Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteCameron John Wagenius, a former U.S. Army soldier, pleaded guilty on July 15, 2025, to conspiracy to commit wire fraud, extortion in relation to computer fraud, and aggravated identity theft. On September 25, 2026, the Department of Justice reported that he had been sentenced to 70 months in prison and ordered to pay $294,978 in restitution. The DOJ says he conspired to obtain login credentials for protected computer networks and targeted at least 10 organizations between April 2023 and December 18, 2024. Public DOJ releases do not name every victim.
What Wagenius pleaded guilty to
The 2025 plea covered three charges. Two earlier and separate counts are also part of the record. Readers often mix these up, so the distinction matters.
- July 15, 2025: conspiracy to commit wire fraud, extortion in relation to computer fraud, and aggravated identity theft.
- March 5, 2025: two counts of unlawful transfer of confidential phone records information, according to the DOJ, which describes this as a separate guilty plea.
The sentence reported on September 25, 2026 applies to the case as a whole. The DOJ release does not describe the March 2025 counts as a separate sentence, so this article does not attribute a separate penalty to them.
How the alleged scheme worked
According to the DOJ’s case description, Wagenius, then 21, conspired with others to obtain login credentials and use them to reach networks they were not authorized to access. The alleged sequence runs in roughly this order:
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- Credential acquisition. The conspirators used a hacking tool they called SSH Brute, among other methods, to obtain login credentials for protected networks.
- Coordination on Telegram. Group chats on Telegram were used to pass credentials between participants and to discuss unauthorized access.
- Data theft. Once inside, the conspirators stole data. The DOJ does not list every category of stolen data in its releases, and this article does not add categories beyond what the DOJ and reporting describe.
- Extortion. The conspirators threatened to publish stolen data unless paid. The DOJ reports attempted extortion totaling at least $1 million.
- Sale and downstream fraud. Some stolen data was offered for sale on cybercrime forums. The DOJ also says the stolen data was used in other frauds, including SIM-swapping, in which an attacker moves a victim’s phone number to a device the attacker controls.
The DOJ describes the conduct as a campaign, not a single intrusion. The timeline it gives, April 2023 through December 18, 2024, covers all of these steps.
How many victims, and who they were
The DOJ’s figure is a floor. It says “at least 10 victim organizations,” not exactly 10. The count is also not a list of companies. The official release does not identify every victim organization, and the DOJ does not describe all 10 as telecommunications firms. The release does describe the scheme as involving telecommunications companies, so both points should be kept separate.
Rank #2
Specific companies have been linked to the case in secondary reporting. The table below separates what officials have said from what reporters have attributed to others.
| Claim | Source type | Status |
|---|---|---|
| At least 10 victim organizations | U.S. Department of Justice plea release, 2025 | Official aggregate count; not a named list |
| Attempted extortion of at least $1 million | U.S. Department of Justice plea release, 2025 | Official figure for attempted extortion |
| Access to Snowflake customer environments | Secondary reporting | Attributed to reporting; not named in the DOJ release |
| AT&T metadata | Secondary reporting | Attributed to reporting; not named in the DOJ release |
| Verizon Push-to-Talk | Secondary reporting | Attributed to reporting; not named in the DOJ release |
| Phone records tied to political figures | Reuters contemporaneous report | Not confirmed by Reuters; the DOJ refers to records of a government official and of relatives of another former official without naming them |
Treat the company names in the table as reported associations. The DOJ has not used them in its releases, and this article does not treat them as a complete victim list.
Recommended Free Tools
Rank #3
The sentence and restitution
On September 25, 2026, the DOJ reported a sentence of 70 months in prison and $294,978 in restitution. Restitution is money ordered to be paid to victims for losses caused by the crime. The DOJ release does not break down how the $294,978 is divided among victims, so the amount should not be assumed to match the $1 million in attempted extortion.
The DOJ’s sentencing release also cites institutional context. Its Computer Crime and Intellectual Property Section, it says, has secured more than 180 cyber and intellectual property criminal convictions since 2020, and court orders returning more than $350 million in victim funds. These are figures for the section as a whole, not for this case.
Rank #4
What officials said
Three officials spoke in the DOJ’s sentencing release:
- Assistant Attorney General A. Tysen Duva, Criminal Division: “Cameron Wagenius spent more than a year and a half betraying the trust placed in him as an active duty soldier by carrying out a sweeping cybercrime campaign.”
- First Assistant U.S. Attorney Charles Neil Floyd, Western District of Washington: “Mr. Wagenius engaged in a long spree of criminal conduct attempting to blackmail hacking victims for more than $1 million.”
- Assistant Director Brett Leatherman, FBI Cyber Division: “The FBI and its law enforcement partners moved quickly to identify, locate, and arrest Cameron Wagenius, who abused the trust that came with his military service to break into the networks of U.S. telecommunications companies, steal the private records of Americans, and extort victims for profit.”
What this case means for your own accounts
The mechanics in this case, stolen credentials followed by SIM-swapping, are the same ones that affect ordinary account holders. Several protections are worth checking regardless of whether your carrier was involved:
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →- Ask your mobile carrier to add a port-out PIN or account passcode, which makes it harder for someone to transfer your number without your approval.
- Where your bank, brokerage, or email provider offers an app-based or hardware security key option, use it in place of text-message codes.
- Watch for a sudden loss of mobile service, which can signal a SIM swap in progress. Contact your carrier and your financial institutions immediately if it happens.
- If you receive a notice that your personal data was exposed, consider placing a free credit freeze with each of the three nationwide credit bureaus.
These steps do not depend on the outcome of this case. They reduce the risk from the same kind of attack.
Sources: U.S. Department of Justice plea release (2025) and sentencing release (September 25, 2026); Reuters contemporaneous report (2025).
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




