Cameron John Wagenius has been sentenced to 70 months in prison for a hacking and extortion scheme that turned stolen telecommunications records into bargaining chips. The U.S. Justice Department announced the sentence on September 25 and said he must pay $294,978 in restitution. The exposed material included confidential records about calls, not their audio — a distinction that did little to remove their value to the criminals.
This is a new court outcome in a case involving activity from April 2023 through December 18, 2024, rather than a newly disclosed breach. Its useful lesson is how access to one organization’s database can become pressure on the people whose lives that database describes.
Credentials opened the door; records became the product
According to DOJ’s account of court documents, Wagenius and his co-conspirators obtained credentials for the protected networks of at least 10 victim organizations. One method involved SSH Brute, a hacking tool he helped develop. They passed stolen credentials through Telegram group chats and discussed access to the companies’ networks while Wagenius was an active-duty Army soldier.
The account describes a sequence with separate stages: obtaining a login, entering a network, taking data, and then finding ways to profit from it. The stolen credentials were the means of entry; the telecommunications records were what the group could threaten to expose or sell. DOJ does not say that every organization was entered by the same method.
In November 2024, Wagenius made two online posts disclosing non-content call records belonging to a government official and relatives of another former official. He threatened to release more unless a ransom was paid. DOJ says one post also suggested retaliation for another cybercriminal’s arrest. Public exposure therefore served both as a threat and as a demonstration that the records were in the attacker’s possession.
A conversation can remain private while its existence does not
“Non-content” describes an important limit: these were records about communications, not a disclosed recording of what someone said. It should not be read as “harmless.” Information connecting people through their communications can reveal relationships a person would prefer to keep private, even when the conversation itself remains unknown.
That is the privacy distinction illustrated by this case. A criminal does not necessarily need the words spoken on a call to make publication damaging. Conversely, a stolen call record does not by itself establish that the criminal can listen to future calls, read every message, or control the subscriber’s handset.
Extortion was only one way to use the stolen data
DOJ says the conspirators tried to extort at least $1 million in total. They also offered stolen data for sale on cybercrime forums, successfully sold some of it, and used stolen information in other frauds, including SIM swapping. That figure is the amount sought through extortion; it is not a statement that $1 million was paid. The restitution order is a separate court outcome, not proof that victims have already received the money.
SIM swapping adds a different risk: an attacker takes control of a phone number by persuading a carrier to move service to another SIM. The FTC explains that this can let the attacker receive calls and text messages, including login codes. That is general background on the technique. DOJ’s announcement does not reconstruct each SIM swap in this case or establish that call logs alone supplied everything needed.
Protect the phone account, not just the handset
The FTC recommends a PIN or password on the cellular account and an authenticator app or security key for sensitive accounts where available. SMS verification can be defeated if an attacker takes over the number. If service unexpectedly disappears or your provider reports a SIM activation you did not request, contact the provider through a known official channel immediately; after regaining the number, change account passwords and check financial accounts for unauthorized activity.
Be equally cautious about someone calling with a convincing story about protecting your assets. Our report on the Coinbase impersonator’s “safe wallet” scheme shows a separate route from a trusted-sounding phone conversation to financial loss. The cases are unrelated; the shared decision is whether the caller’s request has been independently verified.
The sentence closes a stage of the criminal case. It does not erase copies of stolen records. Recovering control of an account and limiting the damage from information already taken are different tasks — and a notice saying call audio was untouched should not make the second one disappear.
References
- U.S. Department of Justice. Former U.S. Soldier Sentenced for Hacking and Extortion Scheme That Exposed Sensitive Data of U.S. Government Official. September 25, 2026.
- Alvaro Puig, Federal Trade Commission. SIM Swap Scams: How to Protect Yourself. Military Consumer, October 23, 2019; accessed September 28, 2026.

