Skip to content
Security & Trust

Soldier Sentenced for AT&T Hack Also Sought AI Help With Exploit Code

Cameron Wagenius drew 70 months for the AT&T breach, then used prison email proxies to query AI for exploit code.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Soldier Sentenced for AT&T Hack Also Sought AI Help With Exploit Code
Key finding

AT&T customer records exposed: 100 million+ (Source: KrebsOnSecurity (September 28, 2026))

A soldier's data heist, and its unraveling

Cameron John Wagenius, 22, was serving with the U.S. Army in South Korea when he built a criminal sideline hacking telecom providers. A federal court in Seattle handed him a 70-month prison sentence and a $294,978 restitution order for the scheme.

Under the online alias Kiberphant0m, Wagenius siphoned call and text records belonging to more than 100 million AT&T subscribers and told cybercrime forums he had broken into more than a dozen telecom operators worldwide — Verizon's Push-to-Talk division among them — before pressuring the companies for payment to keep the stolen data from surfacing publicly.

100 million+
AT&T customer records exposed
Source: KrebsOnSecurity (September 28, 2026)

The entry point was mundane: exposed credentials on customer accounts of the cloud data platform Snowflake that had not enabled multi-factor authentication. Snowflake has since made MFA mandatory across all accounts, but the case is a reminder that a single unenforced control on a third-party data platform can expose customer records at a carrier's scale, not just the vendor's.

The financial mechanics of the case cut against the scale of the breach. AT&T paid the extortion group $370,000 in Bitcoin to keep the stolen data private, according to prosecutors, yet Wagenius personally made roughly $1,500 from selling data before his arrest. The sentencing memo states that despite his limited financial gain, Wagenius "both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government."

$294,978
Restitution ordered at sentencing
Source: KrebsOnSecurity (September 28, 2026)
$370,000
Bitcoin ransom AT&T paid the extortion group
Source: KrebsOnSecurity (September 28, 2026)
~$1,500
Total Wagenius earned selling the stolen data
Source: KrebsOnSecurity, citing DOJ sentencing memo (September 19, 2026)

Exploit requests from behind bars

A sentencing memo filed September 19 by federal prosecutors describes conduct that continued after Wagenius pleaded guilty and while he awaited sentencing. Bureau of Prisons records cited in the memo say Wagenius violated BOP computer-use policy in attempts to learn about vulnerabilities in the bureau's computer systems. Separately, the memo details a broader pattern: several instances in which Wagenius relayed AI queries through other inmates' email accounts, some apparently aimed at software vulnerabilities and others unrelated to any computer network.

Because inmates cannot access AI tools directly, prosecutors say Wagenius worked around the restriction by logging into other prisoners' email accounts and asking outside contacts to relay his questions to a commercial AI system. One message asked the tool to identify privilege-escalation vulnerabilities in Windows 10 Enterprise and produce working exploit scripts for each. Days later, from a different inmate's account, he pushed for a complete walkthrough — functioning code included — for CVE-2023-45208, a three-year-old command-injection flaw in D-Link networking equipment.

The same month, prosecutors say, Wagenius used the same method to ask AI for guidance on building a radio antenna from commissary items to extend reception, and separately to research escaping prison — requests that, unlike the Windows and D-Link queries, do not concern BOP's computer network. Prosecutors say Wagenius framed several of the requests as research for a book he claimed to be writing, a framing they describe as a form of prompt injection intended to get an AI system to output material it would otherwise decline to provide. The government told the court it found no evidence Wagenius used the information against Bureau of Prisons systems.

What this means for security budgets

The case does not turn on a novel technical exploit — the initial breach traces to a well-understood gap, unenforced MFA on a cloud data platform. What is new is the second act: a subject already in custody, cut off from direct computer access, still managing to relay AI queries through intermediaries and disguise intent as fiction or research, with prosecutors saying some of that activity was tied to probing the network of the facility holding him. For organizations building policies around employee and contractor use of AI coding assistants, that is a live pattern to account for, not a hypothetical one.

Questions for your team

Ask your security and IT leadership whether MFA is enforced on every account connected to cloud data platforms your company uses, including contractor, service, and analytics accounts, not just primary employee logins. Ask whether your organization's AI tool usage policies and logging would catch a request for exploit code disguised as research, fiction, or a hypothetical scenario relayed through a third party. Ask how quickly your team could determine, if a former or sidelined insider's credentials or communications were used to solicit technical help against your own systems, whether that activity ever touched production.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Krebs on Security.

CVEs in this analysis
CVE-2023-45208
Share this insight