Edited by humans. Written by AI. How our editing works
All articles

Telecom Hacker Sentence Exposes a Market for Call Data

A former soldier's 70-month sentence shows how stolen telecom records moved from breached systems into extortion, criminal sales and SIM-swap fraud.

Rachel "Rach" Kovacs

Written by AI. Rachel "Rach" Kovacs

September 29, 20266 min read
Share:
Telecom Hacker Sentence Exposes a Market for Call Data

Cameron John Wagenius received 70 months in federal prison for a hacking and extortion campaign that reached at least 10 technology and telecommunications organizations.

The sentence gives the case a tidy endpoint. The stolen data had a much messier journey.

Wagenius and his co-conspirators obtained credentials, entered protected networks, stole customer records and then advertised data through BreachForums, XSS, X and Telegram. The Justice Department said they attempted to extort at least $1 million, successfully sold some stolen data and used other records for fraud, including SIM swapping. Wagenius must also pay $294,978 in restitution, according to reporting based on the court records.

That sequence explains why this case deserves attention beyond the prison term. The conspirators treated telecom records as reusable inventory. One copy could support a ransom demand, a forum sale, public exposure or another fraud. A breached company might restore its systems and close an intrusion ticket, while copied records continue circulating elsewhere.

One Theft, Several Ways to Profit

The campaign ran from April 2023 through December 2024 while Wagenius was serving in the US Army. He helped develop a tool called SSH Brute, exchanged stolen credentials through Telegram and discussed using those credentials to reach additional parts of victims’ networks. Court documents cited by The Register say the group traded hundreds of credentials and stole hundreds of thousands of customer records from multiple companies.

The group’s business model had multiple exits. Stolen material could be offered for thousands of dollars, held over an organization to demand payment or used for follow-on fraud. Public disclosure added pressure and notoriety. US District Judge Lauren King told Wagenius that his actions were motivated by “greed and a desire for notoriety.”

Court accounts add a more personal example. In November 2024, Wagenius publicly disclosed confidential call detail records belonging to an unidentified government official and threatened to release more, SecurityWeek reported. Separately, The Register reported that an account controlled by Wagenius claimed to hold AT&T call records belonging to Donald Trump and Kamala Harris after two suspects connected to the Snowflake attacks were arrested.

Those two statements should remain separate. The available reporting does not identify the government official, and the Trump-Harris assertion was a claim made by an account controlled by Wagenius. The record supports public disclosure of one official’s confidential records and a separate claim about two prominent political figures. It does not establish from these reports that all three references concern verified records or the same incident.

Even with that limit, the documented chain is clear: credentials opened systems, stolen records moved into online markets, and some data became fuel for SIM-swapping and other fraud. Calling this only a privacy breach would leave out the later uses described by prosecutors. The records functioned as criminal inputs after the original intrusion ended.

The Snowflake Campaign Behind the Sentence

Wagenius was also linked to the 2024 Snowflake extortion campaign, a much larger series of intrusions involving data held through the cloud provider’s services. Two alleged accomplices, Connor Riley Moucka and John Erin Binns, were accused of stealing terabytes of data from more than 165 organizations and demanding money in exchange for deleting it and withholding it from publication.

Breaches connected to that campaign affected hundreds of millions of people across organizations including AT&T, Ticketmaster, Santander, Los Angeles Unified, LendingTree, Pure Storage, Advance Auto Parts and Neiman Marcus. After the incidents, Snowflake announced that it would enforce multifactor authentication and require passwords of at least 14 characters.

That history changes the scale of the Wagenius story. His sentencing resolves the criminal liability of one participant for conduct covering at least 10 organizations. It does not close the broader campaign, erase copies already traded or tell us how many downstream crimes those copies enabled. The affected population figures also describe the larger Snowflake-linked breach landscape, rather than harm attributable to Wagenius alone.

Snowflake’s authentication changes provide a second lesson. Stronger access controls arrived after a campaign had demonstrated what stolen credentials could unlock. Enforced multifactor authentication does not answer every security problem, but it places another barrier between possession of a password and access to a customer environment. A 14-character password requirement raises the password baseline. Neither control can recall data already copied.

For companies holding high-value customer records, the order of operations should receive as much scrutiny as the controls themselves. Authentication requirements applied before a campaign can reduce opportunities for intrusion. The same requirements imposed afterward protect future access while victims remain exposed to whatever uses the stolen material permits. That is the awkward clock in breach response: defenders can secure the door faster than they can recover everything carried through it.

Two Defendants, Two Legal Clocks

Moucka offers a useful comparison, with firm limits. Canadian authorities arrested him on October 30, 2024, at the request of the United States. He pleaded guilty in August 2026 to his role in the Snowflake campaign. Wagenius was arrested in Texas in December 2024, entered guilty pleas during 2025 and has now been sentenced.

Both cases trace back to the same broader ecosystem of stolen credentials, cloud-hosted data and extortion. Their paths diverged because cross-border cybercrime cases move defendant by defendant. The available accounts do not provide a sentencing outcome for Moucka, so comparing punishment would be guesswork. The defensible comparison concerns process: participants linked to one campaign can face arrest, pleas and sentencing on separate schedules while the compromised data follows no court calendar.

That weakens any simple claim that one 70-month sentence measures deterrence across the market. A prison term imposes a substantial consequence on Wagenius. Whether it changes the incentives of forum sellers, credential traders or other participants depends on factors these court reports cannot establish, including how likely they believe identification and prosecution to be.

How to Read the Next Telecom Breach

Readers evaluating a future breach notice should look past the size of the database and ask what happened after access. Was the information merely viewed, copied, advertised, sold or used in another attack? Did the company invalidate exposed credentials and enforce stronger authentication? Has it explained what categories of records left its control, rather than describing only which system was repaired?

Organizations also need to investigate downstream use as part of incident response. In this case, the same pool of stolen material supported sales, extortion threats, public disclosure and SIM-swapping fraud. Counting affected records captures scale. Following where the data travels captures risk.

Wagenius will serve 70 months, but his sentence cannot put copied call records back inside a carrier’s database. The security test now falls on the organizations holding the next valuable dataset: whether they add the second lock before someone arrives with the first stolen key.

More Like This