Cameron John Wagenius, a former U.S. Army soldier, was sentenced to 70 months in federal prison on September 28 for hacking at least 10 U.S. technology and telecommunications companies while on active duty. The victims included AT&T and Verizon along with eight other organizations that Wagenius targeted during a campaign spanning from April 2023 through December 2024.
Active-Duty Soldier Conducted Attacks Against Wireless Carriers and Tech Firms
Wagenius conducted the hacking campaign while serving in the U.S. Army, using his access and technical skills to breach multiple technology and telecommunications companies. The attacks targeted AT&T and Verizon—two of the largest wireless carriers in the United States—plus eight additional organizations in the technology sector. Wagenius stole proprietary information from the compromised companies, extracting data that included internal technical details, customer records, and business intelligence.
The attacks represent an insider threat scenario where an individual with security clearance and military training conducted offensive operations against civilian infrastructure. Active-duty military personnel typically hold clearances that grant access to classified information and systems, creating heightened risk when such individuals apply those skills and access privileges toward criminal activity.
Campaign Included Extortion Demands Seeking $1 Million in Ransom
Beyond data theft, Wagenius attempted to extort approximately $1 million in ransom payments from the victim organizations. The extortion component transformed the intrusions from pure espionage or theft into a financially motivated campaign designed to coerce victims into paying to prevent public disclosure of the stolen information.
Telecommunications companies hold particularly sensitive data including customer call records, text message metadata, location tracking from mobile devices, and network architecture details. The threat to disclose this information publicly creates significant pressure on victim companies to pay ransom demands, as public exposure could trigger regulatory investigations, customer lawsuits, and competitive disadvantage if proprietary technical information reaches competitors.
AT&T and Verizon Breaches Exposed Wireless Infrastructure and Customer Data
The AT&T and Verizon compromises gave Wagenius access to infrastructure operated by the two largest wireless carriers in the United States. These companies collectively serve hundreds of millions of subscribers and operate critical telecommunications infrastructure. Successful intrusions into these environments could expose vast amounts of customer communications metadata, subscriber personal information, and operational details about network architecture and security controls.
The proprietary information Wagenius stole from wireless carriers likely included technical specifications, security configurations, and internal operational procedures that are not publicly disclosed. This information has value both for criminal operations—understanding how carriers detect fraud or intrusions helps attackers evade those controls—and for competitive intelligence if sold to international parties interested in U.S. telecommunications infrastructure design.
Insider Threat from Military Personnel Requires Specialized Monitoring
The Wagenius case highlights insider threat risks from personnel with security clearances and specialized technical training. Military cybersecurity roles train soldiers to conduct offensive operations, analyze networks, and exploit vulnerabilities—skills that can be redirected toward criminal activity if the individual chooses to violate their obligations. The same capabilities that make military cyber operators effective in their official duties also make them high-risk insiders if they engage in unauthorized activity.
Organizations that employ current or former military personnel in technical roles should implement insider threat monitoring that accounts for the specialized skills these individuals possess. Standard access controls and activity monitoring designed to detect typical insider threats may not adequately address actors with formal training in evasion, operational security, and advanced persistent access techniques.
Federal Prosecution and 70-Month Sentence Signal Consequences
The 70-month federal prison sentence reflects the severity of the crimes and the aggravating factor of Wagenius conducting the attacks while in a position of trust as an active-duty soldier. Federal prosecutors pursued charges for the computer intrusions and extortion attempts, working with the U.S. Army which conducted an internal investigation into how Wagenius used military resources or training to execute the campaign.
The affected companies implemented remediation following breach notification, but the long timeline of the attacks from April 2023 through December 2024 suggests that Wagenius maintained access to victim networks for extended periods before detection. The case highlights the difficulty of detecting insider threats, particularly when the attacker has legitimate technical skills and understands the security controls they need to evade.
Organizations in the technology and telecommunications sectors should review the case details for any insight into attack methods or indicators that could inform detection of similar insider threat activity. Monitoring for unusual access patterns from privileged accounts, particularly access to sensitive customer data or proprietary technical information outside normal job responsibilities, provides a detection layer against insider abuse.
