Security2 publishers3 min readPublished
Army soldier who extorted AT&T using Snowflake logins without MFA gets 70 months
Army soldier Cameron Wagenius got 70 months in prison for extorting AT&T with call records taken from Snowflake accounts that lacked MFA. His group got in with exposed credentials alone, and AT&T's $370,000 ransom did not stop the leaks that followed.
The Watch · Security desk

What happened
- Cameron Wagenius, 22, was sentenced in Seattle to 70 months in federal prison and ordered to pay $294,978 in restitution.
- He and three alleged co-conspirators downloaded data from large Snowflake customers that had exposed credentials and did not enforce multi-factor authentication.
- Prosecutors say Wagenius, Moucka and Binns stole billions of records and took in more than $2.5 million in extortion payments from victims including AT&T, Ticketmaster and Santander.
- After AT&T paid a $370,000 Bitcoin ransom, Wagenius posted what he claimed were AT&T call logs for Donald Trump and Kamala Harris.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Tenants on any hosted data platform that still allows password-only logins face the same method, since this campaign needed exposed credentials and no software flaw.
- cost AT&T's payment bought no lasting silence; the group leaked records afterward and Wagenius admitted re-extorting victims.
- precedent With Moucka and Binns unsentenced, 70 months for a quick, cooperative guilty plea is the first marker of what the remaining Snowflake defendants face.
Both accounts describe the intrusions as logins. Prosecutors, as CyberScoop reports, say Wagenius and Moucka tried to extort more than 10 organizations after stealing credentials and breaking into the cloud platforms those companies used [26]. Officials said Wagenius stole credentials with SSH Brute, a tool he helped develop, while on active duty [5]. The sources do not say how the Snowflake credentials were first exposed [3]. On a Snowflake tenant, the control that decided whether a stolen password was enough was the customer's own MFA setting [3]. Snowflake has since made MFA mandatory on all accounts [4].
AT&T confirmed in July that attackers entered its Snowflake environment in April and took six months of call and text records for "nearly all" of its customers [6]. Krebs puts the count at more than 100 million [7]. Conor Riley Moucka, a co-defendant, pleaded guilty in August to a central role in compromising more than 165 Snowflake customer environments [8].
Along with the claimed Trump and Harris call logs, Kiberphant0m posted schematics he said were stolen from the NSA [10]. Allison Nixon, chief research officer at Unit 221B, told CyberScoop the Trump records came out during failed attempts to extort $500,000 from AT&T [12]. Wagenius admitted re-extorting victims and threatening to disclose national security secrets [11].
The insider in this case was inside the Army. The reporting does not place him inside AT&T, Snowflake or any other victim; he reached them with stolen credentials [14][26]. For teams on cloud data platforms, these filings support a lesson about credentials and MFA enforcement. Paul Russell, a supervisory special agent with the Defense Criminal Investigative Service, said his agency joined the FBI, Army CID and Secret Service on the case after learning a soldier with a secret clearance was allegedly involved [14]. "We don't often get leads where there's an active duty soldier with a secret clearance who's creating hacking tools and trafficking in data," Russell said, adding that "it was an insider threat, and we weren't sure what we were dealing with" [13]. Before his December 2024 arrest, Wagenius tried to sell stolen data to a foreign intelligence service and looked into defecting to Russia, CyberScoop reports [15].
Some of the people around him have earlier cases. Prosecutors said Kenneth Schuchman, who pleaded guilty in 2019 to running the Satori IoT botnet, helped Wagenius extort victims [19]. John Erin Binns, an American living in Turkey, is also wanted over the 2021 T-Mobile breach that exposed personal data of at least 76 million customers [18].
Prosecutors' Sept. 19 sentencing memo says that around September 2025, while jailed awaiting sentencing, Wagenius used another inmate's email to ask that a commercial AI tool be prompted for "[w]hat CVE's are there for Windows 10 Enterprise privilege escalation and bypasses" [16]. "His hacking schemes were not only aimed at getting rich, he was also motivated by a desire to achieve status within criminal hacking communities," Charles Neil Floyd, first assistant attorney in the Western District of Washington, said in a statement [17].
Krebs has Wagenius stationed in South Korea when he took up the Kiberphant0m name [20]. CyberScoop has him on active duty in Texas, and says that after agents seized his devices in December 2024 he bought a new laptop against his commanding officer's order and used it in the Fort Cavazos barracks behind a VPN [21]. Krebs dates its own warning about him to late November 2025, with the arrest less than a month later [22]. That conflicts with the December 2024 seizure and the September 2025 prison records [21][16]. Seventy months is five years and ten months [1]. Krebs describes the term as "nearly seven years" [23].
What to watch
- Moucka's sentencing, after his guilty plea to a central role in compromising more than 165 Snowflake customer environments.
- Any move to bring Binns, who lives in Turkey and is not in U.S. custody, before a U.S. court on the Snowflake and 2021 T-Mobile cases.