US Army soldier pleads guilty to hacking telcos, extortion, wire fraud, identity theft
- A former soldier has plead guilty to a number of charges
- These include fraud, identity theft, and conspiracy to hack organisations
- The soldier and his co-conspirators exfiltrated and sold data from companies
The Department of Justice has announced that an ex-soldier has plead guilty to ‘conspiring to hack into telecommunications companies’ databases, access sensitive records, and extort the telecommunications companies by threatening to release the stolen data unless ransoms were paid.’
The 21 year old soldier, named as Cameron John Wagenius, used online accounts under the pseudonym “kiberphan0m”. Wagenius admitted to conspiring with others to defraud ‘at least 10’ organizations by stealing login credentials obtained through a hacking tool called SSH Brute.
Once data was exfiltrated, the group used the access to extort victims, threatening to post stolen data on cybercrime forums, and offering to sell the data to other cybercriminals through the forums. These allegedly occurred whilst Wagenius was actively serving in the US military.
Extorted data
Some of this data was successfully sold, and reportedly used to commit other fraudulent campaigns, including SIM-swapping. The group attempted to extract at least $1 million from their victims.
The crimes Wagenius plead guilty were; extortion in relation to computer fraud, conspiracy to commit wire fraud, and aggravated identity theft. Wagenius has previously plead guilty separately to two counts of “unlawful transfer of confidential phone records information in connection with this conspiracy.”
Wagenius’ activity has been linked to the Snowflake hack in which hundreds of customers were affected and significant data was stolen. This attack was allegedly financially motivated, and originated from a group extorting money in exchange for their stolen data.
Snowflake confirmed that the breach was the result of a successful credential stuffing attack – in which a threat actor had entered countless login combinations (usually purchased off the black market) until one eventually works. Credential stuffing attacks are potent and effective, and have led to some of the most notorious breaches in the last few years.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
You might also like
A former soldier has plead guilty to a number of charges These include fraud, identity theft, and conspiracy to hack organisations The soldier and his co-conspirators exfiltrated and sold data from companies The Department of Justice has announced that an ex-soldier has plead guilty to ‘conspiring to hack into telecommunications…
Recent Posts
- Best Buy slashes up to $400 off Apple tech in a limited-time sale — get AirPods, MacBooks, iPads and Apple Watches from $99.99
- The Instagram Plus subscription has officially launched
- Cyberdecks used to look like little laptops, but now they’re getting more personal
- Canada Prime Minister Mark Carney announces questionable national AI strategy
- Kevin O’Leary agrees to downsize massive Utah data center
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023