Back to Intelligence

Soldier-Turned-Extortionist Sentenced to 70 Months: Defending Tech and Telecom Firms Against Credential-Driven Data Extortion

SA
Security Arsenal Team
September 28, 2026
13 min read

A former U.S. Army soldier has been sentenced to 70 months in federal prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024. The case is a sobering reminder that the most damaging intrusions we respond to rarely involve exotic zero-days — they involve valid credentials, poorly governed cloud data platforms, and organizations that never detect the theft until the extortion email arrives.

This campaign fits the pattern we have seen repeatedly in the Snowflake-related data theft wave and the broader surge of extortion-only intrusions: attackers log in rather than break in, quietly stage and exfiltrate bulk data, then monetize through direct extortion and underground forum sales. For defenders at technology and telecom firms — and frankly any organization holding bulk customer records — the question is not whether your credentials are being tested right now. It is whether you would see the login, the bulk query, and the egress before the ransom note.

This post breaks down the tradecraft behind this campaign from a defender's perspective and delivers concrete detection and hardening guidance your SOC can deploy this week.

Technical Analysis: How Credential-Driven Extortion Campaigns Work

Threat Overview

The defendant operated under the handle "kiberphant0m" and was linked to intrusions against technology and telecommunications providers, including activity associated with the wider cluster of intrusions targeting cloud data warehouse customers. The campaign ran roughly 20 months — a dwell time that tells you everything about the state of detection at the victim organizations.

No CVE is associated with this campaign. That is the point. The attack chain relies on weaknesses in identity and access governance, not software vulnerabilities:

  1. Initial access via valid credentials (MITRE ATT&CK T1078). Credentials are harvested from infostealer malware logs (Raccoon, Vidar, RedLine), purchased from initial access brokers, or obtained via phishing and SIM-swapping against telecom employees. Telecom staff are disproportionately targeted because of their access to subscriber data and internal support tooling.
  2. Access to cloud data platforms (T1530 — Data from Cloud Storage). Single-factor SaaS accounts for platforms like Snowflake, Salesforce, and internal admin panels are abused. In the 2024 Snowflake campaign, the common thread was customer accounts without MFA and credentials sitting in infostealer logs, sometimes for years.
  3. Bulk data discovery and collection (T1213, T1530). Attackers run large SELECT queries against customer PII tables, call detail records (CDRs), and subscriber databases — often exporting millions of rows via the platform's native export or COPY INTO <stage> functionality.
  4. Exfiltration (T1567 — Exfiltration Over Web Service). Data is staged and pushed to attacker-controlled cloud storage (MEGA, Backblaze B2, or external S3-compatible buckets) using tools such as rclone, or pulled directly through the SaaS provider's own export features over TLS — blending into normal traffic.
  5. Extortion (T1657 — Financial Extortion). Victims receive demands with samples posted to criminal forums such as BreachForums successors. Payment is demanded in cryptocurrency; non-payment leads to public leaks or sale.

Why Telecom and Tech Firms Are the Target

Telecom providers hold a uniquely valuable data combination: subscriber PII, call detail records, and — critically — the infrastructure that enables SIM-swapping (T1078/T1656) for downstream attacks against other victims. Technology firms hold source code, API keys, and customer datasets that resell well. An actor with military communications training targeting telecom infrastructure should sharpen every defender's attention: this is someone who understands exactly which systems matter.

Exploitation Status

This is not theoretical. The campaign resulted in confirmed breaches at a minimum of 10 organizations, successful extortion payments, and a federal conviction. The associated tradecraft cluster remains active in 2025–2026, with infostealer-derived credential markets continuing to supply valid sessions for major SaaS platforms. Treat this TTP set as an active, ongoing threat to your organization, not a closed case.

Detection & Response

The detections below target the observable behaviors of this campaign class: anomalous SaaS sign-ins, bulk cloud data access, exfiltration tooling on endpoints, and staging activity. They are tuned to be useful in a production SOC — but as always, baseline against your own environment before raising to high severity.

