He cleared about $1,500. The stock was the call records of 100 million people.
A 22 year old former US Army soldier was sentenced in Seattle on 25 September to 70 months in federal prison and ordered to pay $294,978 in restitution. Cameron John Wagenius, who went by kiberphant0m online, pleaded guilty to conspiracy to commit wire fraud, extortion in relation to computer fraud, aggravated identity theft and two counts of unlawfully transferring confidential phone records.
The Justice Department says he and his co-conspirators hit at least ten organisations between April 2023 and December 2024, much of it while he was on active duty, and tried to extort at least $1 million. Krebs on Security reports that the haul included call and text metadata for more than 100 million AT&T customers: who rang whom, when, and for how long. Wagenius made roughly $1,500 selling data of that scale.
The break-in was not clever. The group ran a credential-guessing tool called SSH Brute, then walked into cloud storage accounts that had no second factor switched on. No zero-day, no genius. Just usernames and passwords that worked, on accounts nobody had bothered to lock properly.
You cannot make a phone company switch on two-factor authentication, and none of this was your fault. What you can control is the same weakness on your own accounts, because the criminals buying that data use it to sound convincing on the phone. If someone rings claiming to be your bank and knows a number you called last week, that proves nothing. Hang up and call back on the number printed on your card. Tendvane's privacy and accounts check runs through the sign-ins saved on your PC and the account settings behind them, so you can see where you have left a password doing all the work on its own.