CIA officer found with $40 million in gold bars in his basement reaches tentative plea agreement

Federal prosecutors said on Friday that they reached a tentative plea deal with a former CIA officer who was found with more than $40 million in gold bars in the basement of his Virginia home. 

According to U.S. officials, David J. Rush, who was an officer in the agency’s science and technology division, created a false classified program that only a few people were allowed to know about. The program allowed him to accumulate the gold bars. He was arrested on May 19 after FBI agents found 303 gold bars and nearly three dozen luxury watches in his home, the New York Times reported

gov.uscourts.vaed_.596235.31.0.pdf

A court filing seeking an extension of time to file an indictment states that government lawyers and Rush’s attorney told a federal district court in Virginia that a “preindictment resolution promotes the public interest.” Part of the reason, the attorneys explained, is the extensive hurdles that dealing with classified material might create to a trial.

“The parties have made significant progress and have a plea agreement in principle that would resolve the matter prior to an indictment,” the government and defense lawyers wrote in a joint filing to the court.

In a court filing, the lawyers for the government and Rush’s attorney asked the court to give them until Oct. 8 to reach an agreement. 

Keep reading

US Customs supervisor busted for stealing Core i7 CPUs, RAM, and hard drives from Homeland Security PCs, damage estimated at $105,800 — stolen tech swapped with inferior hardware and cashed out on Newegg

According to a report from The Maine Wire, the FBI has arrested and charged Terry “Jiajia” Liu, a Customs and Border Protection supervisor based in Calais, Maine, for theft and damage to government property. Liu allegedly stole computer hardware, including Intel 14th Generation Raptor Lake Refresh processors, memory modules, and hard drives, from at least 46 Department of Homeland Security computers across three Maine border facilities. They replaced the stolen parts with inferior hardware and exchanged the stolen equipment through Newegg’s trade-in program for store credit.

Liu’s official responsibilities were limited to information-technology support, so they did not have access to modify any government computer. Port Director Theodore Cummings made the restriction abundantly clear to Liu in a written order: “Please do not move any computers or computer parts.” However, criminals rarely listen.

Hidden surveillance cameras captured Liu opening government computers and swapping hardware during the midnight shift. The perpetrator would take the systems to a training room to commit the crime. One camera recording showed Liu using a screwdriver to scrape thermal paste off a processor and installing a replacement chip in one system. Meanwhile, another recording caught Liu removing a memory module from a system and storing it in their desk drawer.

Keep reading

Ben Shapiro’s Uncle Who Stole U.S. Uranium and Built Israel’s Nuclear Program

Ben Shapiro has a favorite word.

Conspiracy.

Question whether Israeli pressure helped drag America into another Middle Eastern war?

“Conspiracy trash.”

Question Israel’s connection to Jeffrey Epstein?

“Mythology.”

Keep investigating?

“Brain rot.”

When Joe Kent accused Israel and its powerful American lobby of helping push America toward war with Iran, Shapiro did not merely disagree.

He ridiculed the question.

“Conspiracy trash.”
“Conspiratorial idiocy.”
“This stuff is brain rot.”

But there is one problem with Ben Shapiro’s favorite word:

OPEN HIS OWN FAMILY’S FILES.

Ben’s uncle, Zalman Shapiro, ran NUMEC, a Pennsylvania facility handling highly enriched uranium that became the center of a decades-long U.S. investigation into missing American nuclear material diverted to Israel.

The CIA became sufficiently concerned about Shapiro’s relationship with Israel that CIA Director Richard Helms asked the FBI to investigate the “nature and extent” of that relationship.

Then Israeli intelligence figures appeared inside his nuclear facility.

One of them was Rafael Eitan.

Eitan would later head LAKAM, run Israeli spy Jonathan Pollard, and participate in the Plumbat operation, which covertly diverted roughly 200 tons of uranium oxide to Israel.

So before Ben Shapiro dismisses questions about Israeli intelligence and influence as “brain rot,” there is somewhere Americans should look first:

His uncle’s files.

Keep reading

SoCal: Orange County Woman Shocked as FBI Agents Arrest Her For Stealing More Than $400,000 From High School Football Team in Pre-Dawn Raid

The FBI on Thursday morning arrested an Orange County, California, woman for stealing more than $400,000 from a high school football team.

