Inside the story of the US defense contractor who leaked hacking tools to Russia

A veteran cybersecurity executive who prosecutors said “betrayed” the United States will spend at least the next seven years behind bars, after pleading guilty to stealing and selling hacking and surveillance tools to a Russian firm.

Peter Williams, a former executive at U.S. defense contractor L3Harris, was sentenced on Tuesday to 87 months in prison for leaking his former company’s trade secrets in exchange for $1.3 million in crypto between 2022 and 2025. Williams sold the exploits to Operation Zero, which the U.S. government calls “one of the world’s most nefarious exploit brokers.”

The successful conviction of Williams follows one of the most high-profile leaks of sensitive Western-made hacking tools in recent years. Even now that the case is over, there are still unanswered questions.

Williams, a 39-year-old Australian citizen who resided in Washington, D.C., was the general manager of Trenchant, the division of L3Harris that develops hacking and surveillance tools for the U.S. government and its closest global intelligence partners. Prosecutors say Williams took advantage of having “full access” to the company’s secure networks to download the hacking tools onto a portable hard drive, and later to his computer. Williams contacted Operation Zero under a pseudonym though, so it’s unclear if Operation Zero ever knew Williams’ real identity.

Trenchant is a crew of hackers and bug hunters who dig deep into other popular software made by companies like Google and Apple, identify flaws in those millions of lines of code, then devise techniques to turn those flaws into workable exploits that can be used to reliably hack into those products. These tools are typically called zero-day exploits because they take advantage of software flaws unknown to its developer, which can be worth millions of dollars.

The U.S. Department of Justice alleged that the hacking tools Williams sold could have allowed whoever used them to “potentially access millions of computers and devices around the world.”

For the past few months, I have been talking to sources and reporting on Williams’ story before news broke that he had been arrested. But what I had heard was patchwork and at times conflicting. I had heard someone had been arrested, but given the secret nature of the work involved in exploit development, proving it would be challenging.

Contact Us

Do you have more information about this case, and the alleged leak of Trenchant hacking tools? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram, Keybase and Wire @lorenzofb, or by email.

When I first heard of Williams, I wasn’t clear that I had even gotten his name right. At that point, his story was a rumor, moving through the hush-hush grapevine of zero-day exploit developers, sellers, and people with ties to the intelligence community.

I heard that maybe he was called John, or perhaps Duggan? Or all the different ways you can spell that in English.

Some of the first rumors I heard were contradictory. Apparently he stole zero-days from Trenchant, and maybe he sold them to Russia, or perhaps another enemy of the United States and its allies, like North Korea or China?

It took weeks just to confirm that there was indeed someone who even fit that description. (It turned out that Williams’ middle name is John, and Doogie is his nickname in hacker circles.)

Then, as the weeks of reporting rolled on, things started to become much clearer.

The Russian connection

As I first revealed in October, Trenchant fired an employee after Williams, who was still at the time head of Trenchant, accused the employee of stealing and leaking Chrome zero-days. The story was even more intriguing because the employee told me that after he was fired, Apple notified him that someone had targeted his personal iPhone.

What I learned was just the tip of the iceberg. I had heard more from my sources, but we were still piecing parts of the story together.

Soon after, prosecutors made their first formal accusation against a man named Peter Williams for stealing trade secrets, which first surfaced in the U.S. public court system. In that first court document, prosecutors confirmed that the buyer of these trade secrets was a buyer in Russia.

However, there was no explicit reference to L3Harris nor Trenchant, nor the fact that the trade secrets that Williams stole were zero-days. Crucially, we still couldn’t confirm for certain that it was the same Peter Williams, who we thought would have access to highly sensitive exploits as Trenchant’s boss, and not some terrible case of mistaken identity.

We still weren’t there.

On a hunch and with nothing to lose, we contacted the Department of Justice to ask if they would confirm that the person in the document was in fact Peter Williams, the former boss of L3Harris Trenchant. A spokesperson confirmed.

Finally, the story was out. A week later, Williams pleaded guilty.

When I first heard of his story, while I trusted my sources, I remained skeptical. Why would someone like Williams do what the rumors claimed? But he did, and did so for money, prosecutors allege, which Williams then used to buy a house, jewelry, and luxury watches.

