US National WireUS NATIONAL WIRE
TechOpinion

The 'State-of-the-Art' Lie: How a Single Soldier Exposed Telecoms' Fragility

Portrait of Tobias Lund
Tobias Lundtelecom & connectivitySep 29AI
The 'State-of-the-Art' Lie: How a Single Soldier Exposed Telecoms' Fragility

AI-generated image · US National Wire

Carriers charge us premiums for security, yet a 22-year-old with a hacking tool managed to breach ten organizations and steal hundreds of thousands of records.

OPINION: Every month, we see the surcharges on our bills. The carriers frame these costs as necessary investments in 'state-of-the-art' security and infrastructure. But if you want to know what that money is actually buying, look no further than the case of Cameron John Wagenius.

As The Register first reported, Wagenius, a 22-year-old who carried out a hacking campaign while serving on active duty in the US Army, recently received a 70-month prison sentence for targeting telecommunications companies and other organizations. The details revealed in court documents are a sobering reminder that our critical connectivity infrastructure is often just a playground for anyone with a laptop and a grudge.

Between April 2023 and December 2024, while stationed in Texas and South Korea, Wagenius and three co-conspirators breached the protected networks of at least ten organizations. They didn't use some impossible, futuristic weapon; they used a hacking tool Wagenius helped develop called 'SSH Brute' to obtain login credentials. From there, the group traded hundreds of credentials in Telegram group chats to pivot deeper into victim networks.

The result? The theft of hundreds of thousands of customer records. The Justice Department, as reported by The Register, noted that the group used these records to commit fraud, including SIM swapping—a nightmare scenario for any consumer who trusts their carrier to protect their identity.

Perhaps most damning is the link to the 2024 Snowflake extortion campaign. The Register reports that this campaign affected industry giants Verizon and AT&T. In a brazen display of the vulnerability of these systems, an account controlled by Wagenius claimed to have AT&T call records belonging to Kamala Harris and Donald Trump.

While the carriers brag about their security perimeters, Wagenius and his accomplices were treating sensitive data like a commodity, advertising stolen records on X, Telegram, BreachForums, and XSS. They attempted to extort more than $1 million from their victims, successfully selling some of the data before their capture.

US District Judge Lauren King didn't mince words during sentencing, stating that Wagenius acted out of greed and a desire for notoriety, showing a "shocking disregard" for US safety and security. The court ordered Wagenius to pay $294,978 in restitution.

For the average consumer, the lesson is clear: the 'security' we are paying for is a facade. When a single active-duty soldier can compromise ten organizations and target the records of the highest officials in the land, the carriers' claims of 'state-of-the-art' protection aren't just exaggerations—they are insults.

Sources

More from Tobias Lund