Every week I go through DOJ press releases, vendor research, and breaking news to find the insider threat and fraud cases worth knowing about. Then I explain why they matter and what they mean for your program. No vendor pitch. Just the cases, the numbers, and the lessons.
|
There's something nice about the flow of putting one of these together. You collect all the resources, then look for the common thread. In insider risk that part is usually easy. There's always fraud. There's always embezzlement. And now AI is becoming its own insider risk, so there's a whole new category to pull from. The stories I keep coming back to are the ones in the gray area. That's the headline this week: insider trading on prediction markets. Once you're there, the same thread runs straight out into crypto, and into the stock market. It's the same shape every time. People with access. Not just to information, but to influence, the kind that can move a market in an indirect way and still pay off for them, or for the people close to them. And there's the blurred line. No direct evidence in the moment. But look at the market in hindsight and the trend tells you plainly that the right people did well out of the actions, or even just the words, of whoever was involved. This Week's Headline: Managed Completely IndependentlyThere is a version of insider trading that we catch, and a version we don't. The difference is not the conduct. It's the distance between the person who knows something and the person who places the trade. We covered the White House teleprompter operator a couple of weeks ago. He allegedly used advance knowledge of Trump's speeches to bet on Kalshi's mention markets, the ones where you wager on whether a specific word gets said. His account got frozen with about $90,000 in it. A clean example, because he did it himself. This week there are three more, and they follow the same rule. George Santos settled with the CFTC for $35,000 and a three year ban after regulators said he manipulated a Kalshi market on his own State of the Union attendance, pumping one side in public and quietly betting the other. Master Sergeant Gannon Van Dyke, an Army Special Forces soldier who helped capture Maduro, is charged in New York with using classified details of the operation to win more than $400,000 on Polymarket. And a Google engineer, Michele Spagnuolo, is charged with turning the company's confidential Year in Search data into a $1.2 million Polymarket payday before the results went public. Every one of them got caught for the same reason. They were the insider and the trader. One person. Van Dyke even tried to bury it afterward, asking Polymarket to delete his account and swapping the email on his crypto exchange, and it did not save him, because the trades were still his. You can draw the line straight from the desk to the bet. Now change one thing. Have the soldier's brother place the trade. Have the engineer tell a friend what's coming and let the friend buy. The knowledge is still inside. The benefit still lands close to home. But the line you were drawing from the desk to the bet now runs through someone who can say, truthfully, that nobody told them what to do. That is the whole game. The cutout doesn't make the trade clean. It makes it unprovable. Which is where the crypto story comes in, and why it belongs in the same piece. On his show in July, John Oliver walked through the Trump family's crypto ventures, the meme coin and World Liberty Financial. By his figures, Trump made around $636 million from the coin, close to a million people lost money on it, and the losses ran to about $3.8 billion. His financial disclosures reportedly showed $2.2 billion in income in his first year back, roughly $1.4 billion of it from crypto. There was a private dinner for the top 220 holders. Access, in exchange for buying in. The family's answer to the conflict-of-interest question is that the ventures are managed completely independently. And that is exactly the point I keep landing on. Independent management is not the opposite of the insider-trading problem. It is the cutout, built in advance and written into the structure. Nobody has to get caught telling anyone anything, because the arrangement was designed so that no telling is required. I am not saying the family traded on inside knowledge. I am saying the defense they lean on is the same gap that lets the small cases walk, just formalized. And it scales past crypto. The same shape sits under equities, under any market where a person with the right access, or just a well-timed sentence, can move the price and let the benefit settle on people close to them. In the moment there