The recent plea agreement between the Department of Justice and Nathan Vilas Laatsch is a classic insider risk-becomes-a-reality case. In this instance, Laatsch pled guilty to a single count of Distribution of National Defense Information.

We learned that he had become disillusioned with the current administration of the United States and unilaterally decided that sharing sensitive information from within the Defense Intelligence Agency’s insider risk program to a foreign country was appropriate. The Washington Post tells us the country was Germany.

What makes this case especially heinous is that Laatsch was part of the team operating within the highly sensitive insider risk program. In essence, we have an instance of the “watcher” breaking trust. The recipient of the intriguing entrée offering classified information contacted the United States, which allowed the Federal Bureau of Investigation to feed the miscreant enough rope to effectively hang himself.

This begs the question: who is watching the watchers?

Laatsch: The insider who volunteered

Laatsch, a 29-year-old resident of Alexandria, VA, obtained his B.S. in Cyber Security from Florida Polytechnic University in 2018. The court documents tell us he joined the DIA in 2019, held a Top Secret security clearance, and also had appropriate special compartments.

In his initial correspondence to the foreign entity, he identified himself to be a member of the technical team within the insider risk program via email sent in early-2025. As bona fides, he attached images of two government identification cards – with photo and name redacted. The FBI was subsequently able to associate these IDs directly to Laatsch.

His entrée: I am an officer of the Defense Intelligence Agency (DIA) serving in a technical role in support of our internal Office of Security (SEC). The recent actions of the current administration are extremely disturbing to me … I do not agree or align with the values of this administration and intend to act to support the values that the United States at one time stood for. To this end, I am willing to share classified information that I have access to, which are completed intelligence products, some unprocessed intelligence, and other assorted classified documentation.

As noted, the FBI was provided with the email and attachments and began their communication with Laatsch over the course of several weeks via a messenger application. He noted that “he had access to multiple repositories containing classified information.” He also confirmed that he had removed classified information from his workplace.

Dead drops and covert communications

The FBI moved to have him place classified information in a “dead drop” site in a public park in Arlington, VA. The site was subsequently loaded by Laatsch, an act observed by the FBI. The FBI retrieved a thumb-drive, which contained nine documents that included information classified as SECRET and TOP SECRET. He went on to conduct a second operational act, providing classified materials via impersonal communication, he sat at a designated picnic table in an Arlington park with a laptop and executed an electronic file transfer of over 20 documents.

In late-May 2025, Laatsch was arrested. His case, given the sensitivity of the information at risk required CIPA procedures be followed. On August 26, Laatsch pled guilty.

We learned from his plea and the statement of facts how on April 28, 29, and 30 2025, Laatsch was observed accessing his classified workstation, making notes in a notebook and on paper, which he hid in his socks or the bottom of his lunch box, and exfiltrated out of the building. In addition, the DIA workplace video (in place or placed specifically to monitor Laatsch is not clear) captured Laatsch’s actions.

On May 1, 2025 he loaded the Arlington dead drop, with the USB containing nine documents and the following note:

I am including his [sic] additional document to provide some additional context on the products, selection rationale, and notes having now practically done this. I choose to include … a decent sample size … and decently demonstrate the range of types of products. This is not all encompassing, but it should give a good idea. Whenever possible, I have retained classification markings. This in general applies to the formatting (bolding, italics, etc.) which I have tried to preserve for accuracy. This does not extend to original font, size, and visual embellishments that are sometimes used in original documents. There was no direction provided on topics of interest, so I selected them partially based on assumed interest. I have to the best of my ability attempted to copy the products by hand, but I cannot guarantee that every single word is completely correct. If there are any mistakes, they would only be a basic word or two, and nothing that would alter the content or meaning of the product. As anticipated, the process of manually copying by hand will be time intensive. Many of the provided products took around 40-60 minutes to fully complete, and often two full pages of notebook paper per-product. I did not choose products which were significantly longer than what I’ve noted as a ‘standard’ length.

The DOJ tells us, “After receiving confirmation that the drive had been received, Laatsch communicated that he was interested in “citizenship” to the foreign country. Laatsch also stated that, though he was “not opposed to other compensation,” from a financial standpoint, he did not need ‘material compensation.’”

On May 10, he provided the following to the FBI, noting that he believed he would not come to the attention of his colleagues, explaining how internal investigations were conducted. Laatsch explained, “it will not be easy for them, for example, to open a case on me without my knowledge since my permissions to see that would need to be changed and I’d notice.” He went on to discuss “’stupid mistakes’ others make when cases are opened on them and said these mistakes ‘should not be too difficult for me to avoid.’”

Luck plays a role in counterintelligence

Darren B. Cox, Assistant Director in Charge of the FBI Washington Field Office commented, “As an employee of the DIA Insider Threat Office, the American people relied on Nathan Laatsch to detect spies and other insider threats within our midst.  Laatsch betrayed that trust and instead became the very threat he was sworn to defend against. Fortunately, the swift action of the FBI and our partner agencies prevented even greater harm and brought him to justice. This case underscores a fundamental truth: The strength of our national security depends not only on our capabilities, but also on the integrity of those entrusted to safeguard it. When that trust is violated, the consequences can be profound.”

The modus operandi and hubris exhibited by Laatsch is similar to that used by Jonathan and Diana Toebbe in 2020 who proffered U.S. Navy nuclear secrets to a friendly government, Brazil. Jonathan Toebbe was quite pleased with himself, proudly describing how he was able to operate without being detected by the insider risk program.

Indeed, both Toebbe and Laatsch were successful in their subterfuge, until the countries friendly to the United States revealed to the United States government their perfidy. Once revealed, the reactive actions of the FBI were stellar. One can only imagine the damage possible had they chosen a country who found it to be in their interest to entertain the offer of United States Defense Information.

Related News

Christopher Burgess (@burgessct) is an author and speaker on the topic of security strategy. Christopher, served 30+ years within the Central Intelligence Agency. He lived and worked in South Asia, Southeast Asia, the Middle East, Central Europe, and Latin America. Upon his retirement, the CIA awarded him the Career Distinguished Intelligence Medal, the highest level of career recognition. Christopher co-authored the book, “Secrets Stolen, Fortunes Lost, Preventing Intellectual Property Theft and Economic Espionage in the 21st Century” (Syngress, March 2008).