{"id":203056,"date":"2025-11-03T21:44:28","date_gmt":"2025-11-03T21:44:28","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2025\/11\/03\/how-an-ex-l3harris-trenchant-boss-stole-and-sold-cyber-exploits-to-russia-techcrunch\/"},"modified":"2025-11-03T21:44:28","modified_gmt":"2025-11-03T21:44:28","slug":"how-an-ex-l3harris-trenchant-boss-stole-and-sold-cyber-exploits-to-russia-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2025\/11\/03\/how-an-ex-l3harris-trenchant-boss-stole-and-sold-cyber-exploits-to-russia-techcrunch\/","title":{"rendered":"How an ex-L3Harris Trenchant boss stole and sold cyber exploits to Russia | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Peter Williams, the former general manager of Trenchant, a division of defense contractor L3Harris that develops surveillance and hacking tools for Western governments, <a href=\"http:\/\/techcrunch.com\/2025\/10\/29\/former-l3harris-trenchant-boss-pleads-guilty-to-selling-zero-day-exploits-to-russian-broker\/\" target=\"_blank\" rel=\"noreferrer noopener\">pleaded guilty last week to stealing some of those tools and selling them to a Russian broker<\/a>. \u00a0<\/p>\n<p class=\"wp-block-paragraph\">A court document filed in the case, as well as exclusive reporting by TechCrunch and interviews with Williams\u2019 former colleagues, explained how Williams was able to steal the highly valuable and sensitive exploits from Trenchant.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Williams, a 39-year-old Australian citizen who was known inside the company as \u201cDoogie,\u201d admitted to prosecutors that he stole and sold eight exploits, or \u201c<a href=\"https:\/\/techcrunch.com\/2025\/04\/25\/techcrunch-reference-guide-to-security-terminology\/#zero-day\" target=\"_blank\" rel=\"noreferrer noopener\">zero-days<\/a>,\u201d which are security flaws in software that are unknown to its maker and are extremely valuable to hack into a target\u2019s devices. Williams said some of those exploits, which he stole from his own company, Trenchant,\u00a0were worth $35 million, but he only received $1.3 million in cryptocurrency from the Russian broker. Williams sold the eight exploits over the course of several years, between 2022 and July 2025.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Thanks to his position and tenure at Trenchant, according to the court document, Williams \u201cmaintained \u2018super-user\u2019 access\u201d to the company\u2019s \u201cinternal, access-controlled, multi-factor authenticated\u201d\u00a0secure network where its hacking tools were stored and to which only employees with a \u201cneed to know\u201d had access. \u00a0<\/p>\n<p class=\"wp-block-paragraph\">As a \u201csuper-user,\u201d Williams could view all the activity, logs, and data associated with Trenchant\u2019s secure network, including its exploits, the court document notes. Williams\u2019 company network access gave him \u201cfull access\u201d to Trenchant\u2019s proprietary information and trade secrets.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Abusing this wide-ranging access, Williams used a portable external hard drive to transfer the exploits out of the secure networks in Trenchant\u2019s offices in Sydney, Australia, and Washington, D.C., and then onto a personal device. At that point, Williams sent the stolen tools via encrypted channels to the Russian broker, per the court document. \u00a0<\/p>\n<p class=\"wp-block-paragraph\">A former Trenchant employee with knowledge of the company\u2019s internal IT systems told TechCrunch that\u00a0Williams \u201cwas in the very high echelon of trust\u201d within the company as part of the senior leadership team. Williams had worked at the company for years, including prior to L3Harris\u2019 acquisition of <a rel=\"nofollow noopener\" href=\"https:\/\/www.vice.com\/en\/article\/iphone-zero-days-inside-azimuth-security\/\" target=\"_blank\">Azimuth and <\/a><a href=\"https:\/\/www.vice.com\/en\/article\/iphone-zero-days-inside-azimuth-security\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Linchpin<\/a><a rel=\"nofollow noopener\" href=\"https:\/\/www.vice.com\/en\/article\/iphone-zero-days-inside-azimuth-security\/\" target=\"_blank\"> Labs<\/a>, two sister startups that <a href=\"http:\/\/cyberscoop.com\/l3-acquires-azimuth-and-linchpin\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">merged into Trenchant<\/a>. \u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cHe was, in my opinion, perceived to be beyond reproach,\u201d said the former employee, who asked to remain anonymous as they were not authorized to speak about\u00a0their\u00a0work at Trenchant. \u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cNo one had any supervision over him at all. He was kind of allowed to do things the way he wanted to,\u201d they said.\u00a0<\/p>\n<div class=\"article-block block--callout block--right has-green-500-background-color\">\n<h4 class=\"block--callout__title\">Contact Us<\/h4>\n<p>\t\t\tDo you have more information about this case, and the alleged leak of Trenchant hacking tools? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram, Keybase and Wire @lorenzofb, or <a href=\"https:\/\/techcrunch.com\/2025\/11\/03\/how-an-ex-l3-harris-trenchant-boss-stole-and-sold-cyber-exploits-to-russia\/mailto:lorenzo@techcrunch.com\/\" target=\"_blank\" rel=\"noopener\">by email<\/a><a href=\"https:\/\/techcrunch.com\/2025\/11\/03\/how-an-ex-l3-harris-trenchant-boss-stole-and-sold-cyber-exploits-to-russia\/mailto:lorenzo@techcrunch.com\/\" target=\"_blank\" rel=\"noopener\">.<\/a> \t\t<\/div>\n<p class=\"wp-block-paragraph\">Another former employee, who also asked to not be named,\u00a0said that \u201cthe general awareness is that whoever is the [general manager] would have unfettered access to everything.