Security

Cyber-crime

US Army soldier who allegedly stole Trump's AT&T call logs arrested

Brings the arrest count related to the Snowflake hacks to 3


A US Army soldier has been arrested in Texas after being indicted on two counts of unlawful transfer of confidential phone records information. 

While the indictment [PDF] doesn't specify any hacking activity or victims' names, Cameron John Wagenius, 20, is suspected of being a cybercriminal known as Kiberphant0m, who claimed to have breached at least 15 telecommunications firms including AT&T and Verizon, according to KrebsOnSecurity.

Wagenius is allegedly an associate of Connor Riley Moucka, one of the men accused of compromising multiple organizations' Snowflake-hosted environments, stealing sensitive customer data housed in the cloud storage service, and then extorting victims for millions of dollars.

Infosec journalist Brian Krebs spoke with Wagenius' mother, Alicia Roen, who said her son worked on radio signals and network communications at an Army base in South Korea.

"I never was aware he was into hacking," Roen said. "It was definitely a shock to me when we found this stuff out."

On November 6, shortly after Moucka's arrest, Kiberphant0m bragged on BreachForums about stealing AT&T call logs for President-elect Donald Trump and for Vice President Kamala Harris. The crook threatened to leak all of the call logs unless AT&T contacted either Kiberphant0m or Reddinton, and signed the post "#FREEWAIFU."

The identity of Reddinton remains unknown.

According to the court documents, on or about November 6, Wagenius did "knowingly and intentionally sell and transfer, and attempt to sell and transfer, confidential phone records information of a covered entity, without prior authorization from the customer to whom such confidential phone records information was obtained fraudulently."

Wagenius appeared in a Texas court on December 20, and federal prosecutors requested his extradition to Washington state, TheDesk reported.

Wagenius' indictment and subsequent arrest bring the number of suspects in the Snowflake data storage hacks to three. In addition to Wagenius and Moucka, who lives and was arrested in Canada, John Erin Binns, an American living in Turkey, was arrested earlier this year and is being held in a Turkish prison.

The Feds unsealed an indictment against Moucka and Binns in November. Both men face 20 counts of conspiracy, computer fraud and abuse, wire fraud, and aggravated identity theft after allegedly breaking into at least 10 organizations' online environments and accessing "billions of sensitive customer records."

Federal prosecutors allege the duo also demanded ransom payments from the victims before ultimately selling the stolen data.

Previous reports indicated digital intruders compromised at least 165 Snowflake customers, including AT&T, Santander Bank, Ticketmaster, and Advance Auto Parts.

The criminals may have ties to Scattered Spider, which Google tracks as UNC3944. Scattered Spider is also believed to be behind the 2023 Las Vegas casino digital heists. ®

Send us news
16 Comments

Charter, Consolidated, Windstream reportedly join China's Salt Typhoon victim list

Slow drip of compromised telecom networks continues

Miscreants 'mass exploited' Fortinet firewalls, 'highly probable' zero-day used

Ransomware 'not off the table,' Arctic Wolf threat hunter tells El Reg

Ransomware crew abuses AWS native encryption, sets data-destruct timer for 7 days

'Codefinger' crims on the hunt for compromised keys

Mitel 0-day, 5-year-old Oracle RCE bug under active exploit

3 CVEs added to CISA's catalog

Chinese cyber-spies peek over shoulder of officials probing real-estate deals near American military bases

Gee, wonder why Beijing is so keen on the – checks notes – Committee on Foreign Investment in the US

Russia's Star Blizzard phishing crew caught targeting WhatsApp accounts

FSB cyberspies venture into a new app for espionage, Microsoft says

China's Salt Typhoon spies spotted on US govt networks before telcos, CISA boss says

We are only seeing 'the tip of the iceberg,' Easterly warns

FBI wipes Chinese PlugX malware from thousands of Windows PCs in America

Hey, Xi: Zài jiàn!

Microsoft sues 'foreign-based' cyber-crooks, seizes sites used to abuse AI

Scumbags stole API keys, then started a hacking-as-a-service biz, it is claimed

Crims backdoored the backdoors they supplied to other miscreants. Then the domains lapsed

Here's what $20 gets you these days

GoDaddy slapped with wet lettuce for years of lax security and 'several major breaches'

Watchdog alleged it had no SIEM or MFA, orders rapid adoption of basic infosec tools

FireScam infostealer poses as Telegram Premium app to surveil Android devices

Once installed, it helps itself to your data like it's a free buffet