Full Report
Active-duty campaign targeted at least ten organizations and sought $1 million in ransom payments
Analysis Summary
# Incident Report: Active-Duty Hacking and Extortion Campaign
## Executive Summary
A former US Army soldier, Cameron John Wagenius (operating under the alias "kiberphant0m"), orchestrated a sophisticated hacking and extortion campaign against at least ten organizations while on active duty. The campaign involved the theft of sensitive telecommunications records and hundreds of thousands of customer data points, resulting in ransom demands exceeding $1 million. The actor has been sentenced to 70 months in prison and ordered to pay nearly $300,000 in restitution.
## Incident Details
- **Discovery Date:** Investigation culminated in guilty pleas in March and July 2025.
- **Incident Date:** April 2023 – December 2024
- **Affected Organization:** At least ten organizations, including major US and overseas telecommunications companies (Linked to the Snowflake extortion campaign affecting AT&T and Verizon).
- **Sector:** Telecommunications / Technology
- **Geography:** United States and South Korea (Actor's location during deployment)
## Timeline of Events
### Initial Access
- **Date/Time:** April 2023
- **Vector:** Credential harvesting and brute-force attacks.
- **Details:** The group utilized a custom-developed tool called "SSH Brute" to obtain login credentials for protected networks.
### Lateral Movement
- **Details:** Stolen credentials were exchanged in Telegram group chats and used to pivot from initial entry points into broader victim networks to access sensitive databases.
### Data Exfiltration/Impact
- **Details:** Stolen records included hundreds of thousands of customer records and confidential phone logs. Data was subsequently advertised for sale on illicit forums.
### Detection & Response
- **How it was discovered:** Law enforcement investigation linked to the 2024 Snowflake data breach campaign and monitoring of cybercrime forums.
- **Response actions taken:** Federal prosecution, arrest of co-conspirators, and judicial sentencing.
## Attack Methodology
- **Initial Access:** Credential theft via custom "SSH Brute" tool and potentially Snowflake environment vulnerabilities.
- **Persistence:** Not explicitly detailed, but maintained through the trade and use of multiple sets of stolen credentials.
- **Privilege Escalation:** Use of administrative credentials to access protected customer databases.
- **Defense Evasion:** Use of online aliases (e.g., "kiberphant0m") and encrypted messaging platforms like Telegram.
- **Credential Access:** SSH brute-forcing and purchasing/trading credentials on BreachForums and XSS.
- **Discovery:** Network reconnaissance to identify sensitive customer record repositories.
- **Lateral Movement:** Credential stuffing and lateral pivoting within cloud and telecom environments.
- **Collection:** Bulk extraction of sensitive telecommunications records and customer PII.
- **Exfiltration:** Transfer of data to attacker-controlled environments for advertising on leak sites.
- **Impact:** Financial extortion (demanding $1M+), data leakage, and SIM swapping fraud.
## Impact Assessment
- **Financial:** $294,978 in court-ordered restitution; attempted extortion of over $1,000,000.
- **Data Breach:** Hundreds of thousands of customer records and confidential phone records stolen.
- **Operational:** Significant disruption to telecom security operations and integrity of customer accounts (SIM swapping).
- **Reputational:** High-profile impact on major carriers like AT&T and Verizon due to association with the Snowflake campaign.
## Indicators of Compromise
- **Network indicators:** Activity associated with SSH brute-forcing tools; connections to Telegram API for credential exfiltration.
- **File indicators:** "SSH Brute" tool artifacts.
- **Behavioral indicators:** Unauthorized access to customer databases from unusual geographic locations (e.g., South Korea-based IPs accessing US telecom backends).
## Response Actions
- **Containment measures:** Law enforcement intervention and seizure of accounts.
- **Eradication steps:** Disruption of the Telegram-based credential trading ring.
- **Recovery actions:** Legal sentencing and financial restitution orders to compensate victims.
## Lessons Learned
- **Insider Threat/Dual Occupations:** Active-duty personnel with technical skills may moonlighting in cybercrime; improved vetting and monitoring of high-clearance individuals’ digital footprints are necessary.
- **Supply Chain Vulnerability:** The incident underscores how third-party services (like Snowflake) can be the weak link for massive organizations like Verizon and AT&T.
- **Credential Hygiene:** The success of "SSH Brute" highlights the continued danger of weak passwords and the lack of Multi-Factor Authentication (MFA) on critical infrastructure.
## Recommendations
- **Enforce MFA:** Implement robust Multi-Factor Authentication across all external-facing services and SSH gateways.
- **Monitor Third-Party Cloud Environments:** Enhance logging and alerting for large-scale data exports from cloud storage platforms (e.g., Snowflake).
- **Zero Trust Architecture:** Implement strict identity-based access controls to prevent lateral movement even if credentials are compromised.
- **Dark Web Monitoring:** Actively monitor forums like XSS and BreachForums for mentions of corporate credentials or data leaks.