It was a remarkable fall from grace for Williams, once seen as an accomplished and brilliant hacker, and especially for someone who previously worked at Australia’s top foreign spy agency and served in the country’s military.

<span class="wp-element-caption__text">the L3Harris building in Burlington, Canada</span><span class="wp-block-image__credits"><strong>Image Credits:</strong>JHVEPhoto / Getty Images</span>

the L3Harris building in Burlington, CanadaImage Credits:JHVEPhoto / Getty Images

What happened to the stolen exploits?

We still don’t know specifically which exploits and hacking tools Williams stole and sold. Trenchant estimated a loss of $35 million, per court documents. But Williams’ lawyers said the stolen tools were not classified as a government secret.

We can glean some insight based on the circumstances of the case.

Given that the Justice Department said the stolen tools could be used to hack “millions of computers and devices,” it’s likely the tools refer to zero-days in popular consumer software, such as Android devices, Apple’s iPhones and iPads, and web browsers.

There is some evidence pointing in their direction. During a hearing last year, prosecutors read out loud a post published on X by Operation Zero, according to independent cybersecurity reporter Kim Zetter, who attended the hearing.

“Due to high demand on the market, we’re increasing payouts for top-tier mobile exploits,” read the post, which specifically mentioned Android and iOS. “As always, the end user is a non-NATO country.”

Operation Zero offers millions of dollars for details of security vulnerabilities in Android devices and iPhones, messaging apps like Telegram, as well as other kinds of software, such as Microsoft Windows, and hardware vendors, such as several brands of servers and routers.

Operation Zero claims to work with the Russian government. At the time Williams sold the exploits to the Russian broker, Putin’s full-scale invasion of Ukraine was already underway.

On the same day that Williams was sentenced, the U.S. Treasury announced it had imposed sanctions against Operation Zero and its founder Sergey Zelenyuk, calling the company a national security threat. This was the government’s first confirmation that Williams had sold the exploits to Operation Zero.

In its statement, the Treasury said the broker “sold those stolen tools to at least one unauthorized user.” At this point we don’t know who this user is. The user could be a foreign intelligence service, or it could be a ransomware gang, given that the Treasury also sanctioned Oleg Vyacheslavovich Kucherov, an alleged member of the Trickbot gang, who also allegedly worked with Operation Zero.

In a court document, prosecutors said that L3Harris was able to figure out that “an unauthorized vendor was selling a component” of one of the stolen trade secrets “by comparing company-specific vendor data found on a stolen component that matched.”

Prosecutors also said that Williams “recognized code he wrote and sold” to Operation Zero “being utilized by a South Korean broker,” further suggesting that both L3Harris and prosecutors know which tools were stolen and sold to Operation Zero.

Another unanswered question is: Did anyone, either the U.S. government or L3Harris, alert Apple, Google, or whichever tech company’s products were affected by the zero-day flaws, now that the exploits had leaked?

Any company or developer would want to know that someone could have used (or could still use) a zero-day against their users and customers so that they can patch the flaws as soon as possible. And at this point, the zero-days are of no use for L3Harris and its government customers.

When I asked Apple and Google, neither company responded to my inquiries. L3Harris did not respond either.

Who hacked the scapegoat, and why?

Then there’s the mystery of the scapegoat, who was fired after Williams accused him of stealing and leaking code.

At sentencing, Justice Department prosecutors confirmed that the employee was fired, saying Williams “stood idly by while another employee of the company was essentially blamed for [his] own conduct.” In response, Williams’ attorney rebuffed prosecutors, claiming that the former employee “was fired for misconduct,” citing claims of dual-employment and improper handling of the company’s intellectual property.

According to a court document submitted by Williams’ lawyers, as part of the L3Harris internal investigation, the company placed the employee on leave, seized his devices, transferred them to the U.S., and “offered them to the FBI.”

When reached for comment, an unnamed FBI spokesperson said the bureau had nothing to add apart from the Justice Department’s press release.

After being fired, that employee, whom we identified with the alias Jay Gibson, received a notification from Apple that his personal iPhone was targeted “with a mercenary spyware attack.”

Apple sends these notifications to users it thinks were the target of attacks using tools like those made by NSO Group or Intellexa.