\u201d\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Before the acquisition, Williams worked at Linchpin Labs, and before then at Australian Signals Directorate, the country\u2019s intelligence agency tasked with digital and electronic eavesdropping, according to the <a href=\"https:\/\/risky.biz\/RB812\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">cybersecurity podcast Risky Business<\/a>. \u00a0<\/p>\n<p class=\"wp-block-paragraph\">Sara Banda, a spokesperson for L3Harris, did not respond to a request for comment. \u00a0<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-grave-damage\">\u201cGrave damage\u201d\u00a0<\/h2>\n<p class=\"wp-block-paragraph\">In October 2024, Trenchant \u201cwas alerted\u201d that one of its products had leaked and was in the possession of \u201can unauthorized software broker,\u201d per the court document. Williams was put in charge of the investigation into the leak, which ruled out a hack of the company\u2019s network but found that a former employee\u00a0\u201chad improperly accessed the internet from an air-gapped device,\u201d according to the court document. \u00a0<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/techcrunch.com\/2025\/10\/21\/apple-alerts-exploit-developer-that-his-iphone-was-targeted-with-government-spyware\/\" target=\"_blank\" rel=\"noreferrer noopener\">As TechCrunch previously and exclusively reported<\/a>, Williams fired a Trenchant developer in February 2025 after accusing him of being double employed. The fired employee later learned from some of his former colleagues that Williams accused him of stealing Chrome zero-days, which he had no access to since he worked on developing exploits for iPhones and iPads. By March, Apple notified the former employee that his iPhone had been targeted by \u201cmercenary spyware attack.\u201d \u00a0<\/p>\n<p class=\"wp-block-paragraph\">In an interview with TechCrunch, the former Trenchant developer said he believed Williams framed him to cover up his own actions. It\u2019s unclear if the former developer is the same employee mentioned in the court document. \u00a0<\/p>\n<p class=\"wp-block-paragraph\">In July, the FBI interviewed Williams, who told the agents that \u201cthe most likely way\u201d to steal products from the secure network would be for someone with access to that network to download the products to an \u201cair\u2011gapped device\u00a0\u2026 like a mobile telephone or external drive.\u201d (An air-gapped device is a computer or server that has no access to the internet.) \u00a0<\/p>\n<p class=\"wp-block-paragraph\">As it turned out, that\u2019s exactly what Williams confessed to the FBI in August after being confronted with evidence of his crimes. Williams told the FBI that he recognized his code being used by a South Korean broker after he sold it to the Russian broker; though, it remains unclear how Trenchant\u2019s code ended up with the South Korean broker to begin with.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Williams used the alias \u201cJohn Taylor,\u201d a foreign email provider, and unspecified encrypted apps when interacting with the Russian broker, likely Operation Zero. This is <a href=\"https:\/\/techcrunch.com\/2023\/09\/27\/russian-zero-day-seller-offers-20m-for-hacking-android-and-iphones\/\" target=\"_blank\" rel=\"noreferrer noopener\">a Russia-based broker that offers up to $20 million<\/a> for tools to hack Android phones and iPhones, which it says it sells to \u201cRussian private and government organizations only.\u201d \u00a0<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.wired.com\/story\/peter-williams-trenchant-trade-secrets-theft-russian-firm\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Wired was first to report<\/a> that Williams likely sold the stolen tools to Operation Zero, given that the court document mentions a September 2023 post on social media announcing an increase in the unnamed broker\u2019s \u201cbounty payouts from $200,000 to $20,000,000,\u201d which matches <a href=\"https:\/\/x.com\/opzero_en\/status\/1706762507631677760\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">an Operation Zero post on X<\/a> at the time. \u00a0<\/p>\n<p class=\"wp-block-paragraph\">Operation Zero did not respond to TechCrunch\u2019s request for comment. \u00a0<\/p>\n<p class=\"wp-block-paragraph\">Williams sold the first exploit for $240,000, with the promise of additional payments after confirming the tool\u2019s performance, and for subsequent technical support to keep the tool updated. After this initial sale, Williams sold another seven exploits, agreeing to a total payment of $4 million, although he ended up only receiving $1.3 million, according to the court document. \u00a0<\/p>\n<p class=\"wp-block-paragraph\">Williams\u2019 case has rocked the offensive cybersecurity community, where his rumored arrest had been a topic of conversation for weeks, according to multiple people who work in the industry. \u00a0<\/p>\n<p class=\"wp-block-paragraph\">Some of these industry insiders see Williams\u2019 actions as causing grave damage.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cIt\u2019s a betrayal to the Western national security apparatus, and it\u2019s a betrayal towards the worst kind of threat actor that we have right now, which is Russia,\u201d the former Trenchant employee with knowledge of the company\u2019s IT systems told TechCrunch. \u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cBecause these secrets have been given to an adversary that absolutely is going to undermine our capabilities and is going to potentially even use them against other targets.\u201d\u00a0<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2025\/11\/03\/how-an-ex-l3-harris-trenchant-boss-stole-and-sold-cyber-exploits-to-russia\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Peter Williams, the former general manager of Trenchant, a division of defense contractor L3Harris that develops surveillance and hacking tools for Western governments, pleaded guilty last week to stealing some of those tools and selling them to a Russian broker. \u00a0 A court document filed in the case, as well as exclusive reporting by TechCrunch [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":203057,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-203056","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/203056","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=203056"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/203056\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/203057"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=203056"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=203056"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=203056"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}