56-year-old Julie Hanway Molina was the treasurer of an Orange County nonprofit and allegedly used more than $400,000 in stolen funds to pay off her mortgage and credit card debt.

Video posted to social media by the California Post shows FBI agents and local law enforcement surrounding Molina’s $1.4 million Aliso Viejo home early Thursday morning and taking her into custody.

The California Post reported that Julie Hanway Molina was stunned as federal agents used a bullhorn and demanded she “come out with your hands up.”

Molina walked out of her front door and looked shocked as federal agents handcuffed her.

Federal prosecutors alleged in the indictment that the scheme to defraud Aliso Niguel High School’s Wolverine Football Club began in 2023 and went through 2025.

Keep reading

BUSTED: AirTags Lead Police Straight to Home of Retired Columbus State Professor and Democrat-Donor Wife After Conservative Candidate’s Campaign Signs Disappear

A conservative-leaning independent candidate in Columbus, Georgia, got tired of watching his campaign signs vanish. He hid Apple AirTags inside them.

The trackers did not ping a dumpster or a random yard. They led straight to the home of a well-known local reverend and her husband, a retired Columbus State University educator.

Stephen Acorn is running as an Independent write-in against longtime Democrat incumbent Debbie Buckner for Georgia House District 137.

After signs kept disappearing near Matthews Elementary School and County Line Road, Acorn cut open replacements, slipped AirTags inside, and waited.

“I feel like I outsmarted the perpetrator,” Acorn told NowGeorgia.com, which first reported the story.

Within 24 hours, Acorn received an alert showing that two of the signs were moving.

The tracking devices eventually led Acorn and police to the residence of retired Columbus State educator Richard Spencer Garrard and his wife, Rev. Dr. Cindy Cox Garrard.

Keep reading

Chinese chipmaker CXMT allegedly used a written roadmap to steal Samsung DRAM tech — South Korean court says ‘Project Hefei’ lifted 620-step recipe to build 10% global market share

The saga involving Chinese DRAM maker CXMT’s alleged theft of Samsung’s trade secrets is going strong. The South Korean court case already includes multiple convictions, two of which carry prison sentences for ex-Samsung engineers. The latest chapter is a doozy, though. Korean publication NoCut News spilled the chips on Project Hefei, a purported CXMT roadmap outlining long-term planning about said technology “acquisitions,” personnel poaching, and production tape-out — all key pieces that may have directly led to CXMT’s ascension to 10% of the global DRAM market.

According to leaked court documents, the prosecution says that Project Hefei was CXMT’s entire DRAM development plan and was spearheaded by the firm’s head of development (formerly Samsung’s DRAM development lead), around August 2016 — not much longer after CXMT itself was created in June 2016.

In brief, the purported plan was to nab Samsung’s Process Recipe Plan (PRP) by September 2016, poach key Samsung engineers by October 2016, have R&D complete in July 2017, and start making DRAM wafers by August 2018 at a rate of 10,000 a month. NoCut says the PRP dataset comprises 620 steps in DRAM manufacturing and includes data on equipment, consumables, and production methods.

The report states that in August 2016, CXMT first attempted to make wafers of 18nm chips by relying on the collective memories of the Samsung engineers it had hired away. Those recollections apparently proved insufficient, so after allegedly gaining illicit access to Samsung’s PRP, CXMT prepared its own document in September 2016. The leaked data even included specific equipment suppliers and model numbers.

Keep reading

ICE Locks Up Three Guatemalan Illegal Aliens in Tennessee for Stealing Americans’ Social Security Numbers — One Was Already Deported THREE TIMES

Federal immigration authorities arrested three Guatemalan illegal aliens in Tennessee during an investigation into the alleged fraudulent use of stolen identities and Social Security numbers.

ICE officers arrested Magdalena Gomez-Garcia, Elias Gomez-Garcia, and Eulalia Ordonez-Carmelo on August 4.

All three Guatemalan nationals were reportedly already subject to final orders of removal from the United States, Border Hawk first reported.

Magdalena Gomez-Garcia is accused of stealing the identity of a New York resident and using the victim’s Social Security number to obtain employment in Tennessee.

