US Soldier Sentenced to 70 Months for Hacking and Extorting Ten Tech and Telecom Companies
What Happened – A former U.S. Army soldier, Cameron John Wagenius, stole SSH credentials from at least ten technology and telecommunications firms using a brute‑force tool he helped develop. He transferred the credentials via Telegram, accessed confidential customer records, and extorted the victims by threatening to publish or sell the data, demanding roughly $1 million.
Why It Matters for Trust & Control Assurance
- The incident illustrates the damage that weak credential hygiene and lack of multi‑factor authentication can cause – exactly the scenario a continuous access‑control assurance program is built to prevent.
- Demonstrable evidence of privileged‑access monitoring, MFA enforcement, and rapid credential rotation provides a defensible audit trail for regulators and partners.
- Leveraging a control‑mapping capability helps organizations prove they meet the “identity and access management” control objective across multiple frameworks (e.g., NIST CSF 2.0).
Who Is Affected – Telecommunications carriers, cloud‑service providers, and technology firms that store or process customer data.
Recommended Actions – Review and harden SSH access policies, enforce MFA for all privileged accounts, implement continuous credential‑use monitoring, and retain evidence of access‑control reviews for audit readiness. Source: https://www.bleepingcomputer.com/news/security/us-soldier-gets-70-months-in-prison-for-extorting-10-tech-telecom-firms/
Technical Notes – Attack vector: stolen SSH credentials obtained via a custom brute‑force tool; data exfiltrated through compromised accounts; extortion leveraged public cybercrime forums. Source: https://www.bleepingcomputer.com/news/security/us-soldier-gets-70-months-in-prison-for-extorting-10-tech-telecom-firms/