← Back to StoryBreak

Former Army Soldier Sentenced to 70 Months in Telecom Hacking and Extortion Case

Cameron John Wagenius, a former Army soldier, was sentenced after admitting to a hacking scheme that targeted telecommunications companies and exposed sensitive phone-record data, including information linked to a U.S. government official.

By StoryBreak

Published September 26, 2026 at 12:13 AM

Former Army Soldier Sentenced to 70 Months in Telecom Hacking and Extortion Case
AI-generated image / StoryBreak

Cameron John Wagenius, a former U.S. Army soldier, was sentenced Friday to 70 months in federal prison for a hacking and extortion scheme that exposed telecommunications data and included sensitive information connected to a U.S. government official, the Justice Department said.

Wagenius, 22, was also ordered to pay $294,978 in restitution. The sentence closes one major phase of a case that prosecutors describe as a far-reaching intrusion campaign rather than a single breach.

According to the Justice Department’s earlier account of the case, Wagenius participated in the scheme while serving on active duty. Between April 2023 and December 2024, he and co-conspirators allegedly obtained credentials for protected computer networks, accessed telecommunications databases and threatened to publish or sell stolen information unless companies paid.

The group targeted at least 10 organizations, prosecutors said, and attempted to extort at least $1 million from the owners of stolen data. Wagenius pleaded guilty to conspiracy to commit wire fraud, extortion related to computer fraud and aggravated identity theft. He also pleaded guilty in a separate case involving the unlawful transfer of confidential phone-record information.

The data at issue was not limited to names or passwords. Reporting by KrebsOnSecurity said the stolen material included mobile call and text metadata associated with more than 100 million AT&T customers. Such records can reveal who communicated with whom, when communications occurred and how long they lasted, even when the content of a call or message is not exposed.

That distinction matters. Metadata may appear less revealing than message content, but patterns of communication can identify relationships, routines and potentially sensitive contacts. In this case, the hackers allegedly used stolen information both as leverage against companies and as a commodity in online criminal forums.

The Justice Department’s case announcement did not describe the government official by name. KrebsOnSecurity reported that the online persona associated with Wagenius claimed to have posted call records involving then-President-elect Donald Trump and then-Vice President Kamala Harris after another alleged participant was arrested. Those claims should be understood as allegations reported in connection with the case, not as a finding that every record claimed by the hackers was authentic.

The broader lesson is that the security problem was not simply a matter of one weak password. Investigators said the conspirators obtained credentials through hacking tools and used online groups to exchange access and discuss targets. The case therefore combined credential theft, database access, extortion and the resale of information—several stages of harm built on the same initial compromise.

The case also illustrates a gap between criminal ambition and criminal profit. Prosecutors said the group sought at least $1 million from victims. Yet KrebsOnSecurity reported that Wagenius made about $1,500 from selling stolen data. Financial failure, however, did not mean limited damage: the Justice Department said the scheme affected numerous organizations and individuals and involved confidential phone records.

The investigation was conducted by the FBI and the Defense Criminal Investigative Service, with assistance from the Army’s Criminal Investigation Division and other Justice Department offices. Two other alleged co-conspirators remain connected to separate proceedings, according to the reporting.

For companies and government agencies, the case is a reminder that a breach can become more dangerous after the initial intrusion. Stolen access can be reused, data can be resold, and threats can continue even after investigators identify the original attack. For the public, the practical takeaway is less about one sentence than about the sensitivity of the digital traces created by ordinary calls and texts—and the number of institutions that may hold them.

StoryBreak

Independent digital news and reporting, updated throughout the day.

This article was researched and drafted with AI assistance and reviewed as part of StoryBreak's editorial process before publication. Read our editorial standards.