka Waifu) and John Erin Binns (aka irdev), are the same men accused of siphoning data from more than 165 organisations hosted on Snowflake — a campaign we documented in detail in our piece on Moucka’s guilty plea. The same actors thus move between brute-forced credentials and the exploitation of cloud accounts missing MFA: two faces of the same extortion economy.

The takedown of the Snowflake cell

Wagenius’s sentencing closes a chapter that began in late 2024. On 30 October 2024, Connor Riley Moucka was arrested in Canada at the request of the United States. In November 2024, Moucka and John Erin Binns were indicted for the Snowflake campaign — more than 165 organisations, terabytes of data, and hundreds of millions of people affected, from Ticketmaster to Santander. Wagenius pleaded guilty in February 2025 and again in July 2025. In August 2026, Moucka pleaded guilty in turn. The 28 September 2026 sentence is the last milestone of that judicial sequence.

That timeline has an operational meaning. The campaign ran for nearly two years before courts produced convictions. In that time the stolen credentials circulated, the data was resold, and victims suffered cascading fraud. The slowness of the criminal response is not an anomaly: it is the norm. It sharpens the defensive conclusion — you cannot wait for the justice system to close your doors.

What it teaches defenders

Three lessons stand out, all actionable without new budget.

Lock down SSH access. The initial vector was brute-forcing against exposed services. Disable password authentication in favour of keys, enforce MFA on all administrative access, and restrict source ranges. A brute-force only succeeds against a target that allows it.

Watch the insider as closely as the outsider. A soldier on active duty operated for nearly two years. Correlate unusual privileged access, bulk exports, and transfers to encrypted messaging services. Detecting exfiltration matters as much as detecting intrusion.

Treat extortion as a product. BreachForums, XSS.is, SIM-swapping: the ecosystem has sales channels, prices, and reputations. Understanding that chain lets you anticipate what an attacker will do with the data — sell it, leak it, or reuse it for downstream fraud.

The thread running through all three is a single sentence: the flaw Wagenius exploited was not in software but in access and credential management. A sophisticated firewall does not stop a stolen credential opening a legitimate session. Consider the concrete countermeasures — disable PasswordAuthentication in favour of keys, run fail2ban on exposed SSH endpoints, enforce MFA on every jump host, and purge default or reused passwords from network devices. None of this is exotic; all of it would have blunted a brute-force that relied on exactly those defaults being present. That is the uncomfortable takeaway — a 21-year-old on active duty did not need a zero-day, only an organisation that had left the door ajar.

Verdict

If you run telecom infrastructure or any service exposed to the internet, audit the authentication on your administration interfaces this week: an SSH brute-force that ran for two years at carriers will not spare a less mature estate. If you manage employee or contractor credentials, remember that insider threat is not confined to the office — it includes anyone holding legitimate access, wherever they are, and a simple credential theft is enough to open an extortion cycle. If you are being extorted, do not pay without weighing the precedent: Wagenius’s sentencing shows that stolen data ends up resold or leaked even after payment. Prison is a signal, not a deterrent — the only reliable defence is to close the doors brute-forcing exploits. And that work is never done once: it is the same hygiene that stops the next kiberphant0m, whoever they turn out to be.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

One URL-encoded character slips attackers past WAFs and onto Oracle PeopleSoft

Google has documented a fresh wave of exploitation of CVE-2026-35273 (CVSS 9.8) by UNC6240, a ShinyHunters-linked actor: the group URL-encodes a single character in the path to bypass WAFs and drop web shells on Oracle PeopleSoft. Patch, disable the EMHub, and hunt for /PSEMHUB/ in every encoded form.

Two GitHub Actions hit by Mini Shai-Hulud re-enabled with their payload still live

The actions-cool/issues-helper and maintain-one-comment actions, compromised on 18 May 2026 in the Mini Shai-Hulud campaign, were re-enabled on 16 September with tags still pointing at malicious code, according to Socket. The lesson is blunt: in CI/CD, a mutable tag is a door left open.

← Back to the feed

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss