Former U.S. soldier gets 70 months for telecom hacking and extortion

Cameron John Wagenius must also pay $294,978 after prosecutors said his group targeted at least 10 organizations and sought more than $1 million in extortion.

By · Published

Primary source: U.S. Department of Justice

Why it matters

The case links credential theft and data extortion to a multi-organization campaign, with prosecutors saying the group tried to extract more than $1 million. The restitution order is a separate, smaller court figure, not a measure of the campaign's total losses.

A dimly lit desk with a glowing computer monitor displaying abstract network diagrams, a manila folder in the foreground, and server racks in the blurred background.

Cameron John Wagenius, the former U.S. Army soldier who used the online name "kiberphant0m," was sentenced on September 25th to 70 months in federal prison for a telecom hacking and extortion scheme, the Justice Department said. The 22-year-old was also ordered to pay $294,978 in restitution.

The sentence closes a case that prosecutors described as a wider operation against at least 10 organizations. Between April 2023 and December 18th, 2024, Wagenius and co-conspirators obtained login credentials for protected computer networks, stole data and tried to extort the organizations, according to court documents summarized by the Justice Department. They sought at least $1 million in total. That is the amount they attempted to extract, not a figure the department says they collected.

Wagenius helped develop a hacking tool called SSH Brute, prosecutors said. The group also used Telegram chats to transfer stolen credentials and discuss unauthorized access. After obtaining data, members threatened victims privately and on cybercrime forums, and offered some stolen information for sale. The Justice Department said at least some of the data was sold and that stolen information was also used in other fraud, including SIM-swapping.

The sentence covers conduct that included the public exposure of sensitive call records. In November 2024, Wagenius posted stolen, non-content call detail records belonging to a government official and family members of another former official, while threatening to release more unless a ransom was paid, prosecutors said. Call detail records capture information about communications rather than the content of calls. The department said one post suggested Wagenius was retaliating for the recent arrest of another cybercriminal.

The prosecution unfolded through guilty pleas in two Western District of Washington cases. Wagenius pleaded guilty on March 5th, 2025, to two counts of unlawfully transferring confidential phone-record information. On July 15th, 2025, he pleaded guilty to conspiracy to commit wire fraud, extortion in relation to computer fraud and aggravated identity theft, according to the Justice Department's plea announcement. The earlier announcement said the identity-theft charge carried a mandatory two-year term consecutive to any other prison time; the judge ultimately imposed a total sentence of 70 months.

The records in the case place the telecom attacks within a broader campaign of credential theft and data extortion. In its sentencing announcement, the Justice Department said Wagenius was on active duty in the Army during the scheme. The agency also said he and his co-conspirators targeted U.S. and foreign telecommunications companies and attempted to sell stolen information to a foreign intelligence service. Those details underscore the range of the alleged operation, while the sentence and restitution order apply to Wagenius.

Earlier reporting connected Wagenius's case to the theft of phone records from AT&T and Verizon. TechCrunch reported in January 2025 that prosecutors had tied his case to an intrusion and extortion investigation involving other defendants and overlapping evidence. The Justice Department's September 25th sentencing release does not name the telecom victims in its account of Wagenius's sentence, so the department's announcement is the basis for the specific scope and restitution figure here.

Restitution of $294,978 is substantially below the more than $1 million prosecutors said the group tried to extort. The figures describe different things: the first is the amount the court ordered Wagenius to repay, while the second is the group's attempted demands across victim data owners. The department did not characterize the restitution order as a total accounting of losses from the wider campaign.

The case also illustrates the operational risk in stolen credentials: they gave the group a way to enter networks, move records among conspirators and turn access into extortion demands. The Justice Department says the group used multiple methods to obtain credentials, including SSH Brute. It does not say that the tool alone enabled the intrusions, or that every target was compromised in the same way.

The Dark Web Informer X thread that circulated the sentence linked to the Justice Department release. The sentence and restitution figure were announced by the department on September 25th, 2026, the same day as that post.

Reader comments

Conversation for this story loads after sign-in.