DIA Insider Used Email to Offer Secrets to “Spy”

The Register Security · Medium sophistication
Last updated August 31, 2026

A Defense Intelligence Agency IT specialist pleaded guilty after an FBI sting caught him trying to provide classified information to someone he believed was a foreign government spy. The case includes a clear, simulation-ready workflow: an initial outreach email offering secrets, a move to encrypted messaging, and instructions for dead-drops and file transfers.

How the outreach unfolded

This case, drawn from a Defense Intelligence Agency IT specialist's guilty plea, offers a clear, real-world sequence of how an insider-initiated approach to a foreign contact can play out over email. The individual created a new email account and sent a message with the subject line referencing outreach from a DIA officer, stating a willingness to share classified information, including completed intelligence products and unprocessed intelligence. The email also included a photo of a government ID used to access his workplace, with name and image redacted, along with a username for an encrypted messaging platform to continue the conversation.

Why the approach could have succeeded

The outreach combined several elements that make this kind of contact plausible to a receiving party: an official-sounding subject line, a specific and detailed offer of access, and a piece of physical evidence (the redacted ID photo) intended to establish legitimacy. The pivot to encrypted messaging is a common technique for moving a conversation off channels that might be monitored or logged, reducing the chance of early detection. In this case, the FBI responded as part of an undercover operation, replying with encouraging, trust-building language and asking for more detail about the sender's role and access.

What to watch for

Security and insider threat teams reviewing this pattern should watch for:

  • Unsolicited messages offering or soliciting sensitive or classified information
  • Newly created or unfamiliar email accounts used to initiate contact
  • Attempts to shift a conversation to encrypted or unofficial messaging platforms
  • Use of credentials or ID imagery as a trust-building device
  • Flattering or encouraging replies designed to keep a sensitive conversation going

Building organizational resistance

Organizations handling sensitive or classified material benefit from clear, well-known reporting paths for any contact that resembles this pattern, whether the recipient is the one initiating contact or the one being approached. Staff should be trained to treat requests to move conversations to encrypted platforms as an escalation trigger, and to verify any claimed official identity or credentials through established, independent channels rather than trusting materials included in the message itself. Because this activity can begin with something as simple as a single email, ensuring that employees know how and where to report concerning contact quickly is a practical, low-cost control that supports broader insider threat programs across government, defense, and intelligence environments.

Key findings

  • The insider initiated contact via a newly created email account and a specific subject line, offering to share classified materials.
  • The outreach included credibility builders (describing his role and sharing a photo of a government ID) and a pivot to encrypted messaging.
  • The FBI replied and continued the conversation as part of an undercover operation, ultimately arranging collection/transfer steps that led to arrest.

Who’s being targeted

  • Commonly targeted roles: Government employees, Defense and intelligence staff, Security/Insider Threat teams, IT administrators, Employees with access to sensitive data.
  • Affected industries: Government / Intelligence, National security.
  • Attack channels: email.
  • Impersonated: USA Defense Intelligence Agency (DIA) Officer, Foreign government representative / spy contact.

Red flags to watch for

  • Unsolicited outreach offering restricted/classified information
  • Newly created email account used to initiate contact
  • Attempt to move the conversation to encrypted messaging
  • Flattering/encouraging language designed to build trust quickly
  • Requests to expand on access and job duties
  • Engagement with an unsolicited sensitive-data offer
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the DIA insider first make contact?

He sent an initial email from a newly created account with the subject line offering outreach from a DIA officer, stating he was willing to share classified information.

What tactics were used to build trust in the outreach?

The email included a picture of his government ID with name and image redacted, and it pointed the recipient to an encrypted messaging platform to continue the conversation.

Why is moving a conversation to encrypted messaging a red flag?

It is an attempt to move communication off official, monitored channels, which is a pattern security and insider threat teams should treat as reportable.

What should employees do if they receive a similar unsolicited offer?

Treat it as a reportable security incident regardless of claimed titles or credentials, and verify any legitimacy claims through known official channels rather than responding directly.

Read the video transcript

Imagine this lands in your inbox: subject line, “Outreach from USA Defense Intelligence Agency (DIA) Officer.” Inside, they say, “I am willing to share classified information I have access to,” attach a photo of a government ID, and give you a username to move the chat to an encrypted messaging app. In the real case, the FBI replied, played along on email and encrypted chat, and the insider was arrested. Your aha: any unsolicited offer of restricted or classified info is itself a security incident. If you ever get an email like this, do not respond or move to encrypted chat, capture it and report it immediately through our security incident channel.

MITRE ATT&CK techniques

Categories

Similar attacks

SilkParasite Hits Central Asia via Phish Docs

SilkParasite Hits Central Asia via Phish Docs

Bitdefender reports a China-linked espionage campaign (“SilkParasite”) targeting government bodies in Central Asia using spearphishing emails carrying malicious Microsoft Office documents. The malware is designed to stay quiet and blend in, including using Google Drive as a communications channel…

August 20, 2026
DPRK “Remote Worker” Scam Slips Into Real Jobs

DPRK “Remote Worker” Scam Slips Into Real Jobs

The article describes North Korean operatives posing as legitimate remote IT candidates to get hired, obtain real company credentials, and gain trusted internal access. It cites an FBI investigation into a DPRK remote IT worker at a U.S. federal agency and a research “hire-and-observe” operation…

August 17, 2026
Fake “FBI Agents” Target Scam Victims in DMs

Fake “FBI Agents” Target Scam Victims in DMs

The FBI’s IC3 warns that scammers are impersonating FBI/IC3 staff on social media and messaging apps, especially targeting people who have already been scammed. The criminals use convincing branding (logos, fake reviews) and may even use AI-generated deepfake videos to pressure victims into…

July 21, 2026
Fake FBI “IC3” Agents Re-Scam Past Victims

Fake FBI “IC3” Agents Re-Scam Past Victims

Scammers are posing as FBI staff who supposedly handle IC3 (Internet Crime Complaint Center) reports to trick people who have already been scammed once. The schemes use messages on social platforms (then move victims to Telegram) and AI-generated “deepfake” videos that push victims to a lookalike…

July 21, 2026
DPRK Job Applicants Use Fake IDs and Remote Laptop Gear

DPRK Job Applicants Use Fake IDs and Remote Laptop Gear

Huntress describes real investigations where suspected North Korean remote workers tricked companies into hiring them using stolen or doctored identity documents and tools to remotely control “employee” laptops. Cases span healthcare, financial services, and sales/marketing roles, showing a…

August 28, 2026
Fake N. Korean IT Workers Flood Job Applications

Fake N. Korean IT Workers Flood Job Applications

Research says a North Korea–linked operation (“PurpleDelta”) is using fake identities to apply for large volumes of remote IT jobs, sometimes successfully getting hired. Once inside a company, these “employees” can record meetings and steal sensitive information such as source code and internal…

August 19, 2026