Circuit Wire — a daily news update from the Circuit.

Cameron John Wagenius, a 22-year-old former US Army soldier, was sentenced on Friday, September 25, to 70 months in prison for hacking into telecommunications companies and trying to extort them with stolen data. The Justice Department said he was also ordered to pay $294,978 in restitution.

Prosecutors said that between April 2023 and December 18, 2024, Wagenius and his co-conspirators defrauded at least 10 victim organizations by stealing login credentials for their networks. Much of this happened while he was on active duty. He operated online as "kiberphant0m" and helped build a credential-stealing tool called SSH Brute. The group swapped stolen logins in Telegram group chats.

Once inside, the conspirators threatened to dump victims' data on criminal forums such as BreachForums and XSS.is unless they paid. They sold some of the stolen data outright and used some of it for other frauds, including SIM swapping. Officials said Wagenius was directly involved in extortion attempts totaling more than $1 million.

In November 2024, he posted stolen call detail records belonging to a government official and to family members of another former official, and threatened to release more. CyberScoop reported that those records included calls of President Donald Trump, used in failed attempts to extort $500,000 from AT&T, according to researcher Allison Nixon of Unit 221B. The Justice Department said Wagenius also sought to sell stolen information to a foreign intelligence service.

When federal agents seized his devices in December 2024, they found he had access to thousands of stolen identification documents and large amounts of cryptocurrency. Days later, officials said, he bought a new laptop against his commanding officer's order and used it daily in the barracks at Fort Cavazos, Texas, with VPN software to hide his identity and location. CyberScoop reported that he had also searched online for information about defecting to Russia.

Wagenius pleaded guilty in July 2025 to conspiracy to commit wire fraud, extortion in relation to computer fraud, and aggravated identity theft. In a separate case in March 2025, he pleaded guilty to two counts of unlawfully transferring confidential phone records.

His case ties back to the 2024 Snowflake breaches, one of the largest data theft campaigns of that year. Co-conspirator Connor Moucka, a Canadian extradited to the US in March 2025, pleaded guilty in August to his role in compromising more than 165 Snowflake customer environments. Prosecutors say Wagenius, Moucka and alleged co-conspirator John Erin Binns received more than $2.5 million in extortion payments combined. Victims included AT&T, Ticketmaster, Advance Auto Parts and Santander. Binns is not in US custody.

Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.

Spotted something we should cover? Send tips and feedback via circuit-magazine.com.