Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

US Soldier Sentenced to 70 Months for Hacking and Extorting Ten Tech and Telecom Companies

A former U.S. Army soldier stole SSH credentials from multiple telecom and tech firms, accessed confidential customer records, and extorted the victims for up to $1 million. The case underscores the need for strong access‑control safeguards and auditable evidence of MFA and credential‑monitoring practices.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
bleepingcomputer.com

US Soldier Sentenced to 70 Months for Hacking and Extorting Ten Tech and Telecom Companies

What Happened – A former U.S. Army soldier, Cameron John Wagenius, stole SSH credentials from at least ten technology and telecommunications firms using a brute‑force tool he helped develop. He transferred the credentials via Telegram, accessed confidential customer records, and extorted the victims by threatening to publish or sell the data, demanding roughly $1 million.

Why It Matters for Trust & Control Assurance

  • The incident illustrates the damage that weak credential hygiene and lack of multi‑factor authentication can cause – exactly the scenario a continuous access‑control assurance program is built to prevent.
  • Demonstrable evidence of privileged‑access monitoring, MFA enforcement, and rapid credential rotation provides a defensible audit trail for regulators and partners.
  • Leveraging a control‑mapping capability helps organizations prove they meet the “identity and access management” control objective across multiple frameworks (e.g., NIST CSF 2.0).

Who Is Affected – Telecommunications carriers, cloud‑service providers, and technology firms that store or process customer data.

Recommended Actions – Review and harden SSH access policies, enforce MFA for all privileged accounts, implement continuous credential‑use monitoring, and retain evidence of access‑control reviews for audit readiness. Source: https://www.bleepingcomputer.com/news/security/us-soldier-gets-70-months-in-prison-for-extorting-10-tech-telecom-firms/

Technical Notes – Attack vector: stolen SSH credentials obtained via a custom brute‑force tool; data exfiltrated through compromised accounts; extortion leveraged public cybercrime forums. Source: https://www.bleepingcomputer.com/news/security/us-soldier-gets-70-months-in-prison-for-extorting-10-tech-telecom-firms/

📰 Original Source
https://www.bleepingcomputer.com/news/security/us-soldier-gets-70-months-in-prison-for-extorting-10-tech-telecom-firms/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →