
Virginia Man Who Hacked Snapchat Account to Prey on 41 Girls Gets 40 Years
Malachi Morgan Thomas, 24, of Virginia, was sentenced to 40 years in prison for sexual exploitation of children and possession of child sexual abuse material (CSAM), authorities announced.
Thomas pleaded guilty on April 2 to one count of production of CSAM and one count of possession of CSAM, according to the Justice Department.
According to court documents, Thomas used a Snapchat account — which he had previously hacked and stolen from a minor — to coerce approximately 41 minor girls between the ages of 12 and 17 to engage in sexually explicit conduct.
Prosecutors said Thomas directed victims to create and send CSAM and ordered the girls to engage in sexually explicit conduct during live video calls. He told victims he led a criminal organization and that as long as they did what he told them, they would be safe. To coerce compliance, Thomas threatened to hack the victims’ accounts or harm them and their family members, authorities said.
Thomas was aware that several of his victims suffered from anxiety, depression and other mental health issues, and that many had previously been victims of sexual abuse, according to the release. In at least one instance, Thomas knew that the victim was in foster care.
On June 7, 2020, Thomas traveled to a victim’s home and assaulted the victim, which he recorded and saved in his Snapchat account, authorities said. Police discovered the video after searching one of Thomas’ cell phones, which they seized from him while investigating an altercation.
On July 9, 2020, Thomas traveled to a shopping mall in Virginia to meet a victim he exploited on Snapchat. The victim’s father had learned of Thomas’ actions and appeared at the mall instead of the victim. Thomas’ phone was seized when police responded to the incident.
On Oct. 1, 2020, Fairfax County Police arrested Thomas on charges of rape and sodomy of two minors in Fairfax County. With support from Prince William County Police, Fairfax County Police searched Thomas’ residence in Woodbridge, where investigators located a second phone containing dozens of images and videos of CSAM, including recordings of his sexual assaults of two victims in Fairfax County.
“Malachi Thomas exploited dozens of girls through threats, coercion, and devastating sexual abuse,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division. “His tactics — leveraging hacked accounts, fear of physical harm, psychological manipulation, and physical assaults — underscore the gravity of his abusive and horrific crimes. This defendant will spend the next four decades in prison and never harm another child.”
“Malachi Thomas preyed upon our most vulnerable — our children — and he deserves a sentence that reflects the enormity of his crimes,” First Assistant U.S. Attorney Theophani K. Stamos for the Eastern District of Virginia said. “The sentence imposed yesterday does just that. Thomas’ pursuit of his victims was reprehensible and unrelenting. We are committed to using all tools at our disposal to protect children from exploitation and to prosecute offenders to the fullest extent of the law.”
“Today’s sentence reflects the profound harm Malachi Thomas inflicted on dozens of vulnerable children,” said Assistant Director in Charge Darren B. Cox of the FBI Washington Field Office. “The FBI remains steadfast in our commitment to identifying and investigating those who prey on minors, whether online or in our communities. We hope today’s sentence brings a measure of justice for the victims as they continue to heal.”
Kosovar Man Admits Running Rydox, Cybercrime Marketplace That Sold Stolen U.S. Identities and Hacking Tools
A Kosovar national has pleaded guilty in federal court in the Western District of Pennsylvania to charges related to his creation and operation of Rydox, an illicit website and marketplace where cybercriminals bought, sold and traded stolen personal information and accessed devices and other tools for carrying out cybercrime and fraud, the Justice Department said.
Ardit Kutleshi, 28, pleaded guilty to aggravated identity theft and money laundering conspiracy. He is scheduled to be sentenced on Feb. 9, 2027. He faces a mandatory minimum penalty of two years in prison on the aggravated identity theft count and a maximum penalty of 20 years in prison on the money laundering conspiracy count. A federal district court judge will determine the sentence after considering the U.S. Sentencing Guidelines and other statutory factors.
According to court documents, since at least 2016, Rydox conducted more than 7,600 transactions involving stolen personally identifiable information (PII), stolen access devices, means of identification, and cybercrime tools and services, receiving at least $232,000 in revenue. Those transactions involved the sale of PII stolen from victims located in the United States, authorities said.
Kutleshi was arrested by Kosovo law enforcement in December 2024 and extradited from Kosovo to the United States in 2025. In December 2024, the United States also judicially seized the domain www.Rydox.cc, which hosted and facilitated access to the Rydox website. The seizure prevented the owners and third parties from using the site to continue to buy and sell cybercrime tools and stolen personal identifying information of U.S. citizens.
Kutleshi’s brother, Jetmir, pleaded guilty and was sentenced in December 2025 prior to his deportation back to Kosovo, according to the release. U.S. Attorney Troy Rivetti of the Western District of Pennsylvania said the brothers operated the Rydox marketplace for their own gain, making hundreds of thousands of dollars from the marketplace where cybercriminals could purchase information and tools to effect and further their online crime.
