ABOUT 5 HOURS AGO • 7 MIN READ

The Insider Threat Division’s Own Insider - Issue #20 - Insider Threat Weekly

profile

Insider Threat Weekly

Every week I go through DOJ press releases, vendor research, and breaking news to find the insider threat and fraud cases worth knowing about. Then I explain why they matter and what they mean for your program. No vendor pitch. Just the cases, the numbers, and the lessons.

My theme this week has been to be more frugal, with both my time and my money.

On the money side, I have not had a credit card for over a decade. I just use debit. This week I went a step further and started paying with cash instead of tapping my card, and it has made a real difference. When you have to hand over cash, you cannot spend on autopilot. You slow down and actually think about what you are buying, instead of just tapping for the convenience of it. I am going to keep doing that.

On the time side, I have been more picky about what I read and what I give my attention to. That is what gave me the idea to change how this newsletter is put together. So hopefully this helps you too.

From now on, I am laying each story out as a few dot-point facts and then a short, conversational take on the story or the insider risk behind it. If a story grabs you, please go and read the article links. I always recommend that. If you are interested, dig in. Do not take my word for it, and do not take anyone else’s. If it is a news article, try to find the original source. The high-level points and a take should be enough for you to decide whether a story is worth more of your time.


Headline: The Insider Threat Division’s Own Insider

  • Nathan Laatsch, 29, was an IT specialist in the Defense Intelligence Agency’s Insider Threat Division.
  • On August 26 he pleaded guilty to passing national defense secrets to a foreign government.
  • In March 2025 he emailed an offer to help a “friendly foreign government,” saying he was disillusioned with the Trump administration.
  • In May he left a thumb drive at a dead drop in an Arlington park, holding nine documents marked up to Top Secret.
  • The FBI arrested him days later. He now faces up to life in prison, with sentencing set for January.

We have seen this in cybersecurity for years. A new threat emerges and we start to forget the old ones, even though most of what shows up in the security roundups is still just poor hygiene. Insider risk is going the same way. Everyone is focused on AI as the huge new insider risk, with data leaving organizations through models and agents, while the simplest factors still work. Someone loads data onto a USB, or prints it out, and walks out the door.

Source: Former U.S. Government Employee Pleads Guilty to Attempting to Provide Classified Information to Foreign Government (DOJ)


Insider Scoop: Selling Access for $15,000

  • Flashpoint now publishes a monthly report on insider threats traded on the dark web.
  • In July it counted 12,653 insider-threat posts, and most came from insiders advertising their own access rather than being recruited.
  • The targets are spreading out, from the usual telecom and finance into supply chain, logistics, and manufacturing.
  • In one case an insider took $15,000 in crypto to approve a single multi-factor push. That one tap handed attackers domain-admin control of the network.

I am honestly not surprised to see access going for as little as fifteen thousand. We are living through a cost of living crisis, with huge inequality and very little stability. A lot of people do not have a home they own, or even rent they feel safe in. Fifteen thousand dollars goes quickly, but it buys a bit of the security that their job and their career are not giving them. This will not slow down until governments and organizations do a better job of giving people stability. Stability is what builds loyalty, to an employer and to a country. Without it, these offers will keep finding takers.

Source: Insider Threat Report: Dark Web Recruitment & Access Trends (Flashpoint)


Crime Roundup

Trading Ahead of the Numbers - Jesse Mitchell, 48, was a senior finance director at the ad-tech firm The Trade Desk. - Prosecutors say he saw the company’s earnings before they went public and traded on them. - The scheme ran through his role in financial planning and made him about $338,000. - He is charged in New York with two counts of securities fraud.

Source: Ex-Trade Desk Finance Director Accused Of Insider Trading (Law360)

A CFO’s $1 Million Card Habit - Tina Feuerstein, 53, was the CFO of a Pennsylvania company. - A Chicago jury convicted her of eight counts of wire fraud. - Over five years she put more than $1 million of luxury furniture, designer clothing, and everyday spending on the company card. - She hid it by deleting more than 3,800 charges from the books and faking the financial statements.

Source: Former CFO of Chicago-Area Company’s Subsidiary Convicted of Embezzlement (DOJ)


Philips X-Ray Secrets to China

  • A federal jury in Chicago convicted Chih-Yee Jen, 71, a former Philips engineer, of stealing trade secrets.
  • Jen worked at Philips’ Aurora, Illinois plant, which built X-ray tubes for CT scanners.
  • As Philips prepared to close the plant in 2017, a Chinese competitor, Kunshan GuoLi, recruited him to help set up a rival operation.
  • While still employed, he shared confidential Philips documents and pulled other Philips engineers over with him.

This is one of the industries China is targeting to become self sufficient by 2030 and beyond. Most of what they go after is semiconductors, AI, and advanced manufacturing, and those usually carry military links. Healthcare is the interesting one, because it does not. China simply has an aging population it wants to sustain, and that alone is enough to make medical technology a target for trade secret theft.

