Federal prosecutors have charged Peter Williams, a former executive at L3Harris Technologies’ cyber division, with stealing eight trade secrets from two unnamed companies and selling them to a Russian buyer for over $1.3 million. Williams, an Australian national who led Trenchant—a division specializing in hacking and surveillance tools for Western intelligence agencies—allegedly misappropriated confidential proprietary data between 2022 and 2025. Authorities are seeking to seize assets tied to the illicit profits, including real estate, luxury items, and funds in multiple bank and cryptocurrency accounts. The Department of Justice has not accused L3Harris or Trenchant of any wrongdoing, and the nature of the stolen trade secrets remains undisclosed.
Court documents indicate that Williams systematically transferred sensitive information over a period of more than three years, with the case surfacing after an internal investigation at Trenchant reportedly triggered by a leak of hacking tools. While Williams was reportedly arrested, federal officials later clarified he is not in federal custody. The Russian recipient of the stolen data has not been identified, and L3Harris has not commented on the case. An arraignment and possible plea agreement are scheduled in Washington, D.C., as authorities continue to investigate the extent of the breach and its implications for national security.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
U.S. authorities accused a former L3Harris executive and cyber director of stealing and selling the defense contractor's trade secrets to Russian interests. Multiple reports describe the case as involving sensitive proprietary information and resulting criminal charges against the former employee.
3 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcescworld.com
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.