The US arrests a US Army soldier on suspicion of being Kiberphant0m, who sold sensitive customer call records stolen from AT&T and Verizon in the Snowflake hack
Federal authorities have arrested and indicted a 20-year-old U.S. Army soldier on suspicion of being Kiberphant0m …
The case matters because the alleged resale of carrier call records extends the incident’s impact beyond cloud-account compromise to the handling of highly sensitive customer data at AT&T and Verizon.
First-order effects
Federal prosecutors can now pursue the alleged seller of stolen AT&T and Verizon call records, while the named companies face renewed scrutiny over the customer data implicated in the Snowflake incident.
The arrest potentially clarifies the alleged role of a third actor in the client-hack ecosystem, alongside the suspects described in the prior indictment.
Second-order effects
Carriers and other companies using cloud data platforms are likely to face sharper questions about access controls, credential protection, and how stolen data can be monetized after an intrusion.
The case strengthens the enforcement focus on downstream brokers and extortionists, not solely the actors who initially obtain access to customer data.
Third-order effects
If prosecutions continue to connect cloud-account intrusions with resale markets for communications data, breach response will increasingly need to address the full data-monetization chain rather than containment alone.
The episode points to a broader accountability challenge: cloud-service customers, platform providers, and law enforcement each have distinct roles when compromised data moves from unauthorized access into resale.
The trend: Cloud-data breaches are being treated increasingly as interconnected ecosystems of access theft, extortion, and resale rather than isolated intrusions.
A 20 year old United States soldier worked with Threat Actors and, following the arrest of his associates, threatened to leak telephone logs from Kamala Harris and Donald Trump. — This was a very, very, very bad decision. — krebsonsecurity.com/2024/12/u-s- ...
Look. Yes this is bad, but think of the initiative it shows — Is he trustworthy? No, not at all, but have you seen the movie “Blackhat”? — Let's turn him into a one man U.S. cyber weapon — krebsonsecurity.com/2024/12/u-s- ...
“Anonymously extorting the President and VP as a member of the military is a bad idea, but it's an even worse idea to harass people who specialize in de-anonymizing cybercriminals.” -@nixonnixoff 🥶😮💨 U.S. Army Soldier Arrested in AT&T, Verizon Extortions https://krebsonsecurity.…
“Anonymously extorting the President and VP as a member of the military is a bad idea, but it's an even worse idea to harass people who specialize in de-anonymizing cybercriminals,” Nixon told KrebsOnSecurity. Who wants to be next?
Krebs posted a blog post yesterday about a US Army soldier who worked alongside threat actors to steal customer call records from AT&T and Verizon. I found a screenshot dating back to September 2nd, 2022 and I believe it is of Cameron John Wagenius aka Kiberphant0m. [image]
We've never personally encountered an active United States military personnel doing something like this. It is difficult to assess if they'll go to trial as a civilian or as a soldier (United States military court) or both (which is possible, a rare double whammy)
Wagenius (Kiberphant0m) was arrested in Waco, which has a U.S. Army Corps of Engineering post. It isn't clear if he was assigned to that post, or just happened to be in the area at the time of his arrest. Prosecutors have requested his extradition to Washington.
Wagenius allegedly went by the handle Kiberphant0m and was part of the hacking group that stole data from more 100+ Snowflake data storage accounts. I reported back in July that AT&T paid a $370,000 ransom to one of the hackers to delete its stolen data https://www.wired.com/...
A 20 year old United States soldier worked with Threat Actors and, following the arrest of his associates, threatened to leak telephone logs from Kamala Harris and Donald Trump. This was a very, very, very bad decision. https://krebsonsecurity.com/ ...
20-yr-old US Army soldier stationed in South Korea arrested for massive hack of AT&T customer call records reported earlier this year, including call logs for Trump and VP Kamala Harris. Cameron John Wagenius worked on radio signals and network comms for Army. @briankrebs has st…