Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Government & Policy » Former US Soldier Sentenced for 70 Months for Hacking and Extortion

Former US Soldier Sentenced for 70 Months for Hacking and Extortion

Last updated:September 28, 2026
Human Written
  • Former Army soldier Cameron John Wagenius got 70 months in prison for a hacking and extortion scheme.

  • Prosecutors said he and his partners hit at least 10 groups and tried to extort more than $1 million.

  • Wagenius also pled guilty to the unlawful transfer of private phone records in a case tied to the same scheme.

Former US Soldier Sentenced to 70 Months for Hacking and Extortion

A former U.S. Army soldier has been sent to prison for more than five years after hacking phone firms and trying to extort them.

Cameron John Wagenius, 22, must also pay $294,978 to his victims. The Justice Department announced his sentence on September 25.

Prosecutors said Wagenius took part in the crimes while he was on active duty. He used the name “kiberphant0m” online and worked with other hackers from April 2023 through December 2024.

The Hacking and Extortion Scheme

Court records say Wagenius and his partners went after at least 10 groups. They got login details for private computer networks and used them to steal data.

Wagenius helped build a hacking tool called SSH Brute, prosecutors said. The group also used Telegram to share stolen login data and plan attacks.

After they stole data, the hackers tried to make victims pay. They warned that they would post the stolen data on crime sites such as BreachForums and XSS.is.

The group also put some stolen data up for sale. Prosecutors said they sold at least some of it. They also used the data in other crimes, including SIM-swapping.

The group tried to extort at least $1 million in all, the Justice Department said. That sum covers the ransom demands. It does not mean victims paid that amount.

Stolen Phone Records

The case drew more notice after Wagenius posted stolen phone records online in November 2024. The Justice Department said two posts showed private call records tied to a U.S. government official and family members of a former official.

Call records can show who called whom and when. They do not show what the people said. Wagenius also said he would post more records unless he got a ransom. One post said he wanted to strike back after the arrest of another hacker.

A court filing from February 2025 gives more detail. It says Wagenius demanded $500,000 from a major phone firm and warned that he would release more data if the firm did not respond.

The same filing says the threats came while Wagenius was on active duty at Fort Cavazos in Texas. Wagenius was arrested in Texas on December 20, 2024.

Guilty Pleas and Sentence

Wagenius pled guilty on March 5, 2025, to two counts of unlawfully transferring private phone record data. Months later, in July of the same year, he also pled guilty to conspiracy to commit wire fraud, as well as extortion involving computer fraud and aggravated identity theft.

Both cases were presided over by Judge Lauren King in the Western District of Washington. She slapped Wagenius with a 70-month prison sentence on September 25, 2026, and also ordered him to pay $294,978 in restitution.

The Justice Department said King found that greed and a wish for fame drove Wagenius’ crimes. According to the prosecutors, he spent more than a year stealing data and then using it to threaten his victims.

Wagenius’ case also has a link to the case against Connor Riley Moucka and John Erin Binns.

Moucka and Binns face charges in a separate case over attacks on more than 165 groups that used Snowflake’s cloud service. Canadian hacker pleads guilty in Snowflake data theft campaign affecting millions covers Moucka’s guilty plea and the wider data-theft campaign. Prosecutors said the attacks led to large data thefts and ransom demands.

Moucka pled guilty in August 2026. The Justice Department said he and his partners broke into more than 165 groups and stole billions of sensitive records.

The stolen data affected at least 100 million people, according to the Justice Department. It included call and text data, bank data, payroll records, passport data and Social Security numbers.

AT&T was among the firms hit in the wider Snowflake attacks. In July 2024, AT&T said hackers stole call and text records tied to nearly all of its cell users over a six-month period in 2022.

Wagenius’ case and the Snowflake case are not the same case. Still, a February 2025 court filing in the Wagenius case lists the Moucka and Binns case as a related case.

What the Case Shows

The Wagenius case shows how stolen login data can fuel many crimes. The group used stolen access to take data, seek ransoms, sell records and aid other fraud.

Prosecutors also said Wagenius tried to sell stolen data to a foreign military spy service. The Justice Department did not name the country in its September sentencing release.

The FBI and Defense Criminal Investigative Service led the probe. The Army’s Criminal Investigation Division and other Justice Department teams also helped.

The 70-month term now closes a major part of the case against Wagenius. The cases against Moucka and Binns remain separate and will follow their own court paths.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.