Cameron John Wagenius, a 22-year-old former U.S. Army soldier who called himself "kiberphant0m," was sentenced in Seattle federal court on Friday, September 25, 2026, to 70 months in prison and ordered to pay $294,978 in restitution Nextgov - Soldier Sentenced for…. The Justice Department's July 15, 2025 release announcing his guilty plea said he and co-conspirators tried to extort at least $1 million from at least 10 victim organizations between April 2023 and Dec. 18, 2024, while he was on active duty Justice.gov - Cameron Wagenius….
The exposed parties are telecom carriers and customers of Snowflake, the cloud data platform. CyberScoop reported that AT&T confirmed cybercriminals entered its Snowflake environment and stole six months of phone and text records of "nearly all" its customers CyberScoop - Active-Duty Soldier…. Allison Nixon, chief research officer at the investigations firm Unit 221B, told CyberScoop that Wagenius leaked President Donald Trump's call records during failed attempts to extort $500,000 from AT&T CyberScoop - Active-Duty Soldier…. KrebsOnSecurity reported that the Snowflake customers the crew downloaded from had exposed credentials and did not enforce multi-factor authentication, and that Snowflake has since mandated MFA on all accounts krebsonsecurity.com.
Seventy months across two cases
The plea release set maximums of 20 years for conspiracy to commit wire fraud and five years for extortion in relation to computer fraud. It also set a mandatory two-year term for aggravated identity theft, consecutive to any other prison time Justice.gov - Cameron Wagenius…. Those terms sum to the 27-year maximum The Record reported after the plea therecord.media. That ceiling covers the July 2025 plea only. Wagenius also pleaded guilty, in a separate case in the same district, to two counts of unlawful transfer of confidential phone records information justice.gov, and the September 25 sentencing covered both cases krebsonsecurity.com.
The restitution order is about 29% of the attempted extortion, though the two measure different things: one compensates losses, the other totals demands. KrebsOnSecurity reported that AT&T had already paid the extortion group a $370,000 Bitcoin ransom krebsonsecurity.com. Prosecutors said Wagenius, Canadian co-defendant Connor Moucka and John Erin Binns together received more than $2.5 million in extortion payments, CyberScoop reported CyberScoop - Active-Duty Soldier…. Our read is that the $294,978 order tracks losses tied to Wagenius's own conduct, not the crew's receipts.
The entry point was customer credentials without MFA
The Justice Department said the conspirators obtained login credentials with a tool they called SSH Brute, among other means, and traded them in Telegram group chats Justice.gov - Cameron Wagenius…. They threatened to post stolen data on BreachForums and XSS.is, sold some of it, and used it for SIM-swapping Justice.gov - Cameron Wagenius…. The AT&T haul was metadata: source and destination numbers, timestamps and durations, KrebsOnSecurity reported krebsonsecurity.com.
Security.org, a consumer-security site, reported that AT&T disclosed on July 12, 2024 that records were downloaded from its Snowflake workspace between April 14 and April 25, 2024. The records covered about 109 to 110 million wireless customers, from May 1 to October 31, 2022, with a few extending to January 2, 2023 security.org. Snowflake's own customer case study quotes AT&T's chief data officer, Andy Markus, saying the platform lets AT&T "keep that single source of truth so that we're all on the same page" snowflake.com. A second Snowflake page says partners reach AT&T data through Secure Data Sharing without copying it snowflake.com. Our read is that this consolidation is what let one workspace login reach nearly the whole wireless base.
Snowflake reported on September 2, 2026, 23 days before the sentencing, second-quarter fiscal 2027 product revenue of $1.49 billion, up 37% year over year. It reported net revenue retention of 126% and raised full-year product revenue growth guidance to 36% from 31% sec.gov. On this evidence, the customer base has not penalised the platform for the 2024 thefts.
Court filings name no victims; the company list comes from researchers
Authorities did not name Wagenius's victims in court filings. They said only that he disclosed non-content call detail records of a government official and of family members of another former official CyberScoop - Active-Duty Soldier…. Gizmodo's February 2025 report said the hacks were "believed to be related" to Snowflake Gizmodo - AT&T Hacker Sentenced…. Prosecutors also said that before his December 2024 arrest he tried to sell stolen data to a foreign intelligence service and sought information about defecting to Russia CyberScoop - Active-Duty Soldier….
The victim counts diverge by an order of magnitude, and the larger ones describe the whole Snowflake campaign rather than Wagenius's conduct:
| Count | Scope | Reported by |
|---|---|---|
| At least 10 organizations | Wagenius conspiracy, per DOJ | Justice.gov - Cameron Wagenius… |
| More than 100 Snowflake customers | 2024 campaign | The Record therecord.media |
| More than 160 companies | Believed accessed via Snowflake | Gizmodo Gizmodo - AT&T Hacker Sentenced… |
| More than 165 Snowflake customer environments | Moucka's guilty plea | CyberScoop CyberScoop - Active-Duty Soldier… |
Sources: Justice.gov - Cameron Wagenius…CyberScoop - Active-Duty Soldier…therecord.mediaGizmodo - AT&T Hacker Sentenced….
Moucka pleaded guilty in August 2026, KrebsOnSecurity reported krebsonsecurity.com. Binns, an American living in Turkey, is not in U.S. custody CyberScoop - Active-Duty Soldier….