CIA officer said he was developing hacking tools, but actually stole $190 million in top secret fraud scam

CIA officer said he was developing hacking tools, but actually stole $190 million in top secret fraud scam

Welcome to Tech Radar club ! Hi , Your membership journey starts here.

Keep exploring and earning more as a member.

News, deals, reviews, guides and more…

News, deals, reviews, guides and more on the newest computing gadgets

Your membership perks Start exploring exclusive deals, expert advice and more

Unlock and manage exclusive Techradar member rewards.

Unlock instant access to exclusive member features.

Get full access to premium articles, exclusive features and a growing list of member rewards.

No, this is not the plot of Martin Scorsese’s “Wolf of Langley”, the news was just confirmed by the US Department of Justice, who named David J. Rush, of Ashburn, Virginia, as the fraudster, and said he pleaded guilty to “executing a scheme to defraud the federal government”.

“Following an internal investigation that identified potential crimes, CIA immediately referred this matter to the FBI,” said CIA Director John Ratcliffe. “David Rush abused his position and betrayed the public trust and should be held fully accountable for his actions.”

According to court documents, Rush lied during the job interview about his education and military experience, which ultimately helped him land a senior executive-level position with a federal agency. In that position, he held a Top Secret/Sensitive Compartmented Information (TS/SCI) security clearance – a designation some government agencies use to control access to some of the government’s most sensitive classified information.

It combines Top Secret clearance (the highest standard US security classification level), with eligibility to access Sensitive Compartmented Information (SCI) which, in itself, is subject to additional security restrictions.

This clearance allowed Rush to access highly classified US government intelligence, but more importantly, allowed him to create a fake “Special Access Program” and get it funded. He then used this funding to wire himself roughly $145 million, buying luxury real estate, watches, and “at least one car”. He also acquired 298 gold bars, worth approximately $46 million. In total, Rush pocketed $193,590,400 in US government funds.

Obviously, $200 million is no pocket change, and someone must have noticed, since on May 19, the FBI raided Rush’s residence. They recovered 298 gold bars, more than two million in cash, just over €100,000 in euros, and “numerous luxury watches” most of which were Rolexes. He later pleaded guilty and agreed to forfeit the gold bars, the fiat currency, 30 watches, two 2026 BMW Alpina cars (worth north of $150,000 – each), and all of the real estate he bought with the stolen money.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

“By his own admission, David Rush defrauded the government of hundreds of millions of dollars, and then misused those funds for extravagant purchases,” said FBI Director Kash Patel. “Rush betrayed his oath, his co-workers, and the American people and he will now face justice for his actions. This plea demonstrates the FBI’s commitment to protecting the public’s trust; and that no government position, security clearance, or access to government resources places anyone above the law.”

Rush will have to wait until January 28, 2027, to hear his sentence which could be up to 20 years in prison, three years of supervised release, forfeiture, restitution, and a fine, the DoJ said.

“A federal district court judge will determine any sentence after considering the U.S. Sentencing Guidelines and other statutory factors.”

According to TechCrunch, Rush was employed in 2010 and has since then worked on developing hacking tools and techniques for espionage. His “Special Access Program” was described as a “surveillance or intelligence-gathering operation so sensitive that only a few people are read into [it]”.

Rush allegedly constructed the compartmentalized program as a fake “continuity of government” plan, to be used in case of war, natural disaster, or similar major and disruptive event. The gold was apparently bought by a defrauded defense contractor, which Rush later took home.

For years now, Microsoft has been adding different file types to the “blacklist”, in an effort to prevent users from downloading and running malicious attachments sent in phishing emails. As The Register reminds, in December 2023, the company disabled ms-appinstaller protocol handler by default, after it was abused to distribute malware.

Since then, Microsoft has also blocked .py (Python files), .ps1 (PowerShell files), and .cab (cabinet files). Some people found it surprising it took Microsoft this long to remember .msix and .msixbundle types, as well.

The best antivirus for all budgets ➡️ Read our full guide to the best antivirus1. Best overall:Bitdefender Total Security2. Best for families:Norton 360 with LifeLock3. Best for mobile:McAfee Mobile Security

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

📰 Original Source Attribution

Reported by techradar.com.

Read Original Report at techradar.com ↗
Share: WhatsApp WhatsApp
💬

Comments (0)

Join the Conversation

No comments yet. Be the first to share your opinion!

You may like