Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

OpenAI hits back at Google with GPT-5.2 after ‘code red’ memo.

Google’s AI testing feature for clothes now only works with a selfie

Eclipse Energy’s microbes can turn dormant oil wells into hydrogen factories

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    OpenAI hits back at Google with GPT-5.2 after ‘code red’ memo.

    14 December 2025

    Trump’s AI executive order promises ‘a rulebook’ – startups may find legal loophole instead

    13 December 2025

    Ok, so what’s up with the LinkedIn algo?

    12 December 2025

    Google Released Its Deepest Research AI Agent To Date — The Same Day OpenAI Dropped GPT-5.2

    12 December 2025

    Disney hits Google with cease and desist alleging ‘massive’ copyright infringement

    11 December 2025
  • Apps

    Google’s AI testing feature for clothes now only works with a selfie

    14 December 2025

    DoorDash driver faces felony charges after allegedly spraying customers’ food

    13 December 2025

    Google Translate now lets you listen to real-time translations on your headphones

    13 December 2025

    With iOS 26.2, Apple lets you bring back Liquid Glass again — this time on the lock screen

    12 December 2025

    World launches its ‘super app’, including payment encryption and encrypted chat features

    12 December 2025
  • Crypto

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025

    Only 5 days until Disrupt 2025 sets the startup world on fire

    22 October 2025
  • Fintech

    Coinbase starts onboarding users again in India, plans to do fiat on-ramp next year

    7 December 2025

    Walmart-backed PhonePe shuts down Pincode app in yet another step back in e-commerce

    5 December 2025

    Nexus stays out of AI, keeping half of its new $700M fund for India startup

    4 December 2025

    Fintech firm Marquis notifies dozens of US banks and credit unions of data breach after ransomware attack

    3 December 2025

    Revolut hits $75 billion valuation in new capital raise

    24 November 2025
  • Hardware

    Pebble founder unveils $75 AI smart ring to record short notes with the push of a button

    10 December 2025

    Amazon’s Ring launches controversial AI-powered facial recognition feature on video doorbells

    10 December 2025

    Google’s first AI glasses are expected next year

    9 December 2025

    eSIM adoption is on the rise thanks to travel and device compatibility

    6 December 2025

    AWS re:Invent was an all-in pitch for AI. Customers may not be ready.

    5 December 2025
  • Media & Entertainment

    Disney signs deal with OpenAI to allow Sora to create AI videos with its characters

    11 December 2025

    YouTube TV will launch genre-based subscription plans in 2026

    11 December 2025

    Founder of AI startup Tavus says users talk to AI Santa ‘for hours’ a day

    10 December 2025

    Spotify releases music videos in the US and Canada for Premium subscribers

    9 December 2025

    Amazon Music’s 2025 Delivered is now here to compete with Spotify Wrapped

    9 December 2025
  • Security

    The flaw in the photo booth manufacturer’s website exposes customers’ photos

    13 December 2025

    Home Depot exposed access to internal systems for a year, researcher says

    13 December 2025

    Security flaws in the Freedom Chat app exposed users’ phone numbers and PINs

    11 December 2025

    Petco takes down Vetco website after exposing customers’ personal information

    10 December 2025

    Petco’s security bug affected customers’ SSNs, driver’s licenses and more

    9 December 2025
  • Startups

    Eclipse Energy’s microbes can turn dormant oil wells into hydrogen factories

    13 December 2025

    Interest in Spoor’s AI bird tracking software is soaring

    13 December 2025

    Retro, a photo-sharing app for friends, lets you ‘time travel’ to your camera roll

    12 December 2025

    On Me Raises $6M to Shake Up the Gift Card Industry

    12 December 2025

    1X has struck a deal to send its ‘homemade’ humanoids to factories and warehouses

    11 December 2025
  • Transportation

    Inside Rivian’s big bet on self-driving with artificial intelligence

    13 December 2025

    Zevo wants to add robotaxis to its car-sharing fleet, starting with newcomer Tensor

