DKDKCISSPSearch
Threat ResearchDEVELOPING

Ex-US soldier gets 70 months for role in AT&T, Snowflake data thefts - Help Net Security

A former U.S. Army soldier who was part of a group that stole data from telecom companies, including AT&T , has been sentenced to 70 months in prison.

DKCISSP News DeskHelp Net Security28 Sept 2026, 2:15 pm
Ex-US soldier gets 70 months for role in AT&T, Snowflake data thefts - Help Net Security
Image courtesy of Help Net Security. Original report
DKCISSP REPORT

Army soldier who was part of a group that stole data from telecom companies, including AT&T , has been sentenced to 70 months in prison.

Cameron John Wagenius, 22, was part of the group that hacked Snowflake customer accounts in 2024.

Moucka was arrested on October 30, 2024, in Canada at the request of the United States and pleaded guilty to his role in the Snowflake hacking campaign in August 2026.

In November 2024, Wagenius published two online posts that disclosed stolen call detail records belonging to a government official and to family members of another former official.

Snowflake is a US-based cloud data storage and analytics company with more than 13,000 customers worldwide.

and foreign telecommunications companies, compromised the sensitive data of countless people, and even sought to traffic stolen information to a foreign intelligence service.” According to court documents, between April 2023 and December 18, 2024, Wagenius used online accounts associated with the nickname “kiberphant0m” and conspired with others to defraud at least 10 victim organizations.

They took data from more than 165 organizations that used the US cloud storage company, then threatened to leak it unless the victims paid.

In total, Wagenius and his co-conspirators attempted to extort at least $1 million from victim data owners." In addition to the 70-month prison sentence, Wagenius was ordered to pay $294,978 in restitution for hacking into telecom companies' databases, accessing sensitive customer records, and extorting the companies under threat of releasing stolen data unless they paid ransoms.

After these incidents led to massive data breaches, Snowflake announced it would enforce multi-factor authentication (MFA) and require customers to choose passwords at least 14 characters long.

They used Telegram group chats to share stolen credentials and discuss how to get into victim companies’ networks.

What happened

Army soldier who was part of a group that stole data from telecom companies, including AT&T , has been sentenced to 70 months in prison.

Cameron John Wagenius, 22, was part of the group that hacked Snowflake customer accounts in 2024.

What changed

Moucka was arrested on October 30, 2024, in Canada at the request of the United States and pleaded guilty to his role in the Snowflake hacking campaign in August 2026.

In November 2024, Wagenius published two online posts that disclosed stolen call detail records belonging to a government official and to family members of another former official.

Who is affected

Snowflake is a US-based cloud data storage and analytics company with more than 13,000 customers worldwide.

and foreign telecommunications companies, compromised the sensitive data of countless people, and even sought to traffic stolen information to a foreign intelligence service.” According to court documents, between April 2023 and December 18, 2024, Wagenius used online accounts associated with the nickname “kiberphant0m” and conspired with others to defraud at least 10 victim organizations.

Why it matters

They took data from more than 165 organizations that used the US cloud storage company, then threatened to leak it unless the victims paid.

In total, Wagenius and his co-conspirators attempted to extort at least $1 million from victim data owners." In addition to the 70-month prison sentence, Wagenius was ordered to pay $294,978 in restitution for hacking into telecom companies' databases, accessing sensitive customer records, and extorting the companies under threat of releasing stolen data unless they paid ransoms.

Technical details

After these incidents led to massive data breaches, Snowflake announced it would enforce multi-factor authentication (MFA) and require customers to choose passwords at least 14 characters long.

They used Telegram group chats to share stolen credentials and discuss how to get into victim companies’ networks.

They also used Telegram to transfer stolen credentials and plan their attacks.

Response

He conspired to hack into telecommunications companies’ databases, access sensitive records, and extort the companies by threatening to release the stolen data unless they paid a ransom.

The text of one post suggested he was acting in retaliation for the then-recent arrest of another cybercriminal.

Attribution

Help Net Security: Army soldier who was part of a group that stole data from telecom companies, including AT&T , has been sentenced to 70 months in prison.

BleepingComputer: Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S.

MORE IN THREAT RESEARCH

More cybersecurity reporting

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility ToolsThe Hacker News · 2 Oct 2026, 4:45 pmMicrosoft is rolling out Linux container support to WSLBleepingComputer · 30 Sept 2026, 6:10 am57% of security execs report challenges with onboarding entry-level staffSC Media · 30 Sept 2026, 12:49 amDutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters InvestigationThe Hacker News · 29 Sept 2026, 6:56 pm