Sigma Rules

YAML
---
title: Rclone Execution With Cloud Exfiltration Configuration
id: 3f7a2c91-8b4d-4e5a-9c6f-1a2b3c4d5e6f
status: experimental
description: Detects execution of rclone with copy/sync/move commands or remote configuration flags, a common exfiltration pattern in data theft extortion campaigns where stolen data is pushed to attacker-controlled cloud storage.
references:
  - https://attack.mitre.org/techniques/T1567/002/
  - https://www.bleepingcomputer.com/news/security/us-soldier-gets-70-months-in-prison-for-extorting-10-tech-telecom-firms/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.exfiltration
  - attack.t1567.002
logsource:
  category: process_creation
  product: windows
detection:
  selection_binary:
    Image|endswith: '\rclone.exe'
    OriginalFileName: 'rclone.exe'
  selection_args:
    CommandLine|contains:
      - ' copy '
      - ' sync '
      - ' move '
      - 'config create'
      - '--config'
      - 'mega:'
      - 'b2:'
      - 's3:'
  condition: selection_binary and selection_args
falsepositives:
  - Legitimate backup administrators using rclone for sanctioned backup jobs - whitelist by approved destination remote and service account
level: high
---
title: Compressed Archive Staging In User-Writable Directories
id: 8e1b4d72-6a3c-4f2b-b8d9-2c3d4e5f6a7b
status: experimental
description: Detects creation of large archive or database export files in user temp/profile directories, consistent with data staging prior to exfiltration in extortion intrusions.
references:
  - https://attack.mitre.org/techniques/T1560/001/
  - https://attack.mitre.org/techniques/T1074/001/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.collection
  - attack.t1074.001
  - attack.t1560.001
logsource:
  category: file_event
  product: windows
detection:
  selection_path:
    TargetFilename|contains:
      - '\AppData\Local\Temp\'
      - '\AppData\Roaming\'
      - 'C:\Users\Public\'
      - '\Downloads\'
  selection_ext:
    TargetFilename|endswith:
      - '.7z'
      - '.rar'
      - '.zip'
      - '.csv'
      - '.sql'
      - '.bak'
      - '.dump'
  filter_browsers:
    Image|endswith:
      - '\chrome.exe'
      - '\msedge.exe'
      - '\firefox.exe'
  condition: selection_path and selection_ext and not filter_browsers
falsepositives:
  - Developers exporting datasets locally - tune with per-user baselines and expected export schedules
  - IT backup agents writing to public directories
level: medium
---
title: Infostealer-Style Browser Credential Store Access
id: 5c2d9e18-4f7a-4b6c-a1d3-9e8f7a6b5c4d
status: experimental
description: Detects suspicious processes reading browser credential and cookie stores, a common source of the valid SaaS credentials used in credential-driven extortion campaigns.
references:
  - https://attack.mitre.org/techniques/T1555/003/
  - https://attack.mitre.org/techniques/T1539/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.credential_access
  - attack.t1555.003
  - attack.t1539
logsource:
  category: file_event
  product: windows
detection:
  selection:
    TargetFilename|contains:
      - '\Google\Chrome\User Data\Default\Login Data'
      - '\Google\Chrome\User Data\Default\Cookies'
      - '\Google\Chrome\User Data\Local State'
      - '\Microsoft\Edge\User Data\Default\Login Data'
      - '\BraveSoftware\Brave-Browser\User Data\Default\Login Data'
  filter_legit:
    Image|endswith:
      - '\chrome.exe'
      - '\msedge.exe'
      - '\brave.exe'
      - '\MsMpEng.exe'
      - '\svchost.exe'
  condition: selection and not filter_legit
falsepositives:
  - EDR and DLP agents scanning credential stores - whitelist your deployed security tooling by full path and signer
  - Enterprise backup agents
level: high

KQL — Microsoft Sentinel / Defender

These queries hunt the campaign's two most reliable signals: anomalous SaaS sign-ins from infostealer-risk sources, and endpoint exfiltration behavior. The first uses SigninLogs (Entra ID) combined with bulk Snowflake-style query activity ingested via custom logs; the second hunts the endpoint directly.

