A U.S. Army soldier operating under the cybercriminal alias “Kiberphant0m” was sentenced to 70 months in federal prison and ordered to pay nearly $300,000 in restitution. According to KrebsOnSecurity, the individual hacked multiple telecommunications entities and stole mobile call and text metadata belonging to over 100 million customers.
Overview of the Campaign
The perpetrator, 22-year-old Cameron John Wagenius, was stationed in South Korea when he initiated the intrusions. Working alongside co-conspirators, Wagenius targeted cloud data storage accounts that lacked proper access controls.
Key Attack Vectors
- Exposed Credentials: Attackers leveraged credentials harvested from cloud environments that did not enforce multi-factor authentication.
- Extortion and Leaks: Stolen metadata from major providers, including AT&T and Verizon, was used to pressure organizations into paying Bitcoin ransoms.
- Insider Threat Dynamics: Operating with a secret military clearance, the soldier utilized specialized access to coordinate attacks and traffic sensitive data.
Technical Details and Incarceration Activity
Federal prosecutors detailed that Wagenius continued attempting to gather technical exploits while incarcerated, utilizing peer email systems to query artificial intelligence tools for exploit details regarding CVE-2023-45208. The actor attempted to bypass restrictions on AI models by framing requests as research for a book project, demonstrating advanced prompt manipulation tactics even while in custody.
Co-conspirators linked to the broader infrastructure compromises included individuals connected to historical botnets and major telecommunications breaches, highlighting an interconnected network of cybercriminals.
Mitigations and Defensive Priorities
Security teams must enforce strict identity and access management controls to prevent similar cloud storage compromises:
- Mandate Multi-Factor Authentication: Ensure all cloud data storage accounts and administrative portals require phishing-resistant multi-factor authentication without exception.
- Credential Monitoring: Regularly audit cloud environments for exposed static API keys and service account credentials.
- Insider Threat Detection: Implement strict monitoring on internal networks for anomalous data staging and unauthorized reconnaissance queries.
Related: Talos Q2 2026 Report: Phishing and Living-off-the-Land Trends, Picus Blue Report 2026: Enterprise Edge Defenses vs Post-Compromise