Source: Federal Jury in Chicago Convicts Engineer for Stealing Trade Secrets from Philips Medical Systems (DOJ)


AI Insider Threat Watch: The Flaw Is in the Harness, Not the Model

  • Researchers at Novee Security found critical flaws in the three big AI coding agents: Claude Code, Gemini CLI, and OpenAI Codex.
  • Many projects wire these agents into their pipelines, so that opening a GitHub issue makes the agent read it and act on its own.
  • Anyone on the internet can open an issue, with no account privileges and no link to the project, and a booby-trapped issue became instructions the agent followed.
  • That let an outsider reach secret keys and run code on the build servers without ever having access themselves. The vendors’ own default setups were affected, along with more than a hundred other public repositories.
  • The weakness was not in the AI models. It was in the harness around them, the code meant to manage permissions and sandboxing, which failed to contain the injected instructions.

Once again we are hit by the lethal trifecta. All three conditions are here. The agent and its harness have access to sensitive data, the secret keys. There is exposure to untrusted content, through an unprivileged outsider opening a GitHub issue. And there is a way to communicate out, back through that same issue and the logs, so the keys can be taken. When all three line up in one system, this is what you get. I wrote about this last year in one of my insider threat advisories at DTEX, on organizations building their own AI systems and agents. Since we started talking more about the lethal trifecta, we keep seeing it, again and again. That is the value of the framework. When you look at an AI system or agent from a risk perspective, the trifecta gives you the questions to ask. It shows you how an attacker, or even a normal user, could exploit it, misuse it, or trip it by accident into a data loss event.

Source: Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets (The Hacker News)


Mitigation Corner: Don’t Take Your Eyes Off the Basics

  • A Forbes piece this month argued that your next insider threat will not be a person, but an agentic AI.
  • The risk is real, and this issue shows it. But it is only half the picture.
  • This same month, the biggest insider cases were very human: a thumb drive at a dead drop, stolen engineering documents, and people selling their own access for cash.

The fix is not to choose one. Watch your AI agents like privileged insiders, and keep watching the old routes too. Removable drives, printing, personal email, and the gap at offboarding are all still wide open. Give the new threat your attention, but do not take it away from the basics that still cause most of the damage.

Source: Your Next Insider Threat Won’t Be Human: The Risks Of Agentic AI (Forbes)


Trusted Profession Watch: The Fiduciary Who Robbed the Vulnerable

  • Gregory Oveross was a licensed professional fiduciary in the Los Angeles area, appointed to manage the finances of people who cannot manage their own.
  • California prosecutors charged him with stealing more than $6 million from his clients’ accounts in a Ponzi-style scheme.
  • To hide it, he altered bank statements and faked the reports he filed with the courts.
  • His accountant was charged alongside him, and the two were also accused of dodging income tax on the proceeds.

This one is just disgusting. A trusted profession like this exists to help vulnerable people who can no longer manage their own finances. Usually that is an older generation who have lost the ability or the mental capacity, and who are just trying to live out the rest of their years in peace. Instead, someone in that role takes advantage of them. It is the same exploitation you see aimed at any vulnerable community, and it is really sad to see.

Source: AG Bonta Announces Arrest of Los Angeles Area Licensed Fiduciary Charged with Stealing $6 Million from Client Accounts (California DOJ)


Trivia

Nathan Laatsch handed over documents using a “dead drop.” In spy tradecraft, what is a different method known as a “brush pass”?

A) Leaving material hidden in a public spot for later pickup B) A quick, discreet handoff between two people passing in a crowd C) Turning a target into a source using blackmail D) Sending coded messages over shortwave radio

(Answer at the bottom.)


Corporate News: Google’s AI Secrets and a Split Verdict

  • Linwei Ding, a former Google engineer, stole thousands of pages on the company’s AI data-center technology for a Chinese firm that was recruiting him.
  • A jury convicted him in January of both economic espionage and trade secret theft.
  • In August a judge threw out the economic espionage counts, ruling prosecutors never proved Ding knew his theft would benefit the Chinese government.
  • The trade secret theft convictions stand, and he is due to be sentenced on September 1.

There is a wider point that goes beyond this case. Even when data leaves an organization by accident, and not as espionage, it can still end up in the same hands. Once information is outside the walls, it is exposed. If a nation state wants it, there is a good chance they will eventually get it. That is the real risk in any data loss event, not only the ones that begin as theft.

Source: Former Google engineer convicted of stealing AI trade secrets (Yahoo Finance)


What’s On

Insider Risk: When Trust Becomes the Attack, an Everfox FoxForum webinar.

  • When: Thursday, September 3, 2026, 1:00 AM AEST.
  • Speaker: Shibu Thomas, Field CTO for Global Insider Risk at Everfox. He has spent over 20 years building insider risk programs across US and international government agencies, Five Eyes partners, and global enterprises.
  • Register: https://everfox.zoomgov.com/webinar/register/5817865258062/WN_3jZv6ymSTGWZM4Jm8-cL6g

Trivia Answer

B. A brush pass is a brief, choreographed handoff, where two people cross paths and exchange an item without breaking stride, so it looks like nothing happened. Option A describes the dead drop that Laatsch used.

Insider Threat Weekly

Every week I go through DOJ press releases, vendor research, and breaking news to find the insider threat and fraud cases worth knowing about. Then I explain why they matter and what they mean for your program. No vendor pitch. Just the cases, the numbers, and the lessons.