US Army Soldier Turned Hacker: Exposed in $1M Extortion Scandal Targeting AT\&T and Verizon

Listen to this Post

Featured Image
Inside the Shocking Descent of a Young Soldier into Cybercrime

A shocking cybercrime case has rocked the cybersecurity world after a 21-year-old former U.S. Army soldier, Cameron John Wagenius, admitted to an elaborate hacking and extortion operation targeting major telecom companies, including AT\&T and Verizon. The revelation has sparked nationwide concern not only due to the scale of the attack but also because it was conducted by someone who was still serving in the U.S. military at the time. Wagenius’s cybercrime spree occurred between 2023 and 2024, under multiple aliases such as “kiberphant0m” and “buttholio,” and involved the theft of login credentials, SIM-swapping attacks, and extortion threats reaching up to \$1 million. His arrest on December 20, 2024, followed a sweeping investigation by the U.S. Department of Justice, culminating in a plea agreement that could lead to a 27-year prison sentence.

Massive Cybercrime Ring Unveiled

Between April 2023 and December 2024, Cameron John Wagenius orchestrated a sophisticated cybercrime campaign targeting at least ten U.S. telecommunications and technology companies. Operating under hacker aliases like “kiberphant0m” and “cyb3rph4nt0m,” he collaborated with fellow cybercriminals to breach protected networks, steal credentials, and extort companies under the threat of leaking stolen data. Utilizing tools such as “SSH Brute,” Wagenius and his accomplices exploited weaknesses in corporate infrastructure to gain unauthorized access, often coordinating via encrypted Telegram channels.

Authorities confirmed the group sold stolen data on dark web platforms like BreachForums and XSS.is, profiting from resales or using the information for further cyber fraud. Wagenius’s crimes were committed while he was still on active duty in the U.S. Army, highlighting a deeply troubling breach of national trust and military integrity. His criminal indictment includes wire fraud conspiracy, identity theft, and computer-related extortion, as well as two counts of unlawfully transferring confidential phone records.

In one instance, Wagenius demanded \$500,000 in cryptocurrency from a victim, threatening to release over 358GB of sensitive data if they failed to comply. The case has been tied to a broader hacking operation involving cybercriminals Connor Moucka and John Binns, also linked to the notorious Snowflake data breach. Wagenius pleaded guilty to all charges in February 2025, and his sentencing is scheduled for October 6. He faces up to 27 years in prison and potentially more due to overlapping charges. This case highlights how even rudimentary techniques—when used persistently—can compromise high-value systems.

What Undercode Say:

Cybercriminals Are Becoming Younger, Smarter, and More Embedded

The profile of today’s cybercriminal is shifting fast. No longer confined to basement hackers or overseas adversaries, the case of Cameron John Wagenius illustrates how even U.S. military personnel can be lured into the digital underworld. What makes this story even more compelling is the ease with which Wagenius and his group penetrated telecom giants using fairly standard tactics like brute-force tools, SIM-swapping, and Telegram coordination—methods considered “basic” by cybersecurity standards.

Military Access, Civilian Targets

That Wagenius conducted these attacks while serving in the U.S. Army raises serious questions about internal vetting processes and oversight. Military personnel have access to tools, training, and classified knowledge, making their descent into cybercrime even more dangerous. The lines between insider threats and external attacks are becoming increasingly blurred, and this case is a wake-up call to re-evaluate how cybersecurity protocols intersect with national defense.

The Hidden Cost of Simple Breaches

Despite all the buzz around advanced persistent threats and zero-day exploits, the success of Wagenius’s attacks relied on brute-force tools and human error. This reflects a broader trend: attackers often don’t need cutting-edge techniques when basic negligence offers easy entry points. Companies—especially in telecom—must stop underestimating the damage that “low-level” intrusions can cause when amplified at scale.

Telegram: The Cybercriminal Hub of Choice

Telegram has become the tool of preference for threat actors thanks to its encryption and ability to host group chats. Wagenius and his crew used it extensively to transfer stolen credentials and plan their attacks, showing how encrypted communication platforms are central to modern cybercrime ecosystems. This calls for better monitoring, not necessarily of private chats, but of public-facing threat intelligence indicators related to these platforms.

The Dark Web Sales Pipeline

The transition from data theft to financial extortion is no longer linear. Now, attackers monetize data in multiple ways: ransom demands, underground auctions, and by trading data with other hackers. Wagenius’s crew engaged in all of these. The pressure placed on companies to pay quickly—to avoid public embarrassment and regulatory scrutiny—further fuels this black market.

The Shadow of Snowflake

Wagenius’s connection to cybercriminals involved in the Snowflake breach deepens the concern. It suggests a web of interlinked hacker cells, working together or borrowing tools, exploits, and even stolen credentials. These loosely connected cybercrime networks represent a decentralized yet extremely potent threat.

Justice System Is Moving Faster

That Wagenius was indicted, pled guilty, and now awaits sentencing all within a year reflects a faster, more aggressive federal response to cybercrime. The days of protracted court battles are being replaced by plea deals and swift indictments, especially when digital evidence—like Telegram chats and transaction histories—is overwhelming.

Beyond Prison: Long-Term Repercussions

Wagenius faces up to 27 years in prison, but the broader consequences are societal. From eroded trust in the military to growing fear among businesses that even trusted insiders can flip, the psychological impact of this case will outlast any jail sentence.

🔍 Fact Checker Results:

✅ Wagenius was an active-duty U.S. Army soldier during the attacks
✅ He used aliases like “kiberphant0m” and coordinated via Telegram
✅ The extortion demands reached up to \$1 million in cryptocurrency

📊 Prediction:

Expect an uptick in internal threat detection protocols across both government and private sectors 🛡️. Insider threats will be prioritized in security audits 🔐, with special attention given to individuals with elevated access and cybersecurity training. Additionally, data marketplaces like BreachForums may face intensified crackdowns 🚓, pushing cybercriminals to migrate to even more obscure channels.

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub:
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin