CIA officer

A CIA officer forged a fake spy program to steal $190M in cash and gold

David Rush spent years handling highly sensitive intelligence programs, then used that access to invent a fake spy operation and steal $190 million in cash and gold.

3 min readTechCrunch
A CIA officer forged a fake spy program to steal $190M in cash and gold

The scale of the fraud is staggering, but the real story here is how easily institutional trust can be weaponized. A CIA officer who worked on highly sensitive intelligence programs used a fake government contract to siphon $190 million in cash and gold. That is not a clever heist; it is a systematic failure of oversight, and it should make every organization rethink how it verifies the people who hold the keys to its most sensitive systems.

David Rush did not need to hack a network or exploit a zero-day vulnerability. He exploited something far more basic: the assumption that someone with access and clearance must be legitimate. This is the same trust dynamic that makes North Korean hackers linked to $351M Bitget crypto theft so effective. Those attackers did not break through cryptographic walls; they found the human and procedural gaps that exist in every system. The lesson is consistent across intelligence agencies and crypto exchanges: the most dangerous threat is the one that looks like it belongs.

What makes this case particularly unsettling is the gold. Cash can be tracked, frozen, and seized, but physical gold is the ultimate anonymous asset. It is a deliberate choice, and it points to a level of planning that should worry anyone responsible for high-value assets. The same logic applies to emerging technologies like deepfake detection. As 25 million in funding sharpens Modulate's focus on detecting deepfake scams shows, the fight against fraud is increasingly about verifying authenticity in real time. But no algorithm can catch a person who is already inside the perimeter and authorized to act. That is a governance problem, not a technical one.

The practical takeaway for our readers is blunt: trust is not a security control. It is a convenience that must be continuously audited, and the more access a person has, the more scrutiny they should face. This case also raises a question we should all sit with: if a CIA officer can fabricate an entire fake program and walk away with nearly $200 million, how many smaller versions of this are happening inside your own organization, unexamined because the person seems credible? We should not wait for the gold to be gone to ask that question.

From TechCrunch

CIA officer David Rush, who worked on highly sensitive intelligence programs, reached a plea deal with U.S. prosecutors after he was caught siphoning money and gold with a fake government contract.

Read the original at TechCrunch