A U.S. Army soldier ("Kiberphant0m") tied to major telecom data thefts was sentenced to 70 months in prison. Prosecutors say that while jailed, he used other inmates’ email accounts to get someone on the outside to ask commercial AI tools for vulnerability details and even “real world working” exploit scripts, framing the requests as a “book” to bypass safeguards.
How the attack worked
According to prosecutors, a U.S. Army soldier tied to major telecom data thefts and sentenced to 70 months in prison continued attempting to gather exploit information even while incarcerated. Rather than using his own email access, he used other inmates' email accounts to ask an outside recipient to prompt commercial AI tools on his behalf. This proxy approach let him distance himself from the requests while still directing what information was sought.
The requests were specific and technical. He asked what CVEs exist for Windows 10 Enterprise privilege escalation and bypasses, and asked the recipient to have the AI tool provide a real world working script for each CVE without omitted code. In a separate message sent about a week later using a different inmate's account, he asked for step by step exploitation guidance for CVE-2023-45208, along with code, and instructed that if no code existed, the AI tool should make some.
Why it succeeded
The requests were framed as research connected to a book he was writing, a cover story used to make the queries appear legitimate rather than malicious. This kind of framing is a common method of prompt injection, where deceptive inputs are used to get commercial AI tools, which are generally programmed to avoid producing malicious code, to output exactly that. By routing the requests through someone else's account and wrapping them in a plausible-sounding justification, the requests were harder to trace back to their original intent.
What to watch for
- Requests, even ones framed as research, writing projects, or hypothetical scenarios, that ask for exploit scripts, step by step exploitation instructions, or privilege escalation bypasses
- Someone asking you to run an AI query or search on their behalf rather than doing it themselves
- Follow-up requests pushing for code with no omissions, or asking that code be generated if it does not already exist
Building resistance
Organizations should treat any unsolicited request for exploit code or detailed vulnerability bypass guidance as a red flag, regardless of the stated justification. Employees with access to AI tools, along with IT and security staff, should be trained to recognize proxy requests, where someone else asks them to run a query, as a potential attempt to bypass accountability or technical controls. Any such request, especially one involving specific CVEs or exploit scripts, should be escalated to security or legal teams rather than fulfilled, and organizations should consider clear policies on acceptable use of AI tools for security research.
Key findings
- Prosecutors said Wagenius used other inmates’ email to ask an outside recipient to prompt commercial AI tools for vulnerability and exploit information.
- The requests included specific asks for Windows privilege escalation CVEs and “a real world working script for each CVE … without omitted code.”
- He also asked for “step by step” exploitation guidance for CVE-2023-45208 and requested instructions for making an antenna in prison.
- The memo says he framed some of these AI queries as part of a “book he was writing,” described as a common method of “prompt injection.”
Who’s being targeted
- Commonly targeted roles: All employees, IT, Security team, Executives (policy owners for AI/tool governance).
- Affected industries: Telecommunications, Government / Corrections (Bureau of Prisons), Cloud / Data storage services.
- Attack channels: email.
- Impersonated: A “researcher/author” (book-writing cover story).
Red flags to watch for
- Request explicitly asks for privilege escalation “bypasses” and exploit scripts
- Attempts to route the request through someone else’s account (“used another inmate’s email system”)
- Cover story (“book he was writing”) used to justify clearly malicious requests
- Direct request for exploit “step by step” plus code generation
- Asks AI to “make some” code if it doesn’t exist
- Uses an intermediary account (“used a different inmate’s email account”)
Frequently asked questions
What is prompt injection in this case?
Prosecutors said the soldier framed requests to commercial AI tools as being for a book he was writing, a common method of prompt injection used to get around safeguards meant to block malicious code output.
How did the soldier bypass restrictions to make these requests?
He used other inmates' email accounts to ask an outside recipient to prompt AI tools on his behalf, avoiding direct use of his own access and routing the requests through intermediaries.
What kinds of exploit information did he request?
He asked for Windows 10 Enterprise privilege escalation CVEs, a real world working script for each CVE, and step by step exploitation guidance for CVE-2023-45208, including code if none already existed.
Who should pay attention to this kind of attack?
All employees, IT staff, security teams, and executives who set policy for AI and tool governance should be aware, since anyone with AI tool access could be asked to act as an unwitting proxy.
Read the video transcript
Imagine this lands in your inbox: “Hey, can you ask an AI tool what CVEs are there for Windows 10 Enterprise privilege escalation and bypasses?” A U.S. soldier in prison actually did this. He used other inmates’ email accounts to get someone outside to ask commercial AI tools for “real world working” exploit scripts, no code omitted, and step‑by‑step for CVE‑2023‑45208, calling it a book he was writing. Here’s the trick: he’s using you as a proxy to bypass AI safety and hide his identity. The giveaway is the combo: using someone else’s account, plus explicit asks for privilege‑escalation “bypasses”, plus “step‑by‑step” exploit code, all wrapped in a harmless‑sounding research story. If anyone asks you to get exploit scripts or step‑by‑step hacking guidance from an AI tool, even “for a book” or “research”, stop. Don’t run the query. Forward the email to Security and Legal and let them handle it.