is no direct evidence. In hindsight the chart tells you who did well. That is the gray area. It is the most interesting part of this work, and the hardest to prosecute, because the better the structure, the less there is to find. Sources: George Santos Settles Kalshi Insider Trading Case With the CFTC (NOTUS) — https://www.notus.org/us-news/george-santos-settles-kalshi-insider-trading-case-with-the-cftc U.S. Soldier Charged With Using Classified Information To Profit From Prediction Market Bets (U.S. Department of Justice) — https://www.justice.gov/opa/pr/us-soldier-charged-using-classified-information-profit-prediction-market-bets Google engineer charged with insider trading after making $1.2M on Polymarket (TechCrunch) — https://techcrunch.com/2026/05/27/google-engineer-charged-with-insider-trading-after-making-1-2m-on-polymarket/ John Oliver on the Trump family's crypto schemes (The Guardian) — https://www.theguardian.com/tv-and-radio/2026/jul/27/john-oliver-trump-family-crypto-schemes Insider Scoop: An Axe, a Toilet, and a Fake Slack ChannelThe insider is not always your own employee gone bad. Sometimes it's your employee working for someone else. Rippling and Deel are rivals in HR and payroll software, and Rippling alleges that Deel recruited one of Rippling's own staff in its Dublin office, Keith O'Brien, as an embedded mole, paying him around 5,000 euro a month to hand over internal documents. O'Brien had interviewed at Deel, didn't get the job, and connected with Deel's leadership on LinkedIn instead. By his own account, they told him to stay at Rippling and spy. Rippling caught him with a trap. They planted a honeypot Slack channel and referenced it in a legal letter to Deel. The theory was simple. Only someone digging through Rippling's systems for anything about Deel would go looking for that channel. He went looking. Then comes the part that reads like a film. Confronted at the office with a court order to hand over his phone, O'Brien panicked, went to the bathroom, factory reset the device, and flushed the toilet a few times for good measure. He later said he smashed his old phone with an axe and put it down a drain at his mother-in-law's house, on advice from people he believed worked for Deel. To answer the obvious question, he wasn't arrested and he didn't flee. He flipped. He laid all of this out in a sworn affidavit and became Rippling's witness. The criminal side is only now catching up. The Justice Department has reportedly opened a probe into Deel, with grand jury subpoenas out of the Northern District of California. The lesson is the honeypot. You don't always need to watch the data leave. Sometimes you just plant the thing only a leaker would go looking for, and wait. Sources: The affidavit of a Rippling employee caught spying for Deel reads like a movie (TechCrunch) — https://techcrunch.com/2025/04/02/the-affidavit-of-a-rippling-employee-caught-spying-for-deel-reads-like-a-movie/ The Justice Department Is Reportedly Investigating an Alleged Startup Spying Scandal (Inc.) — https://www.inc.com/jennifer-conrad/the-justice-department-is-now-investigating-an-alleged-startup-spying-scandal/91291694 Crime RoundupTheodore Woo, hedge fund CFO. Theodore Woo, 49, was the chief financial officer of a Miami hedge fund, which is a bad place to put someone who likes other people's money. Over several years he moved more than $3 million to himself, causing over 100 fraudulent transfers into a company and accounts he controlled, some of it dressed up as "research consulting services" that were never provided, and running unauthorized personal expenses through the fund's credit cards. He pleaded guilty in the Southern District of New York to one count of securities fraud and is scheduled to be sentenced on November 18, facing up to 20 years. Scott Kelley, postal inspector. Scott Kelley, 52, ran the Mail Fraud team at the Postal Inspection Service's Boston division, supervising the inspectors who investigated scams against seniors. Between January 2019 and August 2023 he used deceptive internal emails to have roughly 1,950 packages, the ones flagged as likely mailed by scam victims, redirected to him, then opened the ones that felt like cash and kept it. He pleaded guilty to stealing about $340,000, plus laundering it and hiding it from the IRS, across dozens of counts. The money went to home renovations, cruises, and escorts. Sentencing is set for November 18. Weston Goldstein, Big Ten Network. Weston Goldstein, 48, was the Big Ten Network's senior director of engineering, and the man in charge of buying its Apple gear. From January 2016 through August 2023 he used company credit cards and the