Seattle, sentencing day: seventy months in federal prison and $294,978 in restitution for Cameron John Wagenius, 22, United States Army—a communications specialist who worked radio signals and network communications at a base in South Korea and spent his off-hours, by his own guilty plea, as one of the loudest extortionists on the cybercrime forums: Kiberphant0m. The soldier-hacker, the keyboard commando, the phantom menace of BreachForums—who, for all the terror he spread, pulled in a grand total of about $1,500 selling stolen data.

The mechanics were embarrassingly simple. At the end of 2023, malicious hackers realized that major corporations had dumped mountains of sensitive customer data into Snowflake cloud accounts guarded by nothing more than a username and password—no multi-factor authentication, which Snowflake has since mandated on all accounts. Working with three alleged co-conspirators, Kiberphant0m raided those repositories and came out with call and text metadata—source and destination numbers, timestamps, durations—on more than 100 million AT&T customers. He claimed to have breached more than a dozen telecom firms worldwide, offered up call logs stolen from Verizon’s push-to-talk customers (mainly U.S. government agencies and emergency first responders), and opened a BreachForums sales thread for a SIM-swapping service aimed at those same Verizon PTT accounts.

The theater was pure grandiosity. AT&T had quietly paid the extortion group a $370,000 Bitcoin ransom, as Wired reported; Kiberphant0m’s job was selling data from victims who refused to pay. Then, the moment news broke that his partner had been arrested, he went on BreachForums and posted what he claimed were the AT&T call logs of President-elect Donald J. Trump and Vice President Kamala Harris—plus, that same day, a purported “data schema” from the National Security Agency. “This was obtained from the ATNT Snowflake hack which is why ATNT paid an extortion,” he wrote. “Why would ATNT pay Waifu for the data when they wouldn’t even pay an extortion for over 20M+ SSNs?”

“In the event you do not reach out to us @ATNT all presidential government call logs will be leaked... You don’t think we don’t have plans in the event of an arrest? Think again.” — signed with a string of #FREEWAIFU tags

The crew: Connor Riley Moucka of Kitchener, Ontario—a.k.a. “Judische,” a.k.a. “Waifu”—arrested October 30, 2024 on a U.S. warrant, indicted on 20 counts tied to the Snowflake breaches, pleading guilty in August 2026. John Erin Binns, an American living in Turkey, also wanted over the 2021 T-Mobile breach that exposed at least 76 million customers. And Kenneth Schuchman, 28, of Vancouver, Washington, who prosecutors said assisted the extortion and who pleaded guilty back in 2019 to running the Satori botnet, an army of hijacked Internet-of-Things devices used for mass DDoS attacks.

And the unmasking—ah, the unmasking, a trail of breadcrumbs dropped by the phantom himself. On Telegram he was @cyb3rph4nt0m, 4,200-plus messages; taunted as a nobody in a fraud channel called Comgirl, a user named “Buttholio” stepped forward to claim the crown: “Type ‘kiberphant0m’ on google with the quotes... I’ll wait. Go ahead. Over 50 articles. 15+ telecoms breached. I got the IMSI number to every single person that’s ever registered in Verizon, Tmobile, ATNT and Verifone.” In an Escape from Tarkov Discord, Buttholio explained why he played on Asian servers: “i am a u.s. soldier so i bought it in the states but got on rotation.” Under another alias, Reverseshell, he told a Telegram channel in November 2022 that he was a U.S. soldier, posted a waist-down photo of military fatigues and a camouflage backpack, griped after a DDoS attack that “Yall just hit military base contracted wifi,” admitted he came online via South Korea Telecom, and bragged, “I’ve hit US gov servers with default creds... I sold a few big companies for like $2-3k a piece.” He sold a Mirai-based botnet called “Shi-Bot,” peddled login credentials for a major U.S. defense contractor, and frequented a DDoS channel whose site was later seized in an international sweep called Operation PowerOFF.

Allison Nixon, chief research officer at the New York cybersecurity firm Unit 221B, helped run him to ground—one of several researchers who had faced harassment and specific threats of violence from Judische and his associates. “Anonymously extorting the President and VP as a member of the military is a bad idea, but it’s an even worse idea to harass people who specialize in de-anonymizing cybercriminals,” she said. “Between when we, and an anonymous colleague, found his opsec mistake on November 10th to his last Telegram activity on December 6, law enforcement set the speed record for the fastest turnaround time for an American federal cyber case that I have witnessed in my career.” In late November, KrebsOnSecurity reported Kiberphant0m was likely a U.S. soldier stationed in South Korea; Wagenius’ Facebook profile photo vanished within hours. On December 20, federal agents arrested the then-20-year-old near Fort Hood, Texas. Two indictments, guilty pleas on all counts, the case transferred to Seattle. Nixon wanted one message passed along: “I know that young people involved in cybercrime will read these articles... You need to stop doing stupid shit and get a lawyer. Law enforcement wants to put all of you in prison for a long time.”

His mother, Minnesota native Alicia Roen, told KrebsOnSecurity her son had always been good with computers and had joined the Army as soon as he was old enough, following his older brother. “He and his brother when they were like 6 and 7 years old would ask for MREs from other countries,” she recalled. “They both always wanted to be in the Army. I’m not sure where things went wrong... I never was aware he was into hacking. It was definitely a shock to me when we found this stuff out.”

Even behind bars, the itch persisted. A sentencing memo filed September 19 by federal prosecutors notes that Wagenius, who pleaded guilty almost immediately and has been remarkably cooperative, got caught probing the Bureau of Prisons’ computer network from inside. In or around September 2025, per the memo, he used another inmate’s email to have the recipient ask a commercial AI tool “[w]hat CVE’s are there for Windows 10 Enterprise privilege escalation and bypasses,” complete with “a real world working script... without omitted code”; less than a week later, using a different inmate’s account, he sought step-by-step code for CVE-2023-45208, a years-old D-Link command-injection flaw; then came a query about building an antenna in a prison environment from commissary items, plus research on escaping prison. He framed the queries as research for a book—a common “prompt injection” trick, the memo notes. Questioned, he said he was only researching “potential vulnerabilities to provide information to the BOP.” The government told the court it knows of no evidence he ever deployed any of it.

“While Wagenius was not particularly financially successful as a cybercriminal, he both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government.” — federal sentencing memo

Paul Russell, resident agent in charge at the Defense Criminal Investigative Service, said the case spun up the FBI, Army CID and the Secret Service fast. “We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data... It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with.”

The other Pentagon headache

The same week, CNN reported a mess of an entirely different scale at the Defense Manpower Data Center—the self-described “one, central access point” for Pentagon entitlements, benefits and “medical readiness,” holding at least 60 million records as of fiscal 2024. Per a letter the center sent victims, “unauthorized users” got into a vulnerable DMDC server starting last October, and the Pentagon didn’t discover and fix the problem until July—nine months later. Social Security numbers, personal data, and in some cases service members’ “occupational specialty” were exposed; Military Times reported four million Defense Department personnel could be affected. The data wasn’t encrypted. The culprit is unknown, the Pentagon says it “does not have any indications of misuse,” and victims get a year of credit monitoring.

“On its own, having personal data on potentially millions of service members exposed is dangerous as the US wages war on Iran and is in competition with multiple other governments,” Justin Sherman, CEO of Global Cyber Strategies, told CNN. “If a foreign adversary was to get this kind of data trove, it could enable phishing, profiling, foreign intel approaches, and much more”—especially paired with commercial datasets to target personnel by “earnings, debts, marriages, spending habits, browsing activities, and worse.” US Central Command has already told lawmakers it has “received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil US personnel in theater.”