P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

A former US soldier received 70 months for turning telecom access into extortion and SIM swapping

The Justice Department says Cameron Wagenius and co-conspirators targeted at least ten organisations, attempted at least one million dollars in extortion and used stolen records for further fraud.

By Parminder Kumar Sharma · · 5 min read

Editorial illustration of telecom network evidence, call graphs and storage media arranged on a prosecutor's case table.

The sentence closes one defendant's case, not the security path it exposed

A federal judge sentenced Cameron John Wagenius, 22, to 70 months in prison and ordered him to pay $294,978 in restitution on 25 September 2026. Wagenius was an active-duty US Army soldier during much of the conduct described by prosecutors.

The US Department of Justice says Wagenius and co-conspirators obtained credentials for protected networks, accessed telecommunications-company databases, stole confidential records, extorted victim organisations and sold some stolen data. They attempted to extort at least one million dollars in total and used stolen material to support other fraud, including SIM swapping.

A criminal sentence answers who was held responsible and what penalty was imposed. It does not answer whether every stolen credential was revoked, every exposed customer was protected from number takeover or every access weakness that supported the campaign was removed.

The conduct crossed five systems that are often investigated separately

The operational chain described by prosecutors

StageConduct in the court recordDefensive evidence
Credential acquisitionCredentials obtained using a tool called SSH Brute and other meansAuthentication failures, source patterns, reused credentials and successful anomalies
Network accessVictim organisations' protected networks were accessedIdentity, VPN, endpoint and administrative logs
Data theftTelecom records and other confidential data were takenDatabase queries, bulk access, exports and unusual account use
Extortion and saleThreats and offers appeared on Telegram and criminal forumsVictim reports, preserved messages and marketplace evidence
Secondary fraudStolen data supported SIM swappingNumber-port, account-recovery and subscriber-identity changes

The table matters because no single control covers all five stages. Rate limiting can reduce brute-force attempts but does not identify a legitimate credential used from an unusual location. A database alert can identify bulk records but may miss selective searches for high-value subscribers. A carrier can stop a SIM swap after the original corporate victim believes its incident is contained.

The campaign therefore belongs in identity, data-access monitoring, fraud and customer-protection workflows at the same time.

Call-detail records are not message content, but they can still expose a person

The Justice Department says Wagenius published stolen confidential non-content call-detail records belonging to a government official and relatives of another former official. The distinction is precise: non-content records are not the words spoken or written in a communication. They can still reveal numbers, timing, routing and relationships.

That metadata can support targeting, social engineering and account recovery. Combined with subscriber data, it can help an attacker impersonate a customer or identify the people around a target. This is why a database query that returns no message body can still be a high-impact privacy event.

The posts threatened further disclosure unless a ransom was paid. Prosecutors say one post suggested retaliation for the arrest of another cybercriminal. The same data therefore served several purposes: status inside criminal communities, pressure on victims and material for later fraud.

Military employment increased the breach of trust, not necessarily the technical access

The sentencing statements emphasise that Wagenius acted while serving in the Army and sought to traffic information to a foreign intelligence service. That context aggravated the public-interest harm and the breach of trust.

The published record does not say his Army access supplied the telecom credentials or provided the victim-company footholds. Defenders should avoid converting employment into an unsupported technical attack path. The established access method includes credentials obtained with SSH Brute and other means, followed by collaboration through Telegram.

The accurate insider lesson is narrower. A person can hold one trusted role while conducting unrelated criminal activity through other identities and infrastructure. Employment screening and acceptable-use policies do not replace authentication telemetry at external organisations.

Telecom data theft continues after the database session ends

When subscriber or call-detail data is stolen, the response cannot stop at rebuilding the compromised server. The copied data remains useful for extortion, impersonation and number takeover. Affected organisations need a fraud-control phase that outlasts the intrusion phase.

For carriers, that means linking cyber incident indicators to high-risk subscriber operations. A customer record touched by a compromised account may need stronger verification for SIM replacement, number porting, PIN reset and account recovery. For organisations whose staff records were exposed, the follow-up includes warning high-risk individuals and watching for social engineering that uses accurate personal context.

Take this with you

Controls mapped to the full chain

  • Detect credential stuffing and brute-force patterns without relying only on account lockouts
  • Alert on successful authentication after concentrated failures or from an unusual source
  • Monitor high-volume and high-sensitivity telecom database queries by user and purpose
  • Require step-up verification for bulk export and privileged subscriber searches
  • Preserve Telegram, forum and extortion communications when they are reported by victims
  • Flag exposed subscriber records for stronger SIM-swap, port-out and account-recovery checks
  • Notify people whose metadata creates a continuing impersonation or targeting risk
  • Keep fraud monitoring active after the original network compromise is contained

The public case spans conduct, arrest, pleas and sentencing

Dates stated in the Justice Department's sentencing release

Date or periodEvent
April 2023 to 18 December 2024Conspiracy conduct described by prosecutors
November 2024Public posts disclosed confidential records and threatened more disclosure
5 March 2025Guilty plea to two counts involving unlawful transfer of confidential phone records
15 July 2025Guilty plea to conspiracy, computer extortion and aggravated identity theft
25 September 2026Sentence of 70 months and $294,978 restitution

Key facts

Sources

  1. PrimaryFormer U.S. Soldier Sentenced for Hacking and Extortion SchemeUS Department of Justiceaccessed 2026-09-28
  2. PrimaryFormer U.S. soldier pleads guilty in hacking and extortion schemeUS Department of Justiceaccessed 2026-09-28

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.