Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

Telecom hacks exposed call records. What a US sentence tells users and businesses

A former soldier was sentenced for hacking, data theft and extortion. We explain why call history is sensitive and how to protect telecom accounts.

PUBLIC RESEARCH
AUTHOR
/ CEO Breachroad · OSCP · PNPT
PUBLISHED
26 September 2026
READING TIME
9 min read
TOPIC
Threats and Incidents
Telecom hacks exposed call records. What a US sentence tells users and businesses

Former US Army soldier Cameron John Wagenius has been sentenced to 70 months in prison and ordered to pay $294,978 in restitution for taking part in a campaign that hacked telecommunications databases, stole confidential data and demanded ransoms. According to the Department of Justice, the conspirators attempted to extort at least $1 million from data owners.

The case draws attention to a type of information that is often incorrectly treated as less sensitive than the content of a conversation. The exposed records were call metadata, not recordings or message content. Such records can nevertheless help reveal a person’s network of contacts and patterns of communication. The precise fields vary between carrier systems.

What the court and prosecutors established

According to court documents described by the DOJ, Wagenius and his co-conspirators obtained login credentials for the protected networks of at least ten organisations between April 2023 and 18 December 2024. Their methods included a tool called SSH Brute that Wagenius helped develop.

They transferred stolen credentials in Telegram group chats and discussed access to victim networks. After stealing data, they threatened organisations with publication, offered some information for sale and used stolen data for further fraud, including SIM swapping.

In November 2024, Wagenius published confidential call-detail records belonging to a government official and family members of another former official, and threatened to disclose more. He was on active Army duty during the campaign. He had previously pleaded guilty to offences involving wire-fraud conspiracy, computer-related extortion, aggravated identity theft and unlawful transfer of confidential phone-record information.

Metadata is not “just a technical trace”

The content of a call answers what was said. Call history can answer different questions: who contacted whom, when and how often. Combined with public information, it may reveal professional relationships, family connections, journalistic sources or the moment when a person reacted to a particular event.

Not every record contains the same fields, so it would be wrong to assume that the database in this case held location, SMS content or recordings. Information should not, however, be dismissed simply because it is “non-content.” Its sensitivity also comes from the pattern that can be reconstructed.

For a fraudster, call records can support a convincing impersonation. Knowledge of a carrier, recent contact or support process can make a story sound credible to a customer or service agent.

What an ordinary phone user can do

Sign in to the carrier account only through the official app or a manually entered address. Review contact details, services, additional numbers and recent changes. Set a strong, unique password and enable the strongest available authentication method.

Ask the carrier about an additional account-support passcode, number-transfer lock or another safeguard against an unauthorised replacement SIM. Names and availability differ between countries and carriers. Do not treat an SMS code as complete protection because a number takeover can bypass that very layer.

If the phone suddenly loses service without an obvious outage, contact the carrier from another device. At the same time, check email, banking and important accounts, particularly where the number is used for recovery. Do not confirm information to a caller merely because they know details of the subscription. End the call and return to the carrier through an official channel.

What carriers and business customers should control

Access to subscriber information and call records needs a defined purpose, limited scope and audit trail. Administrator, service and supplier accounts require separate controls, short-lived privileges and alerts for bulk access or export.

Protecting the customer portal is not enough if a support agent can replace a SIM or recovery data based on easily available information. The process should combine identity verification, a risk assessment of the requested change and a notification through the old channel. Accounts belonging to people at heightened risk need a higher approval threshold.

A business customer should maintain an inventory of corporate numbers used for MFA and account recovery. A departing employee’s number, dormant subscription or phone assigned to a shared mailbox can remain part of a critical process long after ownership changes.

An incident review must cover more than leaked records. Stolen credentials can open other systems, while a hijacked number can enable password resets. The response team should map dependencies between the carrier, email, banking, cloud platforms and privileged accounts.

Do not mistake the sentence for a complete account of every harm

The sentence establishes the offender’s responsibility in the case described. The release does not name every carrier or every person whose information was compromised. Nor does it mean that every telecommunications user is currently being targeted by the same group.

The practical conclusion is broader: telecom data is valuable, and a carrier account can be part of the sign-in system for many other services. Protecting a number and its metadata cannot end with setting a PIN on the handset itself.

Source facts and Breachroad’s conclusions

The US Department of Justice provides the sentence, restitution amount, count of at least ten victim organisations, campaign period, use of stolen credentials, extortion, data sales and SIM swapping. It explicitly describes the disclosed information as non-content call-detail records.

The assessment of metadata risk, user checklist, and recommendations on access control, customer support and dependency mapping are Breachroad’s conclusions. Specific safeguards must be confirmed with the relevant carrier. Our guides provide more detail on SIM-swapping and number takeover and identity-theft protection. Organisations can rehearse caller verification through cybersecurity awareness training.

SHARE / COPY