Nathan Vilas Laatsch, a former civilian IT specialist assigned to the Defense Intelligence Agency's security and Insider Threat Division, pleaded guilty to attempting to provide classified U.S. intelligence to a person he believed represented a friendly foreign government. Holding a Top Secret clearance, Laatsch manually copied classified material from DIA systems, concealed notes while leaving secure facilities, and created files for transfer; he reportedly sought citizenship from the foreign nation and cited opposition to the administration.
In an FBI undercover operation, Laatsch left a USB drive in an Arlington, Virginia, park for an undercover agent, then attempted a second transfer on May 29, 2025, when he was arrested. The recovered device held nine documents, including eight marked Top Secret/Sensitive Compartmented Information, covering intelligence-collection methods, foreign military exercises, and related analysis. Laatsch admitted the conduct and agreed to a recommended prison term of 11 to 18 years; the court could impose life imprisonment and a $250,000 fine.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
On August 27, 2026, Laatsch pleaded guilty to attempting to transmit classified U.S. information to a foreign government. His plea agreement recommended an 11-to-18-year sentence, while the court could impose up to life imprisonment and a $250,000 fine.
On May 29, 2025, Laatsch electronically transferred files from his personal computer at an Arlington park picnic table as part of a second FBI-arranged dead drop. FBI agents arrested him after the transfer attempt; he later admitted the offenses during questioning.
Between May 15 and May 27, 2025, Laatsch again copied classified information by hand at DIA and smuggled the notes from the facility, including by concealing them in his socks.
On May 1, 2025, Laatsch placed a thumb drive at a dead-drop location in an Arlington, Virginia park for a person he believed represented the foreign government. The FBI recovered the device, which contained nine documents, including eight marked Top Secret/Sensitive Compartmented Information.
From April 28 through April 30, 2025, Laatsch accessed classified information at work and transcribed it by hand into a notebook. He concealed the handwritten pages in his socks and, on one occasion, in his lunchbox when leaving the DIA office.
In March 2025, DIA IT specialist Nathan Vilas Laatsch used a newly created email account to offer classified intelligence products and documentation to an overseas government described as friendly. The FBI learned of the offer and began an undercover operation using an agent posing as a foreign intelligence contact.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcedatabreaches.net
Open sourcescworld.com
Open sourcetheregister.com
Open sourcenextgov.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.