A former L3Harris executive, Peter Williams, was sentenced to 87 months (about seven years) in U.S. federal prison after pleading guilty to theft of trade secrets tied to the removal and sale of at least eight zero-day exploit components/cyber tools from Trenchant (L3Harris’ specialized unit supplying exploits to the U.S. government and select allies). Prosecutors said the stolen materials were intended for restricted government use; Williams allegedly leveraged his access over several years, received about $1.3 million in cryptocurrency, and the theft was estimated to have caused $35 million in losses to the contractor. Court reporting also noted Williams’ prior service with Australia’s signals intelligence community and that Trenchant traces back to L3Harris’ acquisition of Australian exploit-focused firms.
The U.S. Treasury’s OFAC simultaneously imposed sanctions on Operation Zero—a St. Petersburg-based Russian exploit brokerage—and its founder Sergey Zelenyuk, citing national security risks from acquiring and reselling zero-days and related tooling that could enable ransomware or other malicious activity. U.S. officials said Operation Zero obtained the stolen Trenchant tools and then resold them to unauthorized users, and multiple reports linked the sanctions action to the Williams case (where the buyer was previously anonymized in court as “Company 3”). Reporting also described Operation Zero’s public market for high-value mobile and app exploits (including past offers for Android, iOS, and Telegram), its marketing toward non-NATO customers and foreign intelligence services, and additional U.S. measures including State Department sanctions and action under the Protecting American Intellectual Property Act, plus sanctions on an affiliated UAE entity Special Technology Services (STS) and other associated parties.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Court reporting said a further hearing on restitution in the Peter Williams case was set for May 12, 2026, to address financial recovery tied to the theft and sale of the stolen cyber tools.
On February 24, 2026, a U.S. court sentenced former L3Harris/Trenchant executive Peter Williams to 87 months in prison for stealing and selling eight trade-secret exploit tools to Operation Zero. The court also ordered forfeiture of proceeds and assets, and prosecutors said the theft caused about $35 million in losses.
On February 24, 2026, the U.S. Treasury sanctioned Sergey Zelenyuk, Operation Zero/Matrix LLC, and associated individuals and entities, while the State Department designated Zelenyuk, Operation Zero, and UAE-based Special Technology Services. Officials described it as the first use of PAIPA sanctions tied to theft of U.S. trade-secret cyber tools.
Peter Williams pleaded guilty to two counts of theft of trade secrets after U.S. investigators tied him to the theft and sale of at least eight exploit components from his employer to the Russian broker.
During 2022 to 2025, Williams sold at least eight stolen trade-secret exploit tools to Operation Zero under multiple arrangements, receiving about $1.3 million in cryptocurrency. U.S. authorities later said some of the tools were resold to at least one unauthorized user.
Between 2022 and 2025, Peter Williams allegedly stole proprietary zero-day exploit components and other cyber tools from Trenchant, an L3Harris unit whose capabilities were intended for U.S. government and allied use.
U.S. authorities said Matrix LLC, publicly operating as Operation Zero, began operating in 2021 as a St. Petersburg-based broker buying and reselling zero-days and spyware to non-NATO customers, including Russian government-linked buyers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
17 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcethecyberexpress.com
Open sourcehome.treasury.gov
Open sourcetechcrunch.com
Open sourcetechcrunch.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.