Monday, August 3, 2026

Policy & Regulation

Former L3Harris executive sentenced for leaking exploits to Russia

Peter Williams, a former L3Harris executive, was sentenced to 87 months for selling hacking tools to a Russian exploit broker, potentially impacting millions of devices.

Former L3Harris executive sentenced for leaking exploits to Russia

On Tuesday, Peter Williams, a 39-year-old Australian citizen residing in Washington, D.C., was sentenced to 87 months in prison. Williams, a former executive at US defense contractor L3Harris, was convicted of stealing and selling trade secrets—confidential business information—to a Russian firm between 2022 and 2025. In exchange for the stolen tools, Williams received $1.3 million in cryptocurrency. Prosecutors from the U.S. Department of Justice stated that Williams betrayed the United States through his actions.

Williams served as the general manager of Trenchant, the L3Harris division that develops hacking and surveillance tools. The theft resulted in an estimated $35 million loss to Trenchant. Williams sold the stolen zero-day exploits—software flaws unknown to the developer, used for hacking—to Operation Zero, a Russian firm that the U.S. government, a government entity, calls “one of the world’s most nefarious exploit brokers.” Operation Zero, which claims to work with the Russian government, operates as an exploit broker, an entity that buys and sells security vulnerabilities. The firm previously posted that high market demand was driving up its payouts for top-tier mobile exploits, noting that its end users are always located in non-NATO countries. The U.S. Department of Justice stated that the stolen tools could have allowed users to potentially access millions of computers and devices around the world.

The sentencing coincided with the U.S. Treasury imposing sanctions against Operation Zero and its founder, Sergey Zelenyuk, designating the firm a national security threat. The Treasury stated that the broker sold those stolen tools to at least one unauthorized user. While Williams’ lawyers argued the stolen tools were not classified as a government secret, the fallout from the leak extended to other employees. In October, it was revealed that Trenchant had fired an employee, identified by the alias Jay Gibson, after Williams accused him of stealing code. On March 5, 2025, Gibson received a notification from Apple stating he was targeted… with a mercenary spyware attack—spyware tools used for targeted attacks—months after the investigation began.

Why it matters

The conviction of a former L3Harris executive for selling zero-day exploits to a Russian broker highlights the risks of insider threats within the defense industry and the global trade in sensitive hacking tools. The case also underscores the government’s crackdown on exploit brokers, evidenced by recent sanctions against Operation Zero.