Who tried to hack Gibson? He received the notification on March 5, 2025, more than six months after the FBI investigation had begun. The FBI “regularly interacted with [Williams] in late 2024 through the summer of 2025,” according to a court document.

Given the nature of the leaked tools, it is plausible that the FBI, or perhaps even a U.S. intelligence agency, targeted Gibson as part of the investigation into Williams’ leaks. But we just don’t know, and there’s a chance that neither the public, nor Gibson, will ever find out.

Updated to clarify 22nd paragraph attributing the tools’ lack of classification to Williams’ lawyers.

Source link

Visited 1 times, 1 visit(s) today

Related Article

Is there school tomorrow? See closure list for Feb. 26, and the whole week

Is there school tomorrow? See closure list for Feb. 26, and the whole week

As the state digs out from record-setting snow, Rhode Island public schools are continuing to announce closures for Thursday, Feb. 26, with some extending all week. Several schools have all canceled school for the remainder of the week, while others have shifted to distance learning for the week. Here are the Rhode Island public school

A swarm of Luanniao motherships

China Shows Off Plans For Aircraft Carrier That Deploys Ships From Space

Chinese state broadcaster CCTV has shown what might be the wildest concept video to come out of Beijing in years. It’s basically a rendered clip of a whole fleet of massive triangular grey motherships hovering at the edge of the Earth’s atmosphere, firing weapons into orbit and deploying futuristic fighter jets. Now, we’ve seen plenty

How many hours of sleep do you really need? The answer may surprise you

How many hours of sleep do you really need? The answer may surprise you

Turns out, some people need more, while others need less. (Getty) Are you one of those people who wake up bright-eyed and bushy-tailed at the first sight of sunlight? Or maybe you’re one of those night owls who gets a second wind when the rest of the world is tucking in for the night? Perhaps

Palestinians sit at a long table amid the rubble of destroyed buildings as they gather for iftar, the fast-breaking meal, during the Muslim holy month of Ramadan in Khan Younis, Gaza Strip, Thursday, Feb. 19, 2026. (AP Photo/Abdel Kareem Hana)

Trump Administration Hits Iran With New Sanctions as Nuclear Talks Near

WASHINGTON (AP) — The Trump administration on Wednesday imposed another tranche of sanctions on people and companies accused of enabling Iran’s ballistic missile program, drone production and illicit oil sales as the U.S. presses Tehran to make a deal ahead of nuclear talks this week. The latest round of talks between U.S. officials, including envoy

Photo: Winnebago County Jail

Rockford gymnastics booster club treasurer pleads guilty to embezzlement

ROCKFORD, Ill. (WTVO) — The treasurer of a Rockford-area gymnastics booster club has pleaded guilty to embezzling more than $34,000. Shondra Mclarty, 55, of Rockton, admitted as part of a plea agreement in federal court that she stole money from the Tumbling and Acro Boosters Club between 2023 and 2024. According to court records, board

FBI serves search warrants at LAUSD headquarters and superintendent's home

FBI serves search warrants at LAUSD headquarters and superintendent’s home

The FBI on Wednesday morning served search warrants at the Los Angeles Unified School District’s headquarters and the superintendent’s home. Federal officials served the warrants as part of an ongoing investigation, according to a person familiar with the matter who spoke on condition of anonymity to discuss the probe. The nature of the investigation and

A SuperAger takes a cognitive test in the lab. - From Shane Collins/Northwestern University

Scientists discover a key to staying mentally sharp in old age

People who have razor-sharp minds in their 80s and 90s — known as “SuperAgers” — produce twice the number of young neurons as cognitively healthy adults and 2.5 times as many as people with Alzheimer’s disease, a new study found. “This shows the aging brain has the capacity to regenerate — that’s huge,” said study

Six people arrested after three-month assault investigation in Clinton

Six people arrested after three-month assault investigation in Clinton

CLINTON, NY (WUTR/WFXV/WPNY) — Oneida County Sheriffs have arrested six people for their parts in an altercation in the village of Clinton in November. Sheriffs were called to the Wynn Hospital in Utica on Sunday, November 23 to speak with a victim of an assault on College Street in the village. Further investigation found that

2022 Tesla Model 3 Performance.

Parked Tesla Goes Up in Flames Moments After Owner Hears ‘Almighty Explosion’

