LOGO

US Army Soldier Linked to AT&T and Verizon Hacks - DOJ Confirms

January 18, 2025
US Army Soldier Linked to AT&T and Verizon Hacks - DOJ Confirms

Army Soldier Linked to Major Telecom Data Theft

U.S. federal prosecutors have officially established a connection between the December arrest of an active-duty U.S. Army soldier and the extensive theft of phone records from both AT&T and Verizon that occurred last year.

Details of the Arrest

Cameron John Wagenius, identified as a communications specialist within the U.S. Army, was apprehended in Texas on December 20th. This followed a grand jury indictment detailing two charges of illegally transferring confidential phone records. Subsequently, Wagenius was extradited to Washington state to face prosecution.

Connection to Snowflake Hack

A recent court filing revealed that the charges against Wagenius are directly related to the earlier indictments of Connor Moucka and John Binns. These individuals are accused by the U.S. government of orchestrating multiple intrusions into Snowflake, a cloud computing company.

These intrusions resulted in the large-scale theft of data belonging to Snowflake’s customers. Notably, AT&T experienced the exfiltration of “nearly all” of its customer call records through 2024 from its Snowflake account, while Verizon suffered a substantial loss of customer call logs.

Overlapping Evidence and Legal Considerations

U.S. Attorney Tessa Gorman informed the Seattle court that both cases stem from the same computer intrusion and extortion attempt. Furthermore, the cases share stolen victim information.

Gorman stated that the cases utilize overlapping evidence and legal procedures, and likely involve common legal questions and factual issues.

Public Acknowledgment of the Link

This marks the first official confirmation from prosecutors that Wagenius’ charges are linked to the breaches at Snowflake last year. Security journalist Brian Krebs initially reported on this connection in November, and subsequently announced Wagenius’ arrest.

Widespread Impact of the Snowflake Hacks

The Snowflake account compromises represent one of the most significant cyberattacks of the past year. The attack impacted a wide range of organizations, including AT&T, LendingTree, Santander Bank, and Ticketmaster, as well as at least 160 other companies.

Hackers reportedly stole vast amounts of personally identifiable information and sensitive corporate data stored within Snowflake. This was achieved, in part, through the use of malware to steal employee passwords.

A significant factor contributing to the success of the attacks was the lack of multi-factor authentication among many Snowflake customers, a security measure that was not mandated by Snowflake at the time.

Wagenius’ Claims and Extortion Attempt

Following the arrest of Moucka by Canadian authorities, Wagenius allegedly posted on a cybercrime forum claiming access to the call logs of Vice President Kamala Harris and President-elect Donald Trump.

He reportedly threatened to release all stolen files if Moucka was not freed.

Data Compromised in the Hack

Prosecutors allege that the stolen data includes a wide array of sensitive information, such as:

  • Personal information
  • Cell phone and IMEI numbers
  • Dates of birth
  • Postal and email addresses
  • Passwords
  • Social Security numbers
  • Government-issued identity numbers
  • Payment card and bank account numbers

Current Status

Wagenius was ordered to be detained on January 8th and remains in custody in Washington state.