KQL — Microsoft Sentinel / Defender
// Hunt 1: Anomalous SaaS/cloud data platform sign-ins with impossible travel or new ASN,
// correlated to bulk data export activity (Snowflake COPY INTO / large result sets ingested via custom connector)
let lookback = 14d;
let SuspiciousSignins =
    SigninLogs
    | where TimeGenerated > ago(lookback)
    | where ResultType == 0
    | where AppDisplayName has_any ("Snowflake", "Salesforce", "Okta", "Internal Admin")
        or AppDisplayName has_any ("Snowflake", "Salesforce")
    | extend NewCountry = iff(LocationDetails.countryOrRegion != "US", true, false)
    | summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated),
                IPs=make_set(IPAddress), Countries=make_set(LocationDetails.countryOrRegion),
                UserAgents=make_set(UserAgent), Apps=make_set(AppDisplayName)
        by UserPrincipalName, bin(TimeGenerated, 1d)
    | where array_length(Countries) > 1 or NewCountry == true;
SuspiciousSignins
| project UserPrincipalName, TimeGenerated, IPs, Countries, Apps, UserAgents
| sort by TimeGenerated desc;

// Hunt 2: Endpoint exfiltration tooling - rclone/mega processes and mass file reads of data stores
DeviceProcessEvents
| where TimeGenerated > ago(7d)
| where FileName has_any ("rclone.exe", "megacmd.exe", "megasync.exe", "winscp.exe", "filezilla.exe")
   or ProcessCommandLine has_any ("rclone copy", "rclone sync", "rclone move", "mega:", "b2:")
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine,
          FolderPath, SHA256, InitiatingProcessFileName
| sort by TimeGenerated desc;

// Hunt 3: High-volume egress from workstations/servers to uncommon cloud storage destinations
DeviceNetworkEvents
| where TimeGenerated > ago(7d)
| where RemoteUrl has_any ("mega.nz", "mega.co.nz", "backblazeb2.com", "file.io", "transfer.sh", "temp.sh")
    or RemoteIP in (dynamic(["66.203.125.0/24"]))  // extend with your TI feed of anonymous upload services
| summarize Connections=count(), BytesSentApprox=count()*1, RemoteIPs=make_set(RemoteIP),
            RemoteUrls=make_set(RemoteUrl)
    by DeviceName, InitiatingProcessFileName, InitiatingProcessAccountName, bin(TimeGenerated, 1h)
| where Connections > 50
| sort by Connections desc;

Tune Hunt 1 to your actual SaaS estate and expected geographies. If your workforce is distributed, drop the country filter and pivot on new-ASN-plus-new-user-agent combinations instead — that pairing fires rarely and catches proxy-based logins well.

Velociraptor VQL

For DFIR triage on a suspected compromised host, this artifact pulls the two highest-value artifacts in one sweep: exfiltration tool execution and staging artifacts in user-writable paths.

VQL — Velociraptor
-- Hunt for exfiltration tooling execution and staged data archives
-- Deploy as a hunt across servers and admin workstations, or run targeted on a suspect host
LET exfil_procs = SELECT Pid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ '(?i)rclone|megacmd|megasync|winscp|filezilla'
   OR Exe =~ '(?i)rclone\.exe|megacmd'

LET staged_data = SELECT FullPath, Size, Mtime, Btime
FROM glob(globs=[
  'C:/Users/*/AppData/Local/Temp/*.7z',
  'C:/Users/*/AppData/Local/Temp/*.rar',
  'C:/Users/*/AppData/Local/Temp/*.zip',
  'C:/Users/*/Downloads/*.7z',
  'C:/Users/*/Downloads/*.rar',
  'C:/Users/Public/*.zip',
  'C:/Users/Public/*.7z',
  'C:/Users/*/Desktop/*.csv'
])
WHERE Size > 50000000
  AND Mtime > now() - 1209600