    13 December 2025

    Driving aboard Rivian’s fight for autonomy

    12 December 2025

    Rivian goes big on autonomy, with custom silicon, lidar and a hint of robotaxis

    12 December 2025

    Rivian’s AI assistant is coming to its electrics in early 2026

    11 December 2025
  • Venture

    Runware raises $50 million in Series A to make it easier for developers to create images and videos

    12 December 2025

    Stanford’s star reporter understands Silicon Valley’s startup culture

    12 December 2025

    The market has “changed” and founders now have the power, VCs say

    11 December 2025

    Tiger Global plans cautious business future with new $2.2 billion fund

    8 December 2025

    Sources: AI-powered synthetic research startup Aaru raises Series A at $1B ‘headline’ valuation

    6 December 2025
  • Recommended Essentials
TechTost
You are at:Home»Security»How a former boss of L3Harris Trenchant stole and sold cyber-exploits to Russia
Security

How a former boss of L3Harris Trenchant stole and sold cyber-exploits to Russia

techtost.comBy techtost.com4 November 202506 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
How A Former Boss Of L3harris Trenchant Stole And Sold
Share
Facebook Twitter LinkedIn Pinterest Email

Peter Williams, the former managing director of Trenchant, a division of defense contractor L3Harris that develops surveillance and hacking tools for Western governments, pleaded guilty last week to stealing some of those tools and selling them to a Russian broker.

A court document filed in the case, as well as an exclusive report from TechCrunch and interviews with Williams’ former colleagues, explained how Williams was able to steal the highly valuable and sensitive assets from Trenchant.

Williams, a 39-year-old Australian citizen known inside the company as “Doogie,” admitted to prosecutors that he stole and sold eight exploits, or “zero-days,” which are security flaws in software that are unknown to their maker and are extremely valuable for hacking a target’s devices. Williams said some of those exploits, which he stole from his own company, Trenchant, were worth $35 million, but he only received $1.3 million in cryptocurrency from the Russian broker. Williams sold the eight exploits over several years, between 2022 and July 2025.

By virtue of his position and tenure at Trenchant, according to the court document, Williams “maintained ‘superuser’ access to the company’s ‘internal, access-controlled, multi-factor authentication’ secure network where its hacking tools were stored and to which only employees with a ‘need to know’ had access.”

As a “super-user,” Williams could see all activity, logs and data related to Trenchant’s secure network, including his exploits, the court document notes. Access to Williams’ company network gave him “full access” to Trenchant’s proprietary information and trade secrets.

Exploiting this wide range of access, Williams used a portable external hard drive to transfer the exploits from secure networks to Trenchant’s offices in Sydney, Australia and Washington, DC, and then onto a personal device. At that point, Williams sent the stolen tools through encrypted channels to the Russian broker, according to the court document.

A former Trenchant employee with knowledge of the company’s internal IT systems told TechCrunch that Williams “was at a very high level of trust” within the company as a member of the senior leadership team. Williams had worked at the company for years, even before the L3Harris acquisition Azimuth and Central lever Laboratoriestwo sister newcomers who merged into Trenchant.

“It was considered, in my opinion, to be an eyesore,” said the former employee, who asked to remain anonymous as they were not authorized to speak about their work at Trenchant.

“No one had any supervision over him at all. He was allowed to do things as he pleased,” they said.

Contact us

Do you have more information about this case and the alleged leak of Trenchant hacking tools? From a non-working device, Lorenzo Franceschi-Bicchierai can be reached securely on Signal at +1 917 257 1382 or via Telegram, Keybase and Wire @lorenzofb or via email.

Another former employee, who also asked not to be named, said “the general perception is that whoever the [general manager] he would have unlimited access to everything.”

Before the acquisition, Williams worked at Linchpin Labs and before that at the Australian Signals Directorate, the country’s intelligence agency tasked with digital and electronic eavesdropping, according to Risky Business cyber security podcast.

Sara Banda, a spokeswoman for L3Harris, did not respond to a request for comment.

