/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

The US arrests a US Army soldier on suspicion of being Kiberphant0m, who sold sensitive customer call records stolen from AT&T and Verizon in the Snowflake hack

Federal authorities have arrested and indicted a 20-year-old U.S. Army soldier on suspicion of being Kiberphant0m …

Krebs on Security Brian Krebs

Context & Ripple Effects

The arrest follows reporting that identified Kiberphant0m as a possible third participant in the Snowflake client intrusions, after an earlier indictment alleged that suspects and co-conspirators extorted bitcoin from affected companies. Reporting had tied the alias to the Snowflake case while the earlier indictment described the alleged extortion operation.

The case matters because the alleged resale of carrier call records extends the incident’s impact beyond cloud-account compromise to the handling of highly sensitive customer data at AT&T and Verizon.

First-order effects

  • Federal prosecutors can now pursue the alleged seller of stolen AT&T and Verizon call records, while the named companies face renewed scrutiny over the customer data implicated in the Snowflake incident.
  • The arrest potentially clarifies the alleged role of a third actor in the client-hack ecosystem, alongside the suspects described in the prior indictment.

Second-order effects

  • Carriers and other companies using cloud data platforms are likely to face sharper questions about access controls, credential protection, and how stolen data can be monetized after an intrusion.
  • The case strengthens the enforcement focus on downstream brokers and extortionists, not solely the actors who initially obtain access to customer data.

Third-order effects

  • If prosecutions continue to connect cloud-account intrusions with resale markets for communications data, breach response will increasingly need to address the full data-monetization chain rather than containment alone.
  • The episode points to a broader accountability challenge: cloud-service customers, platform providers, and law enforcement each have distinct roles when compromised data moves from unauthorized access into resale.

The trend: Cloud-data breaches are being treated increasingly as interconnected ecosystems of access theft, extortion, and resale rather than isolated intrusions.

Discussion

  • @vxundergroundre @vxundergroundre on bluesky
    A 20 year old United States soldier worked with Threat Actors and, following the arrest of his associates, threatened to leak telephone logs from Kamala Harris and Donald Trump.  —  This was a very, very, very bad decision.  —  krebsonsecurity.com/2024/12/u-s- ...
  • @bradhoward Brad Howard on bluesky
    Look.  Yes this is bad, but think of the initiative it shows  —  Is he trustworthy?  No, not at all, but have you seen the movie “Blackhat”?  —  Let's turn him into a one man U.S. cyber weapon  —  krebsonsecurity.com/2024/12/u-s- ...
  • @nixonnixoff Allison Nixon on x
    >IQ levels when you are a cybercriminal that tries to extort the president, but you are government property and Krebs is calling your mom :( [image]
  • @imposecost Andrew Thompson on x
    “Anonymously extorting the President and VP as a member of the military is a bad idea, but it's an even worse idea to harass people who specialize in de-anonymizing cybercriminals.” -@nixonnixoff 🥶😮‍💨 U.S. Army Soldier Arrested in AT&T, Verizon Extortions https://krebsonsecurity.…
  • @nixonnixoff Allison Nixon on x
    “Anonymously extorting the President and VP as a member of the military is a bad idea, but it's an even worse idea to harass people who specialize in de-anonymizing cybercriminals,” Nixon told KrebsOnSecurity. Who wants to be next?
  • @vxdb @vxdb on x
    Krebs posted a blog post yesterday about a US Army soldier who worked alongside threat actors to steal customer call records from AT&T and Verizon. I found a screenshot dating back to September 2nd, 2022 and I believe it is of Cameron John Wagenius aka Kiberphant0m. [image]
  • @benlovejoy @benlovejoy on x
    Memo to anyone considering a criminal career: Ask your mom not to tell reporters that you're guilty ...
  • @vxunderground @vxunderground on x
    We've never personally encountered an active United States military personnel doing something like this. It is difficult to assess if they'll go to trial as a civilian or as a soldier (United States military court) or both (which is possible, a rare double whammy)
  • @matthewkeyslive Matthew Keys on x
    Wagenius (Kiberphant0m) was arrested in Waco, which has a U.S. Army Corps of Engineering post. It isn't clear if he was assigned to that post, or just happened to be in the area at the time of his arrest. Prosecutors have requested his extradition to Washington.
  • @kimzetter Kim Zetter on x
    Wagenius allegedly went by the handle Kiberphant0m and was part of the hacking group that stole data from more 100+ Snowflake data storage accounts. I reported back in July that AT&T paid a $370,000 ransom to one of the hackers to delete its stolen data https://www.wired.com/...
  • @vxunderground @vxunderground on x
    A 20 year old United States soldier worked with Threat Actors and, following the arrest of his associates, threatened to leak telephone logs from Kamala Harris and Donald Trump. This was a very, very, very bad decision. https://krebsonsecurity.com/ ...
  • @kimzetter Kim Zetter on x
    20-yr-old US Army soldier stationed in South Korea arrested for massive hack of AT&T customer call records reported earlier this year, including call logs for Trump and VP Kamala Harris.  Cameron John Wagenius worked on radio signals and network comms for Army. @briankrebs has st…
  • r/technology r on reddit
    U.S. Army Soldier Arrested in AT&T, Verizon Extortions
  • r/army r on reddit
    US Army Soldier arrested in AT&T and Verizon extortions