SELECT * FROM exfil_procs
UNION ALL
SELECT NULL AS Pid, 'STAGED_FILE' AS Name,
       format(format='size=%d mtime=%s', args=[Size, Mtime]) AS CommandLine,
       FullPath AS Exe, NULL AS Username, Btime AS CreateTime
FROM staged_data

Complement this with Velociraptor's Windows.Forensics.Prefetch artifact to establish execution timeline for any rclone binaries found — Prefetch will confirm first-run time even if the binary was deleted after exfiltration.

Remediation and Hardening Script

This PowerShell script verifies the highest-impact controls for this threat class on Windows endpoints and Entra ID: MFA coverage, legacy auth status, browser credential protection, and exfil tool detection. Run it as an audit baseline, then schedule weekly.

PowerShell
#Requires -RunAsAdministrator
# Security Arsenal - Credential-Driven Extortion Hardening Audit
# Run on endpoints + connect to Entra for identity checks

Write-Host "=== [1/5] Entra ID: Identifying users WITHOUT MFA registered ===" -ForegroundColor Cyan
# Requires Microsoft.Graph module: Install-Module Microsoft.Graph -Scope CurrentUser
try {
    Connect-MgGraph -Scopes "User.Read.All","UserAuthenticationMethod.Read.All" -NoWelcome
    $noMfa = Get-MgUser -All -Property "Id,UserPrincipalName,AccountEnabled" |
        Where-Object { $_.AccountEnabled -eq $true } | ForEach-Object {
            $methods = Get-MgUserAuthenticationMethod -UserId $_.Id
            if (($methods | Measure-Object).Count -lt 2) { $_.UserPrincipalName }
        }
    if ($noMfa) {
        Write-Host "[!] Accounts lacking MFA - REMEDIATE IMMEDIATELY (SaaS + cloud data platforms):" -ForegroundColor Red
        $noMfa | ForEach-Object { Write-Host "    $_" }
    } else { Write-Host "[+] All enabled accounts have multiple auth methods registered." -ForegroundColor Green }
} catch { Write-Host "[-] Graph query failed - verify module and permissions: $($_.Exception.Message)" -ForegroundColor Yellow }

Write-Host "`n=== [2/5] Checking for exfiltration tooling on this host ===" -ForegroundColor Cyan
$exfilPaths = @("$env:ProgramFiles\rclone","$env:LOCALAPPDATA\rclone","$env:USERPROFILE\Downloads\rclone*")
$found = Get-ChildItem -Path $exfilPaths -Recurse -ErrorAction SilentlyContinue
if ($found) {
    Write-Host "[!] Suspicious exfil tooling found - investigate origin:" -ForegroundColor Red
    $found | Select-Object FullName, CreationTime, Length | Format-Table -AutoSize
} else { Write-Host "[+] No rclone/mega tooling detected in common paths." -ForegroundColor Green }

Write-Host "`n=== [3/5] Verifying Windows Defender Credential Guard & browser credential protection ===" -ForegroundColor Cyan
$cg = Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard -ErrorAction SilentlyContinue
if ($cg.SecurityServicesRunning -contains 1) {
    Write-Host "[+] Credential Guard is RUNNING (protects LSA credential material)." -ForegroundColor Green
} else {
    Write-Host "[!] Credential Guard NOT running. Enable via GPO or Intune:" -ForegroundColor Red
    Write-Host "    Set-ItemProperty HKLM:\SYSTEM\CurrentControlSet\Control\Lsa -Name LsaCfgFlags -Value 1"
}

