Executive Summary
Former Army soldier Cameron John Wagenius was sentenced to 70 months in prison for orchestrating a multi-year cybercrime campaign targeting major companies including AT&T, Ticketmaster, and Santander. Operating under aliases 'kiberphant0m' and 'cyb3rph4nt0m,' Wagenius collaborated with Connor Moucka to compromise over 165 Snowflake customer environments, stealing billions of records and attempting to extort over $1 million from victims. The breach exposed call detail records of high-profile government officials and resulted in the theft of nearly all AT&T customer phone and text records spanning six months. This case highlights the growing threat of insider compromise and the vulnerability of cloud infrastructure, particularly as organizations increasingly rely on third-party cloud platforms for sensitive data storage. The incident underscores the critical need for enhanced access controls, comprehensive monitoring, and zero-trust security architectures to prevent credential-based attacks and lateral movement.
Why This Matters Now
This incident demonstrates the evolving threat landscape where trusted insiders exploit cloud vulnerabilities at unprecedented scale, making robust identity verification and continuous monitoring essential for preventing similar multi-billion record breaches.
Attack Path Analysis
Cameron Wagenius and co-conspirators used SSH Brute tool to steal credentials from cloud platforms including Snowflake environments. They gained unauthorized access to over 165 Snowflake customer environments, moved laterally across cloud databases, maintained persistent access while exfiltrating billions of sensitive records including AT&T call detail records, and conducted extortion campaigns against multiple major organizations for over $2.5 million in payments.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers used SSH Brute tool to conduct credential stuffing attacks against Snowflake customer environments and cloud platforms, exploiting weak authentication controls
MITRE ATT&CK® Techniques
Password Spraying
Valid Accounts
Exfiltration to Cloud Storage
Data Encrypted for Impact
Virtual Private Server
Phishing
Exfiltration to Code Repository
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Cryptography for Authentication Credentials
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – ICT Third-Party Risk Management
Control ID: Article 11
CISA ZTMM 2.0 – Identity Credential and Access Management
Control ID: 2.1.4
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001 – Handling of Assets
Control ID: A.8.2.3
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Direct victim of data theft targeting AT&T's call records and cloud platforms, exposing customer communications data requiring enhanced egress security and encrypted traffic protection.
Government Administration
High-risk exposure as government officials' call records were compromised, demonstrating need for zero trust segmentation and threat detection across sensitive communications infrastructure.
Financial Services
Vulnerable to similar Snowflake cloud environment attacks targeting customer data for extortion, requiring multicloud visibility and anomaly detection to prevent data exfiltration.
Information Technology/IT
Critical infrastructure risk from cloud platform compromises affecting multiple organizations, necessitating enhanced Kubernetes security and cloud firewall protection against credential theft attacks.
Sources
- Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companieshttps://cyberscoop.com/cameron-wagenius-att-snowflake-attacks-sentenced/Verified
- Justice Department Announces 70-Month Sentence for Former Army Soldier in Cybercrime Campaignhttps://www.justice.gov/opa/pr/justice-department-announces-70-month-sentence-former-army-soldier-cybercrime-campaignVerified
- AT&T Data Breach Notificationhttps://about.att.com/pages/cyberattackVerified
- Snowflake Security Incident Updatehttps://www.snowflake.com/blog/snowflake-security-incident-update/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have constrained the SSH brute force attack's reach across cloud environments and limited lateral movement between the 165+ compromised Snowflake databases through workload segmentation and east-west traffic controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Identity-aware access controls would likely have reduced the attack surface by limiting credential reuse across cloud environments and constraining the scope of successful brute force attempts against database platforms.
Control: Zero Trust Segmentation
Mitigation: Workload-level segmentation would likely have constrained privilege escalation by limiting the scope of access granted to compromised credentials and reducing their ability to reach sensitive database repositories.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have significantly reduced the blast radius by constraining inter-database communication paths and limiting the attackers' ability to pivot between the 165+ customer environments.
Control: Multicloud Visibility & Control
Mitigation: Centralized multicloud visibility would likely have detected anomalous access patterns and constrained persistent connections by identifying unusual VPN-based communications across the distributed cloud infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: Egress controls would likely have constrained the volume and scope of data exfiltration by limiting outbound data flows and restricting unauthorized transfers of sensitive records from cloud database environments.
While extortion activities would likely still occur, the reduced scope of compromised data and constrained access to customer environments would limit the attackers' leverage and reduce the overall financial impact on affected organizations.
Impact at a Glance
Affected Business Functions
- Customer Communications Services
- Telecommunications Infrastructure
- Data Privacy and Security
- Customer Service Operations
Estimated downtime: N/A
Estimated loss: $2,500,000
Massive data breach affecting multiple major companies including AT&T (6 months of phone and text records for nearly all customers including call detail records of government officials), Ticketmaster, Advance Auto Parts, and Santander. Billions of sensitive records stolen including customer PII, call metadata, and corporate data across 165+ Snowflake customer environments.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies and least privilege access controls to prevent lateral movement across cloud environments and limit blast radius of compromised credentials
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound data flows, preventing unauthorized exfiltration to external destinations and blocking shadow AI communications
- • Enable Multicloud Visibility & Control with centralized policy management and traffic observability to detect anomalous interactions and suspicious automation across cloud platforms
- • Implement Encrypted Traffic controls with MACsec and IPsec to protect data in transit and prevent interception of sensitive communications during exfiltration attempts
- • Deploy Threat Detection & Anomaly Response capabilities to baseline normal behavior and detect covert tools, remote access patterns, and unauthorized credential usage in real-time



