Ex-soldier gets 70 months for telecom and Snowflake extortion
Cameron Wagenius, kiberphant0m, was sentenced for hacking and extorting at least 10 organizations. How the Snowflake-era thefts worked and what to check in your tenant.
By Yaali. October 1, 2026, 7 min read, Threat intel, Identity.
Cameron John Wagenius, a 22 year old former US Army soldier who sold and leaked stolen telecom data as "kiberphant0m", was sentenced on September 25, 2026, in the US District Court for the Western District of Washington to 70 months in prison and $294,978 in restitution. Some reports are dated September 28; the Department of Justice puts the hearing on the 25th. Between April 2023 and December 18, 2024, while on active duty in South Korea and at Fort Cavazos, Texas, he and others defrauded at least 10 organizations and tried to extort more than $1 million from them.
The victims included AT&T, whose call and text records for more than 100 million customers were stolen from its Snowflake data warehouse account in 2024, and Verizon's push-to-talk business. The Snowflake thefts did not need a software flaw. The AT&T data came out of a campaign in which a group logged in to about 165 Snowflake customer accounts with stolen passwords that had no second factor behind them. If your company keeps data in Snowflake or any other software-as-a-service (SaaS) platform that accepts a password alone, the same path is open today.

How the Snowflake-era intrusions worked
Snowflake is a cloud data warehouse that companies query with SQL (Structured Query Language). Each customer gets its own account, and in 2024 an account could still let users sign in with a password and nothing else. Mandiant, which tracks the group behind the campaign as UNC5537, found no breach of Snowflake's own platform. Every intrusion it investigated started with a valid login.
Those logins came from infostealers, malware that copies the passwords saved in a browser and sends them to the operator, who sells the resulting "logs" in bulk. Mandiant named Vidar, Lumma, RedLine, Raccoon Stealer, MetaStealer and RisePro among the families involved. At least 79.7% of the accounts UNC5537 used had appeared in earlier stealer logs, some dating to November 2020. Three conditions let those old passwords work: the accounts had no multi-factor authentication (MFA), the passwords had never been rotated, and the Snowflake accounts had no network allow list limiting which IP addresses could connect.
Once inside, the attackers worked like an analyst would. Mandiant recorded SHOW TABLES, SELECT * and LIST to see what was there, then CREATE TEMPORARY STAGE to make a scratch storage area, COPY INTO to dump whole tables into it as gzip compressed CSV files, and GET to download the files. They connected through Mullvad and Private Internet Access VPN exits with a reconnaissance tool Mandiant calls FROSTBITE (it identified itself to Snowflake as rapeflake) and the commercial DBeaver Ultimate database client. A data engineer runs the same commands every day.
Wagenius's own part, as the Department of Justice describes it, used the same raw material. The group traded stolen credentials in Telegram chats, used a brute force tool called SSH Brute that Wagenius helped write to get into other systems, and threatened to publish data on BreachForums and XSS.is unless victims paid. In November 2024 he posted confidential call detail records belonging to a government official. Call detail records hold the numbers, time and duration of each call, enough to show who a person talks to and when.
What the group did with the access
AT&T disclosed the theft on July 12, 2024, and said the records covered calls and texts for "nearly all" of its cellular customers between May 1 and October 31, 2022, downloaded from its Snowflake workspace between April 14 and April 25, 2024. According to Wired's reporting, carried by CSO Online and others, AT&T paid a member of the group about $370,000 in bitcoin in May 2024 to delete its copy. Wagenius later advertised AT&T records himself and offered a SIM swapping service aimed at Verizon push-to-talk customers, as KrebsOnSecurity and SecurityWeek reported at the time of his arrest in December 2024.