Write-Host "`n=== [4/5] Enabling attack surface reduction: block credential theft from LSASS ===" -ForegroundColor Cyan
Set-MpPreference -AttackSurfaceReductionRules_Ids 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2 `
                 -AttackSurfaceReductionRules_Actions Enabled
Write-Host "[+] ASR rule 'Block credential stealing from LSASS' enforced." -ForegroundColor Green

Write-Host "`n=== [5/5] Auditing recent bulk archive creation in user profiles (last 7 days) ===" -ForegroundColor Cyan
$archives = Get-ChildItem "C:\Users" -Include *.7z,*.rar,*.zip -Recurse -ErrorAction SilentlyContinue |
    Where-Object { $_.Length -gt 50MB -and $_.LastWriteTime -gt (Get-Date).AddDays(-7) }
if ($archives) {
    Write-Host "[!] Large recent archives - validate business justification:" -ForegroundColor Yellow
    $archives | Select-Object FullName, @{N='SizeMB';E={[math]::Round($_.Length/1MB)}}, LastWriteTime | Format-Table -AutoSize
} else { Write-Host "[+] No large staging archives detected." -ForegroundColor Green }

Write-Host "`nAudit complete. Forward findings to your SIEM correlation owner." -ForegroundColor Cyan

Remediation: Closing the Doors This Actor Walked Through

There is no patch for stolen credentials — but there is a well-defined control set that makes this exact campaign class fail. Prioritize in this order:

1. Enforce Phishing-Resistant MFA on All Cloud Data Platforms — This Week

Every single-factor SaaS account in your estate is a standing invitation. Mandate MFA on Snowflake, Salesforce, admin panels, VPN, and SSO — ideally FIDO2/passkeys or certificate-based auth. For Snowflake specifically, enforce MFA at the account level, set NETWORK_POLICY to restrict source IPs, and rotate any credential that has ever touched a developer workstation running consumer software. Audit for service accounts with interactive login rights — infostealer logs are full of them.

2. Kill the Infostealer Pipeline

Deploy and tune detections for browser credential store access (Sigma rule above). Enforce LSASS protection and Credential Guard via the provided script. Block execution of unsigned binaries from user-writable paths via AppLocker or WDAC. Subscribe your SOC to infostealer log monitoring services (e.g., credential exposure feeds) so you learn your employees' credentials were stolen before an actor uses them — this single capability has prevented more extortion events in our IR casework than any EDR feature.

3. Detect the Theft, Not Just the Breach

Bulk export is the one step the attacker cannot skip. Enable and centralize audit logging on every data platform: Snowflake ACCESS_HISTORY and QUERY_HISTORY, Salesforce Event Monitoring, and equivalent SaaS telemetry into your SIEM. Alert on queries returning row counts or byte volumes above baseline, COPY INTO statements against external stages, and exports initiated outside business hours from new ASNs. The KQL hunts above give you the endpoint and egress side; the platform-side query-volume alerting is the other half.

4. Telecom-Specific Hardening

If you operate telecom infrastructure: enforce strict role-based access to subscriber data and CDR systems, log and alert on bulk subscriber lookups by support staff, mandate phishing-resistant MFA for all OSS/BSS access, and run insider-threat analytics on call record access patterns. This actor chose telecom targets deliberately — subscriber data and SIM infrastructure are force multipliers for follow-on attacks.

5. Prepare the Extortion Playbook Before You Need It

Extortion-only actors don't deploy ransomware — your IR plan must account for a "quiet" breach. Pre-stage: legal review thresholds for ransom negotiation (note OFAC and sanctions implications), a decision framework for leak-site monitoring, customer/regulator notification workflows, and preservation procedures for SaaS audit logs (many platforms retain only 90 days — export now). Twenty months of dwell time at the victim organizations means the evidence you need may already be aging out.

6. Validate With Adversary Emulation

Have your red team or a penetration testing partner emulate this exact chain: valid credential login → bulk query → staged archive → rclone egress. Measure time-to-detect at each stage. If any stage is invisible, you have your next engineering sprint defined.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.