Post

Former US Soldier Sentenced for Hacking and Extortion Scheme

Former US Soldier Sentenced for Hacking and Extortion Scheme

Former US Soldier Sentenced for Hacking and Extortion Scheme

Cameron John Wagenius, 22, a former Army soldier, was sentenced today to 70 months in prison and ordered to pay $294,978 in restitution for conspiring to hack into telecommunications companies’ databases, access sensitive records, and extort the companies by threatening to release the stolen data unless ransoms were paid. 🚨

In November 2024, Wagenius made two online posts that disclosed stolen confidential non-content call detail records belonging to a government official and family members of another former official, threatening to release additional confidential records unless paid a ransom. The text of one of these online posts suggested that Wagenius was motivated by a desire to retaliate for the then-recent arrest of another cybercriminal.

According to Assistant Attorney General A. Tysen Duva, Wagenius “targeted U.S. and foreign telecommunications companies, compromised the sensitive data of countless people, and even sought to traffic stolen information to a foreign intelligence service.” First Assistant Attorney Charles Neil Floyd noted Wagenius engaged in “a long spree of criminal conduct attempting to blackmail hacking victims for more than $1 million,” adding, “His hacking schemes were not only aimed at getting rich; he was also motivated by a desire to achieve status within criminal hacking communities.”

According to court documents, between April 2023 and December 18, 2024, Wagenius used online accounts associated with the nickname “kiberphant0m” and conspired with others to defraud victim organizations by obtaining login credentials for their protected computer networks. Wagenius and his conspirators obtained these credentials using a hacking tool that Wagenius helped develop called SSH Brute. They used Telegram group chats to transfer stolen credentials and discuss gaining unauthorized access to victim companies’ networks. This activity happened while Wagenius was on active duty with the U.S. Army.

After data was stolen, Wagenius and his conspirators extorted the victim organizations both privately and in public forums. The extortion attempts included threats to post the stolen data on cybercrime forums such as BreachForums and XSS.is. Conspirators also offered to sell stolen data for thousands of dollars via posts on these forums. They successfully sold at least some of this stolen data and also used stolen data to perpetuate other frauds, including SIM-swapping. In total, Wagenius and his co-conspirators attempted to extort at least $1 million from victim data owners. Wagenius pleaded guilty to conspiracy to commit wire fraud, extortion in relation to computer fraud, and aggravated identity theft, as well as two counts of unlawful transfer of confidential phone records information. The FBI and DCIS investigated the case.

Read full article

This post is licensed under CC BY 4.0 by the author.