Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

Former US Soldier Sentenced for AT&T and Snowflake Data Theft, 70‑Month Prison Term

A former U.S. Army soldier was convicted for stealing credentials and exfiltrating data from AT&T and Snowflake customers, affecting over 165 organizations. The breach highlights the need for continuous credential monitoring and audit‑ready evidence in control‑assurance programs.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
helpnetsecurity.com

Former US Soldier Sentenced for AT&T and Snowflake Data Theft, 70‑Month Prison Term

What Happened — A former U.S. Army soldier, Cameron John Wagenius, was convicted for participating in a campaign that stole login credentials and exfiltrated data from AT&T and Snowflake‑hosted customer accounts. The group accessed more than 165 organizations, threatened to publish the data, and attempted extortion of roughly $1 million. Wagenius received a 70‑month prison sentence and was ordered to pay nearly $295 k in restitution.

Why It Matters for Trust & Control Assurance

  • The incident demonstrates how compromised credentials can bypass perimeter defenses and give attackers unfettered access to cloud and telecom environments.
  • Continuous monitoring of privileged account activity and immutable audit trails are core to a control‑assurance program that can detect credential abuse early.
  • Verisq’s Access Controls capability provides the evidence‑ready monitoring and policy enforcement needed to prove that credential management controls are operating as intended.

Who Is Affected

  • Telecommunications providers (e.g., AT&T)
  • Cloud data‑storage and analytics platforms (e.g., Snowflake) and their enterprise customers

Recommended Actions

  • Review and tighten credential‑issuance policies; enforce MFA for all privileged and service accounts.
  • Deploy continuous monitoring of authentication events and integrate alerts into a centralized audit log.
  • Conduct a rapid credential‑rotation exercise for any accounts that may have been exposed.
  • Validate that evidence of these controls is collected and retained for audit readiness.

Technical Notes – The attackers used a custom “SSH Brute” tool to harvest valid credentials, then shared them via Telegram groups. Stolen credentials granted access to protected networks, enabling data exfiltration and subsequent SIM‑swap fraud. Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/09/28/us-army-soldier-snowflake-breaches-extortion/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →