Full Report
A former soldier was sentenced to 70 months in prison last week for a spree of various cybercrimes spanning years, while he was an active duty soldier stationed at Fort Hood. Cameron James Wagenius, 22, was sentenced to prison on Friday, more than a year after pleading guilty to hacking telecommunication companies and extortion schemes…
Analysis Summary
# Incident Report: Hacking and Extortion Spree by Active-Duty Soldier
## Executive Summary
Cameron James Wagenius, an active-duty U.S. Army soldier, participated in a cybercrime conspiracy that targeted at least 10 organizations, primarily in the telecommunications sector. The group utilized custom-developed hacking tools to exfiltrate call detail records (CDRs) and subsequently extort high-profile individuals, including government officials. The incident concluded with Wagenius being sentenced to 70 months in federal prison following a Department of Justice investigation.
## Incident Details
- **Discovery Date:** Approximately late 2024 (during extortion phase)
- **Incident Date:** April 2023 – December 2024
- **Affected Organization:** At least 10 organizations, including telecommunication companies.
- **Sector:** Telecommunications / Government
- **Geography:** Fort Cavazos (formerly Fort Hood), Texas, USA
## Timeline of Events
### Initial Access
- **Date/Time:** Commencing April 2023
- **Vector:** Proprietary/Custom Hacking Tools
- **Details:** Wagenius and his co-conspirators developed and deployed a specific hacking tool to bypass security and gain unauthorized access to telecommunications databases.
### Lateral Movement
- **Details:** The group navigated through the internal networks of the targeted telecommunication providers to reach sensitive databases housing call logs and non-content call detail records (CDRs).
### Data Exfiltration/Impact
- **Details:** Sensitive call logs belonging to at least 10 organizations were exfiltrated. Specifically, in November 2024, Wagenius posted stolen data belonging to a government official and the family of a former official.
### Detection & Response
- **Detection:** The incident gained significant visibility when the actor publicly threatened to release more records unless a ransom was paid.
- **Response:** An investigation was launched by federal authorities (DOJ), leading to a guilty plea and subsequent sentencing in late 2026.
## Attack Methodology
- **Initial Access:** Use of custom-developed hacking tools targeted at telecommunications infrastructure.
- **Persistence:** Not explicitly detailed, but activity spanned over 20 months.
- **Collection:** Gathering of non-content "call detail records" (CDRs).
- **Exfiltration:** Transfer of sensitive logs from corporate servers to public-facing platforms for extortion.
- **Impact:** Extortion/Ransomware-style threats and unauthorized disclosure of government-related PII/communication metadata.
## Impact Assessment
- **Financial:** Unknown total ransom demands; legal costs for 10+ organizations.
- **Data Breach:** Stolen call detail records for government officials and their family members.
- **Operational:** Significant breach of trust in telecommunication security protocols.
- **Reputational:** High-profile impact due to the perpetrator being an active-duty military member and the victims being government figures.
## Indicators of Compromise
- **Behavioral Indicators:** Extortion attempts via social media or online forums using the alias "kiberphant0m."
- **Tooling:** Usage of a specific, unnamed hacking tool co-developed by Wagenius.
## Response Actions
- **Containment:** Federal law enforcement intervention to halt the extortion plot.
- **Recovery:** Prosecution and sentencing (70 months imprisonment).
- **Eradication:** Dismantling of the conspiracy group and their tools.
## Lessons Learned
- **Insider Threat:** The incident highlights the risk posed by technically proficient active-duty personnel engaging in illicit "side" activities.
- **Telecommunications Security:** The vulnerability of CDRs poses a significant national security risk when high-profile government targets are involved.
- **Tool Development:** Threat actors are increasingly co-developing proprietary tools to bypass standard EDR/AV solutions.
## Recommendations
- **Enhanced Vetting:** Implement stricter continuous evaluation for personnel in sensitive positions with advanced technical training.
- **Data Access Control:** Telecommunication companies should implement stricter access controls and monitoring on Call Detail Record (CDR) databases.
- **Monitoring for Extortion:** Organizations should monitor for unauthorized disclosure of internal data on underground forums and social media to catch breaches that bypass traditional detection.