procurement process to buy about $4 million in Apple products, then resold them for around $1.1 million, disguising the orders as equipment for the network. He kept going even after BTN told him to stop, and leaned on the thinner oversight during COVID. He pleaded guilty to wire fraud, was sentenced to 28 months, and ordered to repay the full $4 million. Sources: Former CFO Charged And Pleads Guilty To Defrauding Hedge Fund Of More Than $3 Million (U.S. Department of Justice, SDNY) — https://www.justice.gov/usao-sdny/pr/former-cfo-charged-and-pleads-guilty-defrauding-hedge-fund-more-3-million Former Federal Law Enforcement Officer Pleads Guilty to Stealing $340,000 Cash from Elderly Scam Victims (U.S. Department of Justice, D. Mass.) — https://www.justice.gov/usao-ma/pr/former-federal-law-enforcement-officer-pleads-guilty-stealing-340000-cash-elderly-scam Ex-Big Ten Network employee sentenced in $4M Apple product fraud scheme (FOX 32 Chicago) — https://www.fox32chicago.com/news/big-ten-network-employee-sentenced-apple-fraud-scheme AI Insider Threat WatchSame three ingredients I keep coming back to. Give an agent access to sensitive data, the ability to send things out, and exposure to content it didn't write and can't fully trust, and you have built an insider. Not a metaphorical one. One that will act. The crypto world is the one that has me thinking, because it has already wired the money straight to the agent. Protocol weaknesses in AI trading agents drove more than $45 million in incidents this year. In January, Step Finance, a Solana portfolio manager, had roughly $40 million drained after its agents moved more than 261,000 SOL, because nobody had put real isolation or permission limits around what those agents could do. In May, an attacker got an agent to move about $175,000 using an instruction hidden in Morse code. Researchers at Nanyang Technological University and IBM found direct prompt injections landing more than 79 percent of the time. There is no reliable defence yet. Only guardrails. Now play that forward. These tools are becoming commercially viable, and we are about to invite them into everything. Your email. Your banking. Your crypto wallet. The accounts that hold your identity, your money, and the day-to-day of a life that is now almost entirely digital. Every one you connect is another door, and the agent on the other side can be turned by a sentence buried in a message it was only trying to be helpful with. That is a threat vector running straight into your life, and the failure mode is not an inconvenience. It is your world upturned. The enterprise version showed up this month too. Varonis researchers found a flaw in Microsoft 365 Copilot Enterprise Search, disclosed as CVE-2026-42824 and nicknamed SearchLeak, that chained a prompt injection, a rendering race condition, and a server-side request forgery into a one-click leak of whatever the employee could reach. Microsoft has patched it. Same three ingredients, corporate edition. So here is what I would ask before you hand an agent the keys to an account. If this agent were deleted tomorrow, or quietly taken over, how hard would it be to get everything back? If the honest answer is anything more than moderately difficult, don't do it. Put some segregation between where your agents operate and the accounts that actually matter. Sources: AI Trading Agent Vulnerability 2026: How a $45M Crypto Security Breach Exposed Protocol Risks (KuCoin) — https://www.kucoin.com/blog/en-ai-trading-agent-vulnerability-2026-how-a-45m-crypto-security-breach-exposed-protocol-risks Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments (SecurityWeek) — https://www.securityweek.com/prompt-injection-attacks-trick-ai-agents-into-making-crypto-payments/ Microsoft 365 Copilot SearchLeak (CVE-2026-42824) (PointGuard AI) — https://www.pointguardai.com/ai-security-incidents/copilot-searchleak-turns-search-into-a-data-drain-cve-2026-42824 Mitigation Corner: The Agent Is Whoever Installed ItI have been researching this one at DTEX for more than six months, back when the conversation was still about agentic browsers. The point we kept making in our research and our ITA workshops was simple. An agentic browser that can reach into your local file system and your cloud SaaS apps, running under your account, is not a feature. It is a privileged insider operating at exactly your level of access. It can see what you can see and do what you can do. That has only moved forward. The browsers were the early version. Now we are installing Cursor, Claude, and other agentic tools as full applications, with reach that goes well past what those first browsers had. Same