Former US Soldier Sentenced for AT&T and Snowflake Data Theft, 70‑Month Prison Term
What Happened — A former U.S. Army soldier, Cameron John Wagenius, was convicted for participating in a campaign that stole login credentials and exfiltrated data from AT&T and Snowflake‑hosted customer accounts. The group accessed more than 165 organizations, threatened to publish the data, and attempted extortion of roughly $1 million. Wagenius received a 70‑month prison sentence and was ordered to pay nearly $295 k in restitution.
Why It Matters for Trust & Control Assurance
- The incident demonstrates how compromised credentials can bypass perimeter defenses and give attackers unfettered access to cloud and telecom environments.
- Continuous monitoring of privileged account activity and immutable audit trails are core to a control‑assurance program that can detect credential abuse early.
- Verisq’s Access Controls capability provides the evidence‑ready monitoring and policy enforcement needed to prove that credential management controls are operating as intended.
Who Is Affected
- Telecommunications providers (e.g., AT&T)
- Cloud data‑storage and analytics platforms (e.g., Snowflake) and their enterprise customers
Recommended Actions
- Review and tighten credential‑issuance policies; enforce MFA for all privileged and service accounts.
- Deploy continuous monitoring of authentication events and integrate alerts into a centralized audit log.
- Conduct a rapid credential‑rotation exercise for any accounts that may have been exposed.
- Validate that evidence of these controls is collected and retained for audit readiness.
Technical Notes – The attackers used a custom “SSH Brute” tool to harvest valid credentials, then shared them via Telegram groups. Stolen credentials granted access to protected networks, enabling data exfiltration and subsequent SIM‑swap fraud. Source: Help Net Security