Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

Former US Soldier Sentenced to 70 Months for Hacking Telecom Networks and Extorting Companies

A former U.S. Army soldier was sentenced to 70 months after stealing login credentials, breaching multiple telecom providers, and exfiltrating millions of call‑detail records. The breach underscores the need for strong identity‑governance and continuous access‑control monitoring to satisfy audit and regulatory expectations.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 therecord.media
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
therecord.media

Former US Soldier Sentenced to 70 Months for Hacking Telecom Networks and Extorting Companies

What Happened — A 22‑year‑old former U.S. Army soldier, Cameron John Wagenius, pleaded guilty to stealing login credentials, breaching the networks of multiple U.S. telecommunications providers, exfiltrating millions of call‑detail records, and attempting to extort the firms for ransom. The court ordered a 70‑month prison term and nearly $295 K in restitution.

Why It Matters for Trust & Control Assurance

  • The incident illustrates the risk of credential compromise and inadequate privileged‑access controls—exactly the scenario a continuous access‑control monitoring program is built to detect and document.
  • Demonstrable evidence of strong identity‑governance (MFA, least‑privilege, real‑time logging) provides a defensible audit trail for frameworks such as NIST CSF 2.0.
  • A robust incident‑response and evidence‑preservation process is essential to prove due diligence when regulators or partners request proof of control effectiveness.

Who Is Affected

  • Telecommunications carriers (e.g., AT&T)
  • Cloud‑based data‑storage platforms that hosted telecom metadata (e.g., Snowflake)

Recommended Actions

  • Conduct an immediate privileged‑access review: inventory all service accounts, enforce MFA, and rotate compromised credentials.
  • Deploy continuous monitoring of authentication events and anomalous privileged activity; retain logs for at‑least 90 days for audit purposes.
  • Validate your incident‑response playbook against credential‑theft scenarios and run a tabletop exercise.
  • Document all remediation steps as evidence for future compliance audits.

Source: The Record – Former US soldier gets nearly six‑year sentence for hacking, extorting telecoms

Technical Notes

  • Attack vector: stolen credentials used to gain SSH access; the actor employed a custom “SSH Brute” tool.
  • Data exfiltrated: non‑content call‑detail records, text metadata, and personally identifiable information for millions of customers.
  • No public ransomware payload was observed, but the threat actor leveraged the data for extortion and attempted foreign‑intelligence sale.
📰 Original Source
https://therecord.media/hacker-telecom-army-sentenced ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →