The Snowflake extortion campaign targeting major telecommunications companies has resulted in a 70-month federal prison sentence for a US Army soldier. The case involved stolen call and text metadata associated with more than 100 million AT&T customers.
Cameron John Wagenius, 22, was sentenced in Seattle on 25 September 2026. He was also ordered to pay $294,978 in restitution to victims after pleading guilty to charges brought through two federal indictments.
Snowflake extortion leads to 70-month sentence
Wagenius was stationed at a US Army base in South Korea when he operated under the online name Kiberphant0m. According to the report, he worked with three alleged co-conspirators to obtain information belonging to several large customers of Snowflake, a widely used cloud data platform.
The group did not need to exploit a newly disclosed vulnerability in the Snowflake service. Instead, it used exposed account credentials belonging to customers that had not enforced multi-factor authentication. Those conditions allowed the attackers to enter affected cloud environments and download stored information.
The report does not identify a particular Snowflake software version because the central weakness concerned customer account access rather than a version-specific product flaw. Snowflake has since mandated multi-factor authentication across all accounts, changing the control that was absent from the compromised environments.
In October 2024, Kiberphant0m claimed on cybercrime forums to possess call and text metadata belonging to tens of millions of AT&T customers. The wider theft ultimately involved records associated with more than 100 million of the company’s customers.
What the stolen telecoms records contained
The stolen information was metadata rather than the contents of calls or text messages. However, metadata can still reveal sensitive relationships, communication patterns and activity over time.
The exposed records reportedly included:
- Source and destination telephone numbers.
- Dates and timestamps for communications.
- The duration of calls.
- Records showing which numbers communicated with each other.
Kiberphant0m also claimed to have compromised more than a dozen telecommunications companies around the world. The claimed victims included Verizon’s Push-to-Talk business, although the supplied report does not specify the number of Verizon records involved.
How the Snowflake extortion campaign worked
The Snowflake extortion operation combined credential-based cloud access, large-scale data theft and public pressure. Once the attackers entered customer accounts, they downloaded valuable datasets and threatened to release them unless the affected companies paid.
The reported attack path can be summarised as follows:
- Credentials associated with Snowflake customer accounts became exposed.
- The affected accounts did not require multi-factor authentication.
- The attackers used the credentials to access cloud data environments.
- Large datasets were downloaded from telecommunications customers.
- Victims were contacted and threatened with publication of the information.
- Claims and samples were posted publicly to increase pressure.
This distinction is important for understanding the incident. The Snowflake extortion campaign was enabled by valid credentials and missing authentication safeguards, not by a reported technical exploit against a named Snowflake version.
The group publicly extorted victim companies in exchange for promises that the stolen data would not be released. AT&T had already paid the extortion group a $370,000 Bitcoin ransom when the pressure escalated further following the arrest of an alleged participant.
Wagenius admitted to re-extorting victims, meaning organisations could face additional demands even after responding to an initial attempt. He also threatened to disclose material he characterised as national security secrets.
Following the arrest of alleged co-conspirator Conor Riley Moucka, Kiberphant0m posted what he claimed were AT&T call logs associated with then President-elect Donald Trump and then Vice President Kamala Harris. He also posted schematics allegedly stolen from the US National Security Agency. The report describes these materials as claims by the attacker rather than independently confirmed records.
Timeline and people connected to the campaign
The theft of the AT&T telecoms data occurred in 2024. By October 2024, Kiberphant0m was openly discussing the stolen metadata on cybercrime forums and claiming access to more than a dozen telecommunications companies.
Wagenius was subsequently identified as a possible US soldier stationed in South Korea. He was arrested in 2024, charged under two separate federal indictments and soon pleaded guilty to all counts in both cases.
Federal prosecutors said Kenneth Schuchman, 28, of Vancouver, Washington, assisted Wagenius in attempts to extort victim companies. Schuchman had previously pleaded guilty in 2019 to operating the Satori botnet, a network of compromised Internet of Things devices used to conduct large-scale distributed denial-of-service attacks.
Two other alleged co-conspirators continue to face proceedings connected to the Snowflake data thefts. Their reported circumstances are:
- Conor Riley Moucka, also known as Judische, is from Kitchener, Ontario. He was arrested in 2024 and pleaded guilty in August 2026.
- John Erin Binns is an American living in Turkey. He is also wanted in connection with the 2021 T-Mobile breach that exposed personal information relating to at least 76 million customers.
The sentencing on 25 September 2026 resolves Wagenius’s role at the federal trial court level, but it does not close every part of the wider Snowflake extortion investigation. Proceedings involving the other alleged participants remain relevant to the campaign’s current legal status.
Why the Snowflake extortion case matters
The scale of the AT&T dataset demonstrates the potential consequences of a single cloud identity being compromised. Even where message contents are not exposed, call and text metadata affecting more than 100 million customers can create substantial privacy, investigative and reputational risks.
The case also shows that paying an extortion demand may not end the threat. The admitted re-extortion and later publication claims indicate that copied data can continue to be used as leverage after an initial payment.
Actions for organisations using Snowflake
Organisations should verify that Snowflake multi-factor authentication requirements cover every human and privileged account, including older accounts and administrative identities. They should also examine whether credentials connected to the platform have appeared in exposure reports or unauthorised credential stores.
Reviews should focus specifically on evidence of unexpected logins, unusual data queries and large downloads. Where telecoms or other sensitive metadata is stored, teams should confirm which identities can export it and whether alerts would detect behaviour comparable to this Snowflake extortion campaign.
Originally reported by krebsonsecurity.com.