A quiet residential street in rural England turned into a dramatic scene when a parked electric vehicle suddenly burst into flames, leaving its owner stunned and raising new questions about the risks tied to previously damaged EVs. The incident involved a Tesla owned by Rich Farrant, a 56-year-old resident of Compton Dando in Somerset. According

A paramedic administers a dose of the measles vaccine at a health center in Lubbock, Texas,  in February 2025, amid a large measles outbreak that led to the deaths of two children. - Ronaldo Schemidt/AFP/Getty Images

Few doctors have seen it before

At around 2 a.m., 7-year-old twin brothers arrived at Mission Hospital in Asheville. Both had a fever, a cough, a rash, pink eye, and cold symptoms. The boys sat in one waiting room and then another. Two hours and 20 minutes passed before the two were isolated, according to Centers for Medicare & Medicaid Services

Female manager standing at meeting room and having briefing with her team.

The 6 Hardest-Working States in the US—and 6 That Work the Least

Image Credit: Shutterstock. Americans work an average of 1,805 hours a year, which is more than workers in most other developed countries. Interestingly, some states consistently put in longer hours and have higher employment rates than others. WalletHub recently ranked all 50 states based on how hard their residents work. They looked at 10 different

Ross Stores (ROST) Earns $180 Target Amid Accelerating Card Spending Data

Ross Stores (ROST) Earns $180 Target Amid Accelerating Card Spending Data

We recently published an article titled 12 Best Retail Stocks to Buy According to Analysts. On February 23, Bernstein raised its price target for Ross Stores, Inc. (NASDAQ:ROST) to $180 from $170 while maintaining a Market Perform rating as part of a fourth-quarter preview for off-price retailers. The firm cited very strong holiday trends across

Artist's renderings show plans for a 591-car parking garage at HCA Florida Lawnwood Hospital, which is planned to open in early 2027.

Treasure Coast hospital planning new parking garage amid big expansion

FORT PIERCE — In the midst of an expansion, HCA Florida Lawnwood Hospital is one step closer to providing increased parking to meet its increase in beds and services. A major site plan to build a five-floor, 591-car parking garage on about 3½ acres at the southwest corner of the hospital complex was unanimously approved

The Duke and Duchess of Sussex attended a World Health Organization round-table event with key donors and humanitarian partners

Harry and Meghan arrive in Middle East for summit on refugees’ needs

The Duke and Duchess of Sussex have arrived in the Middle East for their first international trip together in 18 months. Prince Harry and Meghan will spend two days visiting Jordan to highlight efforts to support vulnerable communities affected by conflict and displacement. The couple, who stepped down as working royals in 2020, have travelled

President Trump delivering the first State of the Union address of his second term.

Trump Hails an Economic Turnaround Many Voters Don’t See

WASHINGTON—President Trump told a national audience on Tuesday that he had unleashed a new age of economic prosperity. One thing he didn’t say: I feel your pain. President Trump delivering the first State of the Union address of his second term. At the core of Trump’s State of the Union address was a calculation that

Photo for representation. (AFP)

How to get rich in modern China

The year of the fire horse, which began on February 17th, is hardly galloping along for many Chinese. A property bust and chronic deflation have eroded people’s assets, incomes and prospects. Residential property, where Chinese people store the bulk of their wealth, has lost a fifth of its value on average since 2021. Wage growth

A red 2026 Toyota Tacoma on a paved roadway.

Consumer Reports’ Most Reliable Car Brand Is No Longer Subaru

Reliability sells cars. A 2024 CarGurus study showed that reliability was a key influencing factor for 41% of buyers, more than those who consider budget or expected ownership costs. So bragging rights about dependability are a big deal for automakers. In Consumer Reports‘ latest findings, Japanese brands continue to dominate the podium on the organization’s

UGA professor removed from campus over video appearing to show him chatting with teenage boy

UGA professor removed from campus over video appearing to show him chatting with teenage boy

A University of Georgia professor has been removed from the classroom after a video that may have landed him in trouble with law enforcement. “Street Sweeperz TV” confronted the professor and accused him of chatting inappropriately with someone he believed was a teenage boy. Channel 2’s Michael Doudna learned the independent group started operating six

0
Would love your thoughts, please comment.x
()
x