Counterintelligence — 2026-09-27

US Army Soldier With Secret Clearance Sentenced to 70 Months for Telecom Hacking and Leaking NSA Schematics

BLUFWagenius's attempted outreach to a suspected foreign intelligence service while holding an active secret clearance transforms this from a criminal hacking case into an unresolved counterintelligence failure for Army insider-threat programs.

A federal court in the Western District of Washington sentenced Cameron John Wagenius, 22, a former Army soldier most recently stationed in Texas, to 70 months in prison and $294,978 in restitution for a hacking and extortion campaign carried out under the alias "kiberphant0m" while he held active-duty status and a secret clearance 12. Between April 2023 and December 2024, Wagenius and co-conspirators obtained credentials for at least 10 organizations using a self-developed tool called SSH Brute, stealing AT&T's call and text metadata for over 100 million customers via compromised Snowflake accounts, and attempted to extort more than $1 million total, though DOJ's sentencing memo says he netted only about $1,500 12. In November 2024, per DOJ, he posted stolen call records of a government official and a former official's family members and threatened further releases unless paid 1. Nextgov/FCW reports prosecutors also alleged he tried selling data to an address he believed belonged to a foreign intelligence service and searched for information on defecting to Russia 3. Krebs on Security reports Wagenius pleaded guilty in July 2025 and March 2025 to related charges, and that a September 19 sentencing memo alleges he used other inmates' email accounts from prison to solicit AI-generated information on Windows and D-Link vulnerabilities and on building an antenna, actions the government says show no evidence of successful exploitation 2.

Analysis
This sentencing closes the most prominent case of an active-duty, secret-clearance soldier running a criminal hacking and extortion operation from inside the military, and prosecutors' disclosure that he tried selling stolen data to a contact he believed represented a foreign intelligence service adds a counterintelligence dimension to what DoD and Army CID had otherwise treated as financially motivated crime. His continued efforts from prison to solicit AI-generated exploit code and antenna-building instructions show the underlying behavior outlasted his arrest and guilty pleas, though the government found no evidence he weaponized what he sought. The foreign-contact and Russia-defection searches may instead reflect the same status-seeking bravado that drove his public extortion posts rather than genuine espionage intent, consistent with officials' framing of him as motivated by forum standing as much as profit. Sourcing rests on a DOJ primary release corroborated by Krebs on Security's independent reporting, with two co-conspirators still unresolved: Moucka has since pleaded guilty, Binns remains at large in Turkey, leaving the Snowflake-linked extortion campaign's full accounting incomplete.
4 sources
  1. Former U.S. Soldier Sentenced for Hacking and Extortion Scheme That Exposed Sensitive Data of U.S. Government Official - U.S. Department of Justice
  2. U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions - Krebs on Security
  3. Former Army soldier sentenced to nearly 6 years for telecom hacking, extortion - Nextgov/FCW
  4. Former Army soldier sentenced for telecom hacking and extortion - BNO News

View in full brief →

UNCLASSIFIED // OPEN SOURCE