“Severe Damage”

In October 2024, Trenchant was “notified” that one of its products had been leaked and was in the possession of an “unauthorized software broker,” according to the court document. Williams was put in charge of the leak investigation, which ruled out a breach of the company’s network but found that a former employee “improperly accessed the Internet from an air-gapped device,” according to the court document.

As previously and exclusively reported by TechCrunch, Williams fired a Trenchant developer in February 2025 after accusing him of double-dealing. The fired employee later learned from some of his former colleagues that Williams accused him of stealing Chrome zero-days, which he had not had access to since he worked on developing iPhone and iPad exploits. By March, Apple notified the former employee that his iPhone had been the target of a “mercenary spyware attack.”

In an interview with TechCrunch, the former Trenchant developer said he believed Williams was framing him to cover up his own actions. It’s unclear if the former developer is the same employee listed in the court document.

In July, the FBI interviewed Williams, who told agents that “the most likely way” to steal products from the secure network would be for someone with access to that network to download the products to an “air-gapped device … like a cell phone or external drive.” (An air-gapped device is a computer or server that does not have internet access.)

As it turns out, that’s exactly what Williams confessed to the FBI in August after being confronted with evidence of his crimes. Williams told the FBI that he recognized his code was being used by a South Korean broker after he sold it to the Russian broker. However, it remains unclear how Trenchant’s code ended up on the South Korean broker.

Williams used the alias “John Taylor,” a foreign email provider, and unspecified encrypted apps when interacting with the Russian broker, possibly Operation Zero. It’s a Russia-based broker offering up to $20 million for tools to hack Android phones and iPhones, which it says it sells to “Russian private and government organizations only.”

Wired was the first to report that Williams likely sold the stolen tools to Operation Zero, since the court document cites a September 2023 social media post announcing an increase in the anonymous broker’s “grant payments from $200,000 to $20,000,000,” which fits an Operation Zero location on X at that time.

Operation Zero did not respond to TechCrunch’s request for comment.

Williams sold the first exploit for $240,000, with the promise of additional payments after the tool’s performance was confirmed and subsequent technical support to keep the tool updated. After that initial sale, Williams sold seven more exploits, agreeing to a total payment of $4 million, though he ended up receiving only $1.3 million, according to the court document.

Williams’ case has shocked the hacker cybersecurity community, where his rumored arrest has been a topic of discussion for weeks, according to several people who work in the industry.

Some of these industry insiders see Williams’ actions as causing serious damage.

“It’s a betrayal of the Western national security apparatus, and it’s a betrayal of the worst kind of threat actor we have right now, which is Russia,” the former Trenchant employee with knowledge of the company’s IT systems told TechCrunch.

“Because these secrets have been given to an adversary who is definitely going to undermine our capabilities and potentially use them against other targets as well.”

Acute Azimuth boss cyber security cyberexploits Exclusive infosec L3harris labs with hoop Peter Williams Russia sold Spyware stole Trenchant US Department of Justice Zero-days
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleElad Gil Which AI Markets Have Winners — And Which Are Still Wide Open?
Next Article TikTok announces its first US awards show
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Eclipse Energy’s microbes can turn dormant oil wells into hydrogen factories

13 December 2025

The flaw in the photo booth manufacturer’s website exposes customers’ photos

13 December 2025

Zevo wants to add robotaxis to its car-sharing fleet, starting with newcomer Tensor

13 December 2025
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

OpenAI hits back at Google with GPT-5.2 after ‘code red’ memo.

14 December 2025

Google’s AI testing feature for clothes now only works with a selfie

14 December 2025

Eclipse Energy’s microbes can turn dormant oil wells into hydrogen factories

13 December 2025
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Coinbase starts onboarding users again in India, plans to do fiat on-ramp next year

7 December 2025

Walmart-backed PhonePe shuts down Pincode app in yet another step back in e-commerce

5 December 2025

Nexus stays out of AI, keeping half of its new $700M fund for India startup

4 December 2025
Startups

Eclipse Energy’s microbes can turn dormant oil wells into hydrogen factories

Interest in Spoor’s AI bird tracking software is soaring

Retro, a photo-sharing app for friends, lets you ‘time travel’ to your camera roll

© 2025 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.