principle, more access. The agent is an insider, and it is an extension of whoever installed it. The catch is that most people using one do not fully understand the commands and tools it reaches for when they ask it to go and do something. You approve the goal. You do not see the steps. The rest of the industry is arriving at this now. There is a wave of articles and interviews, and Dark Reading ran a good one this month with Katie Moussouris of Luta Security making the same case: treat every agent as a privileged identity, because the containment meant to hold them is not holding, and most organisations cannot see what their agents are doing. So the fix is deliberately boring. Give every agent its own identity, not your login. Scope its access to the minimum the job needs. Issue it credentials you can pull in a single move. And log what it touches the way you would log a privileged employee. If you cannot answer what an agent touched today, you do not have an agent. You have an insider nobody is watching. Set that up before you connect it, not after the cleanup. Sources: Agentic AI Presents New Insider Threat Model for Orgs (Dark Reading) — https://www.darkreading.com/cyberattacks-data-breaches/agentic-ai-new-insider-threat-model How Agentic AI Browsers Elevate Insider Risk (DTEX i3 Threat Advisory) — https://www.dtex.ai/resources/i3-threat-advisory-agentic-browsers-elevate-insider-risk/ Trusted Profession Watch: The Supply Chain ProfessorDaniel Taylor, 51, taught marketing and supply chain management at Texas Tech's Rawls College of Business. He also ran a fentanyl distribution network, and he pleaded guilty this month to conspiring to distribute more than 40 grams of it. The part that lands is what he admitted in court. The same supply chain expertise he was paid to teach is what he used to build and run the operation. He did not leave his profession at the door. He weaponised it. Prosecutors say the fentanyl powder he supplied caused at least eight overdoses. He faces up to 40 years. It is one thing to see a trusted professional go bad. It is another to watch them turn the specific skill we trusted them to teach into the engine of the harm. Sources: Former Texas Tech Professor Pleads Guilty to Running Fentanyl Trafficking Conspiracy (U.S. Department of Justice, N.D. Tex.) — https://www.justice.gov/usao-ndtx/pr/former-texas-tech-professor-pleads-guilty-running-fentanyl-trafficking-conspiracy TriviaPrediction markets like Kalshi, where people bet on real world outcomes, run as regulated exchanges in the United States. Which federal regulator oversees them? A) The SEC B) The CFTC C) FINRA D) The FTC (Answer at the bottom.) Corporate News: The Insider Is Cheaper Than the Compliance TeamTD Bank has already paid dearly for its anti money laundering failures. This is the human version of that story. Two former TD employees were sentenced this month for helping launder money through the bank from the inside. Wilfredo Aquino, an assistant store manager, spent 2019 to 2021 helping a laundering network run by a man known as David move hundreds of millions of dollars through TD accounts. Aquino personally waved through around $92 million in bank checks, funded by cash deposits that should have triggered reports he never properly filed. His price was about $11,000 in retail gift cards. He got 46 months. The second, Edward Low, was a retail employee who took roughly $26,700 in bribes to hand customer information to people outside the bank, who used it to get into accounts and steal. He got 24 months. What gets me is the exchange rate. A network moved close to half a billion dollars through the bank, and the insider who greased it did it for gift cards. The controls were not beaten by sophistication. They were beaten by a manager who agreed to look away. Sources: Two TD Bank Insiders Sentenced to Prison for Facilitating Money Laundering, Fraud (U.S. Department of Justice) — https://www.justice.gov/opa/pr/two-td-bank-insiders-sentenced-prison-facilitating-money-laundering-fraud Trivia AnswerB, the CFTC. Kalshi runs as a CFTC regulated exchange, and its event contracts sit with the Commodity Futures Trading Commission rather than the SEC. It is also the CFTC that platforms report suspicious trading to, which is how a few of the cases in this week's headline surfaced in the first place. Enjoyed this issue? Buy me a Coffee keeps the research running. |
Every week I go through DOJ press releases, vendor research, and breaking news to find the insider threat and fraud cases worth knowing about. Then I explain why they matter and what they mean for your program. No vendor pitch. Just the cases, the numbers, and the lessons.