An in-depth look at attempts by the US to prosecute hot-headed coder Joshua Schulte, who allegedly leaked the CIA's hacking arsenal, ahead of his June 13 trial
A hot-headed coder is accused of exposing the agency's hacking arsenal. Did he betray his country because he was pissed off at his colleagues? Tweets: @swiftonsecurity , @beijingpalmer , @swiftonsecurity , @samgadjones , @jimsycurity , @wesleysmorgan , @praddenkeefe , @raffiwriter , @hollymawilliams , @iblametom , @weldpond , and @jessmarindavis Tweets: @swiftonsecurity : Basically the CIA lost its most valuable hacking tools and suffered the biggest data breach history because they hired a 10x engineer, made him a server admin on an unmanaged programmer fiefdom network, and allowed him to be a fucking psycho to coworkers https://www.newyorker.com/... James Palmer / @beijingpalmer : a great piece, and also a good lesson in how CIA actually works - personalized, bureaucratic, and often deeply weird. https://twitter.com/... @swiftonsecurity : Locking down your endpoints into unusability just means your programmers will use Linux on a network they think they can manage but can't and it just gets worse for years all the while the IT department is happy because now the programmers don't complain anymore https://twitter.com/... Sam Gad Jones / @samgadjones : Fascinating article full of detail that raises serious questions about vetting in the US intelligence world (again) v-a-v the strange case of Joshua Schulte, who may be responsible for one of the biggest security breaches in US government history https://twitter.com/... https://twitter.com/... Jim Sykora / @jimsycurity : @SwiftOnSecurity This line from the article really stuck with me: “We live in an era that has been profoundly warped by the headstrong impulses of men who are technically sophisticated but emotionally immature.” Wesley Morgan / @wesleysmorgan : This passage is a perfect encapsulation of government overclassification and unwillingness to accept that previously secret information has in fact become public: https://www.newyorker.com/... https://twitter.com/... Patrick Radden Keefe / @praddenkeefe : This is one of the wildest stories I've ever written, about a combustible CIA hacker, Josh Schulte, who tangled with colleagues & kept escalating the conflict. Now he stands accused of the ultimate payback: the biggest leak in CIA history. Meet King Josh https://www.newyorker.com/... Raffi Khatchadourian / @raffiwriter : The crazy story about Joshua Schulte, the CIA software engineer accused of revenge leaking classified hacking tools in 2016 (see #Vault7), gets the full @newyorker treatment by the amazing @praddenkeefe: https://www.newyorker.com/... Holly Williams / @hollymawilliams : “We live in an era that has been profoundly warped by the headstrong impulses of men who are technically sophisticated but emotionally immature.” https://twitter.com/... Thomas Brewster / @iblametom : Great story. Will be interested to see what happens in both the espionage case and the child sexual abuse case. Quotes here from individuals wondering how Schulte got employed by the CIA in the first place given his past behaviour. https://twitter.com/... @weldpond : These are hacks, or “exploits,” designed for individual targets. Sometimes a foreign terrorist or a finance minister is too sophisticated to be hacked remotely, and so the agency is obliged to seek “physical access” to that person's devices. https://www.newyorker.com/... JMDavis / @jessmarindavis : This is a really interesting read, and the grievance collecting of this guy is next level. When we think about leakers we often think about ideology or money as motivation, but revenge / grievances is huge. https://twitter.com/...
Context & Ripple Effects
This week's New Yorker profile lands days before prosecutors finally get their courtroom reckoning with the breach the CIA itself barely registered: an internal report found security was so lax at the time of the Vault 7 leak that, had WikiLeaks not published the files, the agency might never have known it was compromised. The trial turns a years-old technical failure into a legal and reputational one.
Schulte's case also fits a pattern the corpus has tracked across agencies: an NSA contractor lost data on US offensive and defensive cyber capabilities from a laptop exposed via Kaspersky software, and the broader modernization push after the OPM breach has been about making spy operations resilient to exactly this class of loss.
First-order effects
- Joshua Schulte faces a June 13 trial that will force the government to defend both its accusation against him and its own handling of a network where, per the CIA report, a single engineer-administrator could exfiltrate the hacking arsenal undetected.
- The CIA enters the trial carrying public evidence from its own review that WikiLeaks' publication was the only thing that revealed the compromise — a disclosure problem independent of who did it.
Second-order effects
- The NSA's Kaspersky-linked theft shows the vulnerability isn't CIA-specific: every agency hoarding offensive tooling must now treat its own staff and endpoints as the primary attack surface, driving spending toward insider-threat detection over perimeter defense.
- Prosecutors' framing of the case — betrayal driven by workplace grievance rather than ideology, if the profile holds — gives other agencies a template for screening insider risk by organizational culture, not just clearance status.
Third-order effects
- If the pattern holds, stockpiled offensive capabilities function as liabilities that scale with their value: the more potent the arsenal, the bigger the blast radius when one insider walks out with it, pushing agencies toward the resilience-first posture of the post-OPM modernization effort.
- A conviction would harden the legal playbook for prosecuting leakers of classified cyber tools, while the CIA's own report ensures the institutional-failure half of the story stays part of any future breach inquiry.
The trend: US intelligence agencies are learning that centralized arsenals of offensive cyber tools concentrate insider risk as much as capability, forcing a shift from secrecy-first custody to resilience-first operations.