$370K Bitcoin Ransom Didn't Stop AT&T Leak

$370K Bitcoin Ransom Didn't Stop AT&T Leak
$370,000 in Bitcoin. That's what AT&T reportedly paid an alleged hacker β€” and the data still leaked. A 22-year-old Army private, Cameron Wagenius, was sentenced to 70 months for stealing call metadata on 100M+ AT&T customers. His 'SSH Brute' tool shredded the "defense in depth" brochures. He demanded $500K. AT&T paid $370K. The leak never stopped. The reputational damage only grew. Ransom payouts: a tax on incompetence that keeps the extortion machine funded. πŸ’° When known CVEs and a barracks laptop can strip records from multiple carriers at once, what's really secure? β€” Is your enterprise paying for security theater or actual resilience? πŸ”“

Somewhere in a courtroom hallway last week, a 22-year-old kid who once wore a U.S. Army uniform put his hands behind his back for a 70-month stay in federal custody. His name is Cameron Wagenius. His handle was "kiberphant0m." And his rΓ©sumΓ©, as the feds spelled it out, reads like the plot of a movie nobody greenlit because it was too dumb to be believable.

Wagenius wasn't a mastermind from a shadowy foreign capital. He was an active-duty private first class β€” stationed in South Korea, per the sentencing memo dated September 19, 2026 β€” who built a credential-stealing tool called "SSH Brute," chatted with co-conspirators on Telegram, and got kicked out of the Army for hacking telecoms from his base. Between April 2023 and December 2024, he and his crew burgled at least ten organizations β€” AT&T, Verizon's Push-to-Talk service, Ticketmaster, Advance Auto Parts, Santander, and a bunch of Snowflake customer environments.

The haul: call and text metadata for more than 100 million AT&T customers. The alleged crowning achievement: claimed call logs of then-President-elect Donald Trump and Vice President Kamala Harris, dumped on hacker forums right in the middle of an extortion shakedown.

Here's the part that should make you uncomfortable.

The "Secure" Telecom That Paid Up

Wagenius demanded $500,000 from AT&T. What did AT&T do? It reportedly paid a $370,000 Bitcoin ransom. Not "engaged the FBI first, then paid." It paid. And when it paid, the alleged hacker did what alleged hackers with zero impulse control do: he went right back to threatening and leaking anyway. The feds' own account says he and his alleged accomplice, John Erin Binns, kept the extortion pressure on other carriers β€” including T-Mobile and Verizon β€” through blackmail threats.

So the takeaway, per the corporate playbook, is that paying the ransom is a smart business decision. Let's be honest about what that actually was: a $370,000 investment that (a) did not stop the leak, (b) added reputational damage on top of the breach, and (c) gave future extortionists a very encouraging case study.

The final accounting was grimly comic. Wagenius attempted to extract over $1 million across the campaign and collectively pulled in north of $2.5 million across all victims. The court ordered him to pay restitution of $294,978 β€” a number so far below the damage it borders on performance art.

The Security-Clearance Special

The most galling detail isn't the hacking. It's the clearance. Wagenius held a secret security clearance, which β€” in case you're wondering β€” is nominally supposed to indicate someone trustworthy enough to touch military systems. While in military custody proceedings, he was researching prison escape methods, antenna construction, and NSA schematics. And the Bureau of Prisons version of fun? He violated BOP computer-use policies while incarcerated by probing vulnerabilities in BOP systems using AI prompts. That's the guy who had clearance.

He also leaned hard on AI prompt injection against commercial AI tools and exploited known CVEs β€” including the D-Link command injection bug CVE-2023-45208 and Windows 10 privilege-escalation flaws. None of these were new. None required nation-state resources. A barracks-dwelling private pulled this off with a custom SSH tool, some Telegram threads, and enough audacity to try selling stolen data to a foreign intelligence service.

What This Actually Tells Us

Three things, and none of them flattering.

  1. Enterprises are running on borrowed time. If a soldier with a laptop can strip call records from multiple carriers at once, the "defense in depth" brochures are fiction. The Snowflake ecosystem alone β€” with co-conspirator Connor Riley Moucka tied to more than 165 compromised customer environments β€” is a fire alarm nobody wanted to hear. Wagenius claimed to have hacked more than a dozen telecom companies globally. And lest anyone argue this took nation-state expertise, the threat landscape disagrees: a universal jailbreak prompt surfaced this month scoring an 84–100% success rate across nine of the most vulnerable frontier models, with cyber queries the easiest target at a 47% attack success rate. If a barracks kid can weaponize known CVEs, imagine what an "AI jailbreak," openly reusable across 23 models from seven providers, does for everyone else.
  2. Ransom payments are a tax on incompetence. AT&T paid, got leaked anyway, and still faces regulatory and reputational fallout. The math never works.
  3. Clearance β‰  trust. The FBI, Secret Service, Army CID, and DCIS all got involved precisely because a cleared insider walked straight through the front door β€” and kept probing government networks from a federal cell.

The happy ending for the industry? The investigation is "closed." Wagenius gets 70 months off the streets. Co-conspirators, including John Erin Binns and the Schuchman brothers, are presumably watching their own calendars.

And somewhere, a telecom executive is quietly hoping the next guy with an SSH Brute picks a different carrier.