“The guilty plea of Ardit Kutleshi for operating the Rydox marketplace exposes a sophisticated scheme to profit from stolen identities and cybercrime tools,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division. “This guilty plea sends a strong message to all cybercriminals that the Justice Department will identify, arrest, and prosecute cybercriminals regardless of where they are in the world through international cooperation, technical expertise, and cutting-edge law enforcement.”
Rivetti said such cybercrimes cause financial loss and ongoing psychological harm to victims who lose money and trust in institutions and the online market infrastructure.
“These types of cybercrimes cause not only financial loss, but also ongoing psychological harm to the victims who lose both money as well as trust in institutions and the online market infrastructure,” Rivetti said. “Our office will continue to work with our law enforcement partners to find and prosecute individuals who attempt to profit from the illegal sharing and sale of other people’s personal information and access devices, and related cybercrime.”
Assistant Director Brett Leatherman of the FBI’s Cyber Division said Rydox put cybercriminal tools and sensitive data up for sale, including stolen identities and logins of thousands of people.
“Rydox put cybercriminal tools and sensitive data up for sale, including the stolen identities and logins of thousands of people,” Leatherman said. “The FBI and its foreign partners shut the marketplace down, and now the man who created it and ran it pleaded guilty. We will continue to use every legal tool at our disposal to extradite cybercriminals and take down their infrastructure.”
Ex-Army Soldier Who Hacked Telecoms as ‘kiberphant0m’ Sentenced to 70 Months for Extortion Scheme
SEATTLE — A former U.S. Army soldier who hacked into telecommunications companies’ databases, stole sensitive records and tried to extort the companies by threatening to release the data was sentenced to 70 months in prison and ordered to pay $294,978 in restitution, the Justice Department said.
Cameron John Wagenius, 22, most recently stationed in Texas, pleaded guilty in the Western District of Washington to conspiracy to commit wire fraud, extortion in relation to computer fraud and aggravated identity theft on July 15, 2025. He also pleaded guilty in a separate case in the same district to two counts of unlawful transfer of confidential phone records information on March 5, 2025.
According to court documents, between April 2023 and Dec. 18, 2024, Wagenius used online accounts associated with the nickname “kiberphant0m” and conspired with others to defraud at least 10 victim organizations by obtaining login credentials for the organizations’ protected computer networks. Wagenius and his conspirators obtained the credentials using a hacking tool Wagenius helped develop called SSH Brute, among other means, and used Telegram group chats to transfer stolen credentials and discuss gaining unauthorized access to victim companies’ networks. The activity occurred while Wagenius was on active duty with the U.S. Army, authorities said.
After data was stolen, Wagenius and his conspirators extorted the victim organizations both privately and in public forums, according to the release. The extortion attempts included threats to post stolen data on cybercrime forums such as BreachForums and XSS.is. In other instances, conspirators offered to sell stolen data for thousands of dollars via posts on those forums. They successfully sold at least some of the stolen data and also used it to perpetuate other frauds, including SIM-swapping. In total, Wagenius and his co-conspirators attempted to extort at least $1 million from victim data owners.
In November 2024, Wagenius made two online posts that disclosed stolen confidential non-content call detail records belonging to a government official and family members of another former official, and threatened to release additional confidential records unless paid a ransom. The text of one post suggested Wagenius was motivated by a desire to retaliate for the then-recent arrest of another cybercriminal.
“Cameron Wagenius spent more than a year and a half betraying the trust placed in him as an active duty soldier by carrying out a sweeping cybercrime campaign,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division. “He targeted U.S. and foreign telecommunications companies, compromised the sensitive data of countless people, and even sought to traffic stolen information to a foreign intelligence service. His actions reflect an alarming disregard for the security of the public and the United States. Today’s sentence demonstrates the Department of Justice’s commitment to protecting privacy and security.”
First Assistant Attorney Charles Neil Floyd for the Western District of Washington said Wagenius engaged in a long spree of criminal conduct, attempting to blackmail hacking victims for more than $1 million.
“He has repeatedly shown disregard for the privacy and security of others, the rules of the military, and the law,” Floyd said. “His hacking schemes were not only aimed at getting rich, he was also motivated by a desire to achieve status within criminal hacking communities. This sentence must impose real consequences to deter him, and hopefully other would-be hackers.”
Assistant Director Brett Leatherman of the FBI’s Cyber Division said the FBI and its law enforcement partners moved quickly to identify, locate and arrest Wagenius after he abused the trust that came with his military service.
“Today’s sentence of 70 months holds him accountable for those choices,” Leatherman said. “The FBI, working alongside our partners at the Department of Defense Office of Inspector General Defense Criminal Investigative Service and the Army identified and arrested him within weeks of his public extortion threats. The FBI will continue to pursue cybercriminals wherever they are, until they face justice in a U.S. courtroom.”
Special Agent in Charge W. Mike Herrington of the FBI Seattle field office said it was especially shocking that a member of the armed forces, sworn to defend Americans and their constitutional rights, would engage in such a violation of privacy.
“The FBI takes the theft of data seriously and will investigate, identify, and impose consequences on those who steal data or assist in trafficking and sharing it,” Herrington said.