Across the wider Snowflake campaign, victims named in court filings and news reports include Ticketmaster, Santander, Advance Auto Parts and Neiman Marcus. The Record and CyberScoop report that the three men together received more than $2.5 million in ransom payments. Connor Riley Moucka, a Canadian extradited to the United States, pleaded guilty on August 5, 2026, to computer fraud, wire fraud, aggravated identity theft and conspiracy, and is due to be sentenced on October 27. John Erin Binns, a US citizen detained in Turkey in 2024 and also linked to the 2021 T-Mobile breach, remains charged and is not in US custody. Wagenius himself pleaded guilty in 2025, first to transferring confidential phone records and then, in July, to wire fraud conspiracy, extortion and aggravated identity theft.
What to check in your own SaaS and warehouse tenants

Work through these in order. The first three close the path; the rest tell you whether someone already used it.
- List every account that can sign in with a password alone. In Snowflake, query
SNOWFLAKE.ACCOUNT_USAGE.LOGIN_HISTORYfor successful logins whereFIRST_AUTHENTICATION_FACTOR = 'PASSWORD'andSECOND_AUTHENTICATION_FACTORis empty. Snowflake has blocked password-only sign-in for all users since November 2025, so the useful version of this check today is on your other warehouses and SaaS platforms, against their own sign-in logs. Move people to single sign-on (SSO) with MFA and services to key pair or OAuth authentication. - Restrict where logins can come from. Apply a Snowflake network policy, or the equivalent conditional access rule for SSO, so the account only accepts connections from your offices, VPN egress and the fixed IPs of your extract and BI tools. Then watch
QUERY_HISTORYforCREATE_NETWORK_POLICY,ALTER_NETWORK_POLICYandDROP_NETWORK_POLICY, since an attacker with an admin role will try to loosen it. - Rotate anything that may sit in a stealer log. Search a stealer log or breach monitoring feed for your Snowflake account URL (the
<account>.snowflakecomputing.comhost) and your staff and contractor email domains. Rotate every credential found, and any service account password older than your rotation policy. - Hunt for the client fingerprints. In
SNOWFLAKE.ACCOUNT_USAGE.SESSIONS, look atCLIENT_ENVIRONMENTfor an application ofrapeflake, or DBeaver from a Windows Server host when nobody in your team uses it. Datadog Security Labs calls either a strong sign of compromise. - Hunt for bulk export. Search
QUERY_HISTORYforCREATE TEMPORARY STAGE,COPY INTOaimed at a stage or external URL, andGET, especially from a user that normally only runs dashboards. - Mind the retention window. Snowflake keeps
LOGIN_HISTORYandQUERY_HISTORYfor 365 days. Activity from 2024 has already aged out of the views, so if you were among the notified customers, rely on what you exported then. Ship these views to your SIEM (security information and event management system) now so the next hunt is not limited to a year.
If any of these turn up a match, treat the account as compromised: disable the user, rotate its credentials and any keys it could read, list the tables it touched from ACCESS_HISTORY, and assume the data in them is held by someone who will ask for money.
Why a sentencing matters to a defender
Two years after the thefts, one man is sentenced, one awaits sentencing and one is out of reach, and the data is still circulating. AT&T's payment bought a deletion promise that no one can check. Mandiant found that the compromised accounts lacked both MFA and a network allow list, and either one blocks a login built on a stolen password alone. Those two settings belong on every SaaS tenant that holds customer data.
Our cloud and Kubernetes security work includes reviewing SaaS and data warehouse tenants for exactly these settings, and our security operations team can build the login and query hunts above into your monitoring. To find out which of your accounts still accept a password alone, open the chat and Yaali, our AI agent, will pass the question to an engineer.
Sources: US Department of Justice, Office of Public Affairs, US Attorney's Office, Western District of Washington, CyberScoop, SecurityWeek, The Record, KrebsOnSecurity, Help Net Security, The Record on Moucka's plea, Mandiant on UNC5537, SecurityWeek on Mandiant's findings, CSO Online on the AT&T payment, Datadog Security Labs, Snowflake LOGIN_HISTORY documentation.
Read next
- Storm-3068 used Azure DevOps to steal Kubernetes keys
- JadePuffer wiped an Azure tenant in seven minutes
- Times Car breach: 6.6M accounts and licence images
Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.