# US Soldier Sentenced to 70 Months for Telecom Extortions

> A US Army soldier operating as Kiberphant0m received a 70-month prison sentence for hacking telecommunications firms and extorting victims.

- Published: 2026-10-01T03:09:53.000Z
- Severity: high
- Category: Threat Intel
- Tags: Threat Intel, Ransomware, Credential Theft, Snowflake, AT T
- CVEs: CVE-2023-45208 (CVSS 0)
- Author: Runtime Rebel Intel
- Primary source: https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions/
- Canonical: https://runtimerebel.com/blog/us-soldier-sentenced-to-70-months-for-telecom-extortions

## Key points

- A US Army soldier was sentenced to 70 months in federal prison for hacking major telecommunications companies and extorting victims.
- The attacks leveraged exposed cloud storage credentials that lacked multi-factor authentication enforcement.
- Organizations must mandate multi-factor authentication across all cloud environments and monitor internal insider threats.

A U.S. Army soldier operating under the cybercriminal alias "Kiberphant0m" was sentenced to 70 months in federal prison and ordered to pay nearly $300,000 in restitution. According to [KrebsOnSecurity](https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions/), the individual hacked multiple telecommunications entities and stole mobile call and text metadata belonging to over 100 million customers.

## Overview of the Campaign

The perpetrator, 22-year-old Cameron John Wagenius, was stationed in South Korea when he initiated the intrusions. Working alongside co-conspirators, Wagenius targeted cloud data storage accounts that lacked proper access controls.

### Key Attack Vectors

* **Exposed Credentials:** Attackers leveraged credentials harvested from cloud environments that did not enforce multi-factor authentication.
* **Extortion and Leaks:** Stolen metadata from major providers, including AT&T and Verizon, was used to pressure organizations into paying Bitcoin ransoms.
* **[Insider Threat](/glossary#insider-threat) Dynamics:** Operating with a secret military clearance, the soldier utilized specialized access to coordinate attacks and traffic sensitive data.

## Technical Details and Incarceration Activity

Federal prosecutors detailed that Wagenius continued attempting to gather technical exploits while incarcerated, utilizing peer email systems to query artificial intelligence tools for [exploit](/glossary#exploit) details regarding [CVE-2023-45208](https://nvd.nist.gov/vuln/detail/CVE-2023-45208). The actor attempted to bypass restrictions on [AI](/glossary#ai) models by framing requests as research for a book project, demonstrating advanced prompt manipulation tactics even while in custody.

Co-conspirators linked to the broader infrastructure compromises included individuals connected to historical botnets and major telecommunications breaches, highlighting an interconnected network of cybercriminals.

## Mitigations and Defensive Priorities

Security teams must enforce strict identity and access management controls to prevent similar cloud storage compromises:

* **Mandate Multi-Factor Authentication:** Ensure all cloud data storage accounts and administrative portals require [phishing](/glossary#phishing)-resistant multi-factor authentication without exception.
* **Credential Monitoring:** Regularly audit cloud environments for exposed static [API](/glossary#api) keys and service account credentials.
* **Insider Threat Detection:** Implement strict monitoring on internal networks for anomalous data staging and unauthorized [reconnaissance](/glossary#reconnaissance) queries.

**Related:** [Talos Q2 2026 Report: Phishing and Living-off-the-Land Trends](/blog/talos-q2-2026-report-phishing-and-living-off-the-land-trends), [Picus Blue Report 2026: Enterprise Edge Defenses vs Post-Compromise](/blog/picus-blue-report-2026-enterprise-edge-defenses-vs-post-compromise)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/us-soldier-sentenced-to-70-months-for-telecom-extortions
