Full Report
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024. [...]
Analysis Summary
# Incident Report: Multi-Victim Extortion and Telecom Hacking Campaign
## Executive Summary
Between April 2023 and December 2024, a former U.S. Army soldier, Cameron John Wagenius, and several conspirators executed a series of cyberattacks against at least 10 U.S. technology and telecommunications firms. The threat actors utilized custom brute-force tools to gain unauthorized access, exfiltrated sensitive customer data, and attempted to extort over $1 million from the victims. The incident resulted in the sentencing of Wagenius to 70 months in prison and highlighted significant vulnerabilities in cloud storage configurations.
## Incident Details
- **Discovery Date:** Late 2024 (Law enforcement intervention)
- **Incident Date:** April 2023 – December 2024
- **Affected Organizations:** AT&T, Verizon, and at least 8 other tech/telecom entities
- **Sector:** Technology and Telecommunications
- **Geography:** United States
## Timeline of Events
### Initial Access
- **Date/Time:** Commencing April 2023
- **Vector:** SSH Brute-force attacks
- **Details:** The actors used a custom-developed "SSH Brute" hacking tool to identify and exploit weak credentials on victim networks.
### Lateral Movement
- **Details:** Following initial access via SSH, the group targeted cloud storage environments (notably Snowflake) and internal databases to expand their footprint and locate sensitive customer records.
### Data Exfiltration/Impact
- **Details:** Terabytes of data were stolen, including confidential phone records and sensitive customer information. Stolen data was used for SIM-swapping attacks and fraudulent activities.
### Detection & Response
- **Detection:** Identified through federal investigation into cybercrime forum activities and reports from victimized organizations.
- **Response:** Criminal investigation led by U.S. authorities resulted in the arrest of Wagenius in Texas (December 2024) and his subsequent guilty plea and sentencing (September 2026).
## Attack Methodology
- **Initial Access:** Brute-force attacks against SSH protocols.
- **Persistence:** Utilization of stolen credentials to maintain access to cloud environments.
- **Privilege Escalation:** Not explicitly detailed, but involved gaining access to administrative telecom databases.
- **Defense Evasion:** Use of encrypted messaging (Telegram) for coordination and private communication during extortion.
- **Credential Access:** SSH Brute tool and subsequent theft of Snowflake account credentials.
- **Discovery:** Identification of high-value targets in the telecom and tech sectors.
- **Lateral Movement:** Moving from initial entry points to centralized cloud storage and customer databases.
- **Collection:** Gathering sensitive customer PII and phone records.
- **Exfiltration:** Transferring data to attacker-controlled environments and Telegram channels.
- **Impact:** Financial extortion (demands totaling $1M+), SIM-swapping, and public data leaks on BreachForums and XSS.is.
## Impact Assessment
- **Financial:** $294,978 ordered in restitution; $1 million in attempted extortion.
- **Data Breach:** Hundreds of millions of records (across all conspirators' activities), including call logs and PII.
- **Operational:** Disruption to telecom services via unauthorized database access and SIM-swapping.
- **Reputational:** Significant public exposure for major brands like AT&T and Verizon.
## Indicators of Compromise
- **Network indicators:** SSH brute-force attempts from unauthorized IPs; traffic to `xss[.]is` and `breachforums[.]st`.
- **File indicators:** Presence of "SSH Brute" hacking utility.
- **Behavioral indicators:** Unauthorized access to Snowflake instances without MFA; bulk export of customer records during non-business hours.
## Response Actions
- **Containment:** Law enforcement seizure of digital infrastructure and Telegram accounts.
- **Eradication:** Arrest and prosecution of key threat actors (Wagenius, Moucka, Binns).
- **Recovery:** Implementation of mandatory security controls (MFA) by service providers like Snowflake to prevent credential-based re-entry.
## Lessons Learned
- **Credential Strength:** The reliance on brute-forceable credentials allowed for the initial compromise of multiple major firms.
- **Cloud Security Defaults:** Single-factor authentication on high-value cloud storage accounts (Snowflake) served as a primary catalyst for the scale of the data theft.
- **Insider/Service Member Risk:** The involvement of active-duty personnel highlights the need for monitoring and vetting.
## Recommendations
- **Enforce MFA:** Mandatory Multi-Factor Authentication for all administrative and cloud storage interfaces.
- **SSH Hardening:** Disable password-based SSH authentication in favor of public-key authentication; implement rate-limiting and fail2ban protocols.
- **Monitor Cloud Logs:** Actively audit Snowflake and other cloud logs for unusual data egress patterns or logins from unknown locations.
- **Password Policy:** Implement and enforce a minimum 14-character password policy for all corporate accounts.