Former US Soldier Sentenced to 70 Months for Hacking Telecom Networks and Extorting Companies
What Happened — A 22‑year‑old former U.S. Army soldier, Cameron John Wagenius, pleaded guilty to stealing login credentials, breaching the networks of multiple U.S. telecommunications providers, exfiltrating millions of call‑detail records, and attempting to extort the firms for ransom. The court ordered a 70‑month prison term and nearly $295 K in restitution.
Why It Matters for Trust & Control Assurance
- The incident illustrates the risk of credential compromise and inadequate privileged‑access controls—exactly the scenario a continuous access‑control monitoring program is built to detect and document.
- Demonstrable evidence of strong identity‑governance (MFA, least‑privilege, real‑time logging) provides a defensible audit trail for frameworks such as NIST CSF 2.0.
- A robust incident‑response and evidence‑preservation process is essential to prove due diligence when regulators or partners request proof of control effectiveness.
Who Is Affected
- Telecommunications carriers (e.g., AT&T)
- Cloud‑based data‑storage platforms that hosted telecom metadata (e.g., Snowflake)
Recommended Actions
- Conduct an immediate privileged‑access review: inventory all service accounts, enforce MFA, and rotate compromised credentials.
- Deploy continuous monitoring of authentication events and anomalous privileged activity; retain logs for at‑least 90 days for audit purposes.
- Validate your incident‑response playbook against credential‑theft scenarios and run a tabletop exercise.
- Document all remediation steps as evidence for future compliance audits.
Source: The Record – Former US soldier gets nearly six‑year sentence for hacking, extorting telecoms
Technical Notes
- Attack vector: stolen credentials used to gain SSH access; the actor employed a custom “SSH Brute” tool.
- Data exfiltrated: non‑content call‑detail records, text metadata, and personally identifiable information for millions of customers.
- No public ransomware payload was observed, but the threat actor leveraged the data for extortion and attempted foreign‑intelligence sale.