The hacker told fellow members of criminal forums that he was from the US Army and shared pictures of himself in uniform.
One of the hackers who masterminded the Snowflake credential leak that led to the threat actors stealing data from and extorting at least 165 companies, including 560 million Ticketmaster customers and 110 million AT&T customers, could be a US soldier, according to cybersecurity journalist Brian Krebs.
The hacker, known for using the moniker Kiberphant0m, carried out online chats using multiple cybercrime personas across different platforms, Krebs said, adding that the chats suggested their US Army links with possible posting in South Korea.
Two men, Connor Riley Moucka and John Erin Binns, have already been arrested and are under trial in connection with the Snowflake extortions, while Kiberphant0m, whose identity is yet unknown, remains at large and is still extorting victims.