Nathan Vilas Laatsch, 29, an IT specialist at the Defense Intelligence Agency, has pleaded guilty to attempting to pass classified national defence information to a foreign government.
He worked in the DIA's Office of Security. His duties included enabling user activity monitoring on people with access to DIA systems and supporting law enforcement with insider threat tooling. In spring 2025 he was assigned to the Insider Threat Division — the unit whose job is finding leakers.
The FBI's Roman Rozhavsky put it exactly: by his own admission, Laatsch offered classified information to a foreign government, the very thing he was supposed to prevent.
The detail that matters technically
He did not exfiltrate anything over the network. He did not email files, upload them, or copy them to a share.
Between 28 and 30 April and again between 15 and 27 May 2025, he transcribed classified documents by hand at his desk and hid the notes. The man who configured the monitoring knew exactly what the monitoring watched, and he chose the one channel it does not cover — a pen.
Every data loss prevention control in existence works on data in motion through a system: files copied, printed, mailed, written to removable media. None of them see a person writing on paper. It is the oldest exfiltration method there is and it remains completely effective against controls that cost millions.
The sequence
| Date | Event |
|---|---|
| March 2025 | Emails an offer of classified access from a new account |
| 4–23 April | The FBI, having learned of the offer, responds undercover |
| 28–30 April | Transcribes documents at his desk |
| 1 May | Leaves a thumb drive at a dead drop in an Arlington park |
| 15–27 May | Transcribes more material |
| 29 May 2025 | Arrested at a second drop |
His initial message offered completed intelligence products, some unprocessed intelligence, and other assorted classified documentation.
Nine documents were recovered from the thumb drive, eight of them top secret with sensitive compartmented information — covering methods of intelligence collection, intelligence on foreign military exercises, and analysis of their impact.
He chose every file himself. The FBI, posing as the recipient, gave no guidance on what to take, so the selection reflects his own view of what a foreign service would want.
The recipient
Court documents describe it only as a friendly foreign government. The country has not been named.
That phrasing is doing something. Espionage prosecutions usually name the adversary, and where they do not, it is generally because the relationship is more valuable than the point being made. It is also possible the identification is simply not being made public. Either way, nobody outside knows which country it was, or whether it would have collected the material at all.
Where it lands
The plea agreement recommends 11 to 18 years, including time served. The court can impose up to life and a $250,000 fine.
He waived his right to an attorney and confessed at arrest.
What an organisation can actually take from this
- Privileged access to the monitoring is privileged access. The people who administer detection can see its blind spots, and that role needs its own oversight.
- Rotate and separate insider-threat duties. One person configuring monitoring and having clearance to the material it protects is a concentration risk.
- Accept that DLP has a paper-shaped hole, and stop treating clean DLP logs as evidence of nothing happening — the same point CISA made this week about detection tools being only as good as the people and processes around them.
- Behavioural indicators outrank technical ones here. He was caught because he contacted a foreign government, not because a system flagged him.
What is not established
- Which country he believed he was contacting.
- His motive beyond a reported disenchantment with the current administration.
- Whether the foreign government would have collected the material.
- Whether anything else left the building before March 2025.