A former US soldier received 70 months for turning telecom access into extortion and SIM swapping
The Justice Department says Cameron Wagenius and co-conspirators targeted at least ten organisations, attempted at least one million dollars in extortion and used stolen records for further fraud.
By Parminder Kumar Sharma · · 5 min read

The sentence closes one defendant's case, not the security path it exposed
A federal judge sentenced Cameron John Wagenius, 22, to 70 months in prison and ordered him to pay $294,978 in restitution on 25 September 2026. Wagenius was an active-duty US Army soldier during much of the conduct described by prosecutors.
The US Department of Justice says Wagenius and co-conspirators obtained credentials for protected networks, accessed telecommunications-company databases, stole confidential records, extorted victim organisations and sold some stolen data. They attempted to extort at least one million dollars in total and used stolen material to support other fraud, including SIM swapping.
A criminal sentence answers who was held responsible and what penalty was imposed. It does not answer whether every stolen credential was revoked, every exposed customer was protected from number takeover or every access weakness that supported the campaign was removed.
The conduct crossed five systems that are often investigated separately
The operational chain described by prosecutors
| Stage | Conduct in the court record | Defensive evidence |
|---|---|---|
| Credential acquisition | Credentials obtained using a tool called SSH Brute and other means | Authentication failures, source patterns, reused credentials and successful anomalies |
| Network access | Victim organisations' protected networks were accessed | Identity, VPN, endpoint and administrative logs |
| Data theft | Telecom records and other confidential data were taken | Database queries, bulk access, exports and unusual account use |
| Extortion and sale | Threats and offers appeared on Telegram and criminal forums | Victim reports, preserved messages and marketplace evidence |
| Secondary fraud | Stolen data supported SIM swapping | Number-port, account-recovery and subscriber-identity changes |
The table matters because no single control covers all five stages. Rate limiting can reduce brute-force attempts but does not identify a legitimate credential used from an unusual location. A database alert can identify bulk records but may miss selective searches for high-value subscribers. A carrier can stop a SIM swap after the original corporate victim believes its incident is contained.
The campaign therefore belongs in identity, data-access monitoring, fraud and customer-protection workflows at the same time.
Call-detail records are not message content, but they can still expose a person
The Justice Department says Wagenius published stolen confidential non-content call-detail records belonging to a government official and relatives of another former official. The distinction is precise: non-content records are not the words spoken or written in a communication. They can still reveal numbers, timing, routing and relationships.
That metadata can support targeting, social engineering and account recovery. Combined with subscriber data, it can help an attacker impersonate a customer or identify the people around a target. This is why a database query that returns no message body can still be a high-impact privacy event.
The posts threatened further disclosure unless a ransom was paid. Prosecutors say one post suggested retaliation for the arrest of another cybercriminal. The same data therefore served several purposes: status inside criminal communities, pressure on victims and material for later fraud.
Military employment increased the breach of trust, not necessarily the technical access
The sentencing statements emphasise that Wagenius acted while serving in the Army and sought to traffic information to a foreign intelligence service. That context aggravated the public-interest harm and the breach of trust.
The published record does not say his Army access supplied the telecom credentials or provided the victim-company footholds. Defenders should avoid converting employment into an unsupported technical attack path. The established access method includes credentials obtained with SSH Brute and other means, followed by collaboration through Telegram.
The accurate insider lesson is narrower. A person can hold one trusted role while conducting unrelated criminal activity through other identities and infrastructure. Employment screening and acceptable-use policies do not replace authentication telemetry at external organisations.
Telecom data theft continues after the database session ends
When subscriber or call-detail data is stolen, the response cannot stop at rebuilding the compromised server. The copied data remains useful for extortion, impersonation and number takeover. Affected organisations need a fraud-control phase that outlasts the intrusion phase.
For carriers, that means linking cyber incident indicators to high-risk subscriber operations. A customer record touched by a compromised account may need stronger verification for SIM replacement, number porting, PIN reset and account recovery. For organisations whose staff records were exposed, the follow-up includes warning high-risk individuals and watching for social engineering that uses accurate personal context.
Take this with you
Controls mapped to the full chain
- Detect credential stuffing and brute-force patterns without relying only on account lockouts
- Alert on successful authentication after concentrated failures or from an unusual source
- Monitor high-volume and high-sensitivity telecom database queries by user and purpose
- Require step-up verification for bulk export and privileged subscriber searches
- Preserve Telegram, forum and extortion communications when they are reported by victims
- Flag exposed subscriber records for stronger SIM-swap, port-out and account-recovery checks
- Notify people whose metadata creates a continuing impersonation or targeting risk
- Keep fraud monitoring active after the original network compromise is contained
The public case spans conduct, arrest, pleas and sentencing
Dates stated in the Justice Department's sentencing release
| Date or period | Event |
|---|---|
| April 2023 to 18 December 2024 | Conspiracy conduct described by prosecutors |
| November 2024 | Public posts disclosed confidential records and threatened more disclosure |
| 5 March 2025 | Guilty plea to two counts involving unlawful transfer of confidential phone records |
| 15 July 2025 | Guilty plea to conspiracy, computer extortion and aggravated identity theft |
| 25 September 2026 | Sentence of 70 months and $294,978 restitution |
Key facts
Sources
- PrimaryFormer U.S. Soldier Sentenced for Hacking and Extortion SchemeUS Department of Justiceaccessed 2026-09-28
- PrimaryFormer U.S. soldier pleads guilty in hacking and extortion schemeUS Department of Justiceaccessed 2026-09-28


