Full Report
Cameron Wagenius was involved in some of the most high-profile attacks of 2024 while on active duty. The post Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies appeared first on CyberScoop.
Analysis Summary
# Incident Report: Multi-Victim Extortion Campaign (Wagenius & Snowflake Spree)
## Executive Summary
Cameron John Wagenius, a former active-duty U.S. Army soldier, was sentenced to 70 months in prison for his role in a massive 2024 cybercrime and extortion spree targeting AT&T, Ticketmaster, and other major corporations. Collaborating with high-profile threat actors, Wagenius exploited stolen credentials to breach cloud environments, exfiltrating billions of records and attempting to sell sensitive data to foreign intelligence services. The campaign resulted in over $2.5 million in total extortion payments across the conspiracy group and significant operational and reputational damage to affected global enterprises.
## Incident Details
- **Discovery Date:** December 2024 (Arrest of Wagenius)
- **Incident Date:** Ongoing through 2024 (Peak activity April – July 2024)
- **Affected Organizations:** AT&T, Ticketmaster, Advance Auto Parts, Santander, and 165+ Snowflake customers.
- **Sector:** Telecommunications, Entertainment, Retail, Financial Services.
- **Geography:** Global (Primary victims in United States and Canada).
## Timeline of Events
### Initial Access
- **Date/Time:** Early 2024 – April 2024.
- **Vector:** Credential Stuffing / Stolen Credentials.
- **Details:** Attackers used stolen credentials to access Snowflake cloud environments that lacked Multi-Factor Authentication (MFA). Wagenius also utilized a self-developed tool called "SSH Brute" to harvest credentials.
### Lateral Movement
- **Details:** Once inside the Snowflake cloud environments, attackers moved across various customer databases to identify and aggregate sensitive data tables containing PII and call records.
### Data Exfiltration/Impact
- **Details:** Stole six months of phone/text metadata for "nearly all" AT&T customers; exfiltrated billions of sensitive records from over 10 major organizations. Wagenius specifically leaked call records of high-level government officials.
### Detection & Response
- **Detection:** AT&T confirmed the breach in July 2024 following the wider Snowflake environment compromise reports.
- **Response:** FBI investigation led to the arrest of Wagenius in December 2024 and the extradition of co-conspirator Connor Moucka from Canada in March 2025.
## Attack Methodology
- **Initial Access:** Credential theft via "SSH Brute" tool and utilization of previously leaked credentials.
- **Persistence:** Maintaining access through compromised cloud service accounts.
- **Privilege Escalation:** Not explicitly detailed, but involved accessing administrative tiers of cloud databases.
- **Defense Evasion:** Targeting cloud environments lacking MFA.
- **Credential Access:** Brute-forcing and credential stuffing.
- **Discovery:** Reconnaissance of victim cloud platforms (Snowflake).
- **Lateral Movement:** Database-to-database hopping within shared cloud service providers.
- **Collection:** Gathering call detail records (CDRs) and customer PII.
- **Exfiltration:** Large-scale data transfers from cloud storage.
- **Impact:** Extortion (demanding over $1M in specific cases) and public leaking of data to damage reputations.
## Impact Assessment
- **Financial:** Over $2.5 million paid in total extortions by various victims; Wagenius ordered to pay $295,000 in restitution.
- **Data Breach:** Billions of records stolen; PII of "nearly all" AT&T customers; sensitive government official call logs.
- **Operational:** Significant disruption to cloud security postures and emergency incident response for 165+ companies.
- **Reputational:** High-profile public exposure of data; betrayal of trust by an active-duty service member.
## Indicators of Compromise
- **Network indicators:** Connections to known Snowflake administrative endpoints from unauthorized non-corporate IP ranges.
- **File indicators:** Presence and execution of "SSH Brute" hacking tool.
- **Behavioral indicators:** Unusual volume of data egress from cloud environments; logins from IPs associated with known VPN/proxy services used by "kiberphant0m."
## Response Actions
- **Containment:** Revocation of compromised credentials; implementation of MFA across affected Snowflake environments.
- **Eradication:** Law enforcement seizure of Wagenius’ devices and arrest of key conspirators.
- **Recovery:** Restoration of secure cloud configurations and mandatory password resets.
## Lessons Learned
- **MFA is Mandatory:** The lack of Multi-Factor Authentication on critical cloud infrastructure was the primary enabler of this spree.
- **Insider Threat Complexity:** Active-duty personnel with technical skills can pose a significant "off-duty" risk to national infrastructure.
- **Supply Chain Vulnerability:** A single third-party cloud provider (Snowflake) can be the gateway to hundreds of downstream corporate victims.
## Recommendations
- **Enforce MFA:** Mandate hardware-based or phishing-resistant MFA for all cloud administrative accounts.
- **Credential Monitoring:** Implement automated alerts for logins originating from known "leaked credential" databases.
- **Zero Trust Architecture:** Limit the scope of data access within cloud environments to prevent one compromised account from accessing billions of records.
- **Egress Monitoring:** Set thresholds for data exfiltration to trigger immediate account lockout.