According to Border Hawk, the American victim discovered that wages earned by someone else were being reported under her Social Security number. She was then forced to contact authorities repeatedly to correct her records.

Gomez-Garcia was first encountered by Border Patrol near San Luis, Arizona, in 2018. She was issued a notice to appear before an immigration judge and received a final removal order in absentia in April 2019.

Yet she allegedly remained in the country and found employment using another person’s identity.

Keep reading

Grand jury indicts former community school superintendent, business partner in $8 million fraud scheme

A federal grand jury has indicted the former superintendent and operator of a local community school and a business partner with wire fraud and other crimes related to an $8 million fraud and kickback scheme.

Leondo Ramone Davenport, 50, of Cincinnati, and Jonathan Larry Ballew, 62, of Phoenix, Arizona, were arrested this morning by federal agents. 

“We’re putting an end to fraudsters exploiting public trust and profiting off of the American taxpayer,” said U.S. Attorney Dominick S. Gerace II. “Offenders should know that my Office will work hard to ensure that those responsible for fraud end up paying the price and come to understand that the juice is not worth the squeeze.”

“This indictment alleges a brazen scheme that stole from both taxpayers and students,” said Assistant Attorney General Colin McDonald of the Justice Department’s National Fraud Enforcement Division. “Education dollars exist to support the learning and development of American children—not to fund the lifestyles of unscrupulous school officials. The Fraud Division commends the work of our federal and state partners whose efforts were essential in bringing these charges and ensuring that those who abuse positions of trust are held accountable.”

“Fraud against the government is fraud against every taxpayer and we are all victims of these schemes,” stated FBI Cincinnati Special Agent in Charge Jason Cromartie. “The FBI and Department of Justice are committed to rooting out fraud and holding accountable those who conduct illegal activities.” 

“This was an egregious kickback scheme by individuals using taxpayer resources to enrich themselves,” Auditor Faber said. “Thanks to the good work of the U.S. Attorney, the FBI and our other partners in law enforcement for pursuing justice in this case. Our investigation also continues, and we look forward to working alongside the Hamilton County Prosecutor’s Office to ensure everyone involved in these crimes is held accountable for their actions.”

Davenport served as the superintendent of Dohn Community High School from 2015 to 2019. Through an  LLC he incorporated, Dohn served as the operator of the school from 2019 until 2024.

Dohn was incorporated in Ohio as a not-for-profit organization around 1999 to serve as an addiction recovery program for high school students. It operated as a community school under Ohio law from approximately 2001 until 2025. In Ohio, a community school created under state law is a public school, independent of any school district.

Ballew incorporated at least four entities allegedly purporting to provide educational services, training, technology, staffing, and school construction and remodeling services to Dohn. 

The eight-count indictment alleges that, from 2021 to 2024, Davenport and Ballew participated in a kickback scheme to defraud the school. Ballew allegedly submitted false and fraudulent invoices to Dohn on behalf of the entities he controlled. Davenport allegedly authorized Dohn to pay the invoices and received a kickback in return. In total, during this time, Davenport allegedly authorized Dohn to pay over $8 million to Ballew and Ballew correspondingly paid over $4 million back to Davenport.

The charging document details that the defendants allegedly spent the money on luxury automobiles and rental properties. For example, in October 2023, Davenport and Ballew both signed a two-year rental agreement for a luxury vacation property near Miami, Florida, for $30,000 per month.

Davenport and Ballew are each charged with wire fraud, a federal crime punishable by up to 20 years in prison and engaging in monetary transactions in property derived from unlawful activity, which carries a potential penalty of up to 10 years in prison.

Dominick S. Gerace II, United States Attorney for the Southern District of Ohio; Jason Cromartie, Special Agent in Charge, Federal Bureau of Investigation (FBI), Cincinnati Division; and Ohio Auditor of State Keith Faber announced the charges. Assistant United States Attorney Matthew C. Singer is representing the United States in this case.

On April 7, the Department of Justice announced the creation of the National Fraud Enforcement Division (“Fraud Division”). The Fraud Division is investigating and prosecuting those who commit fraud against the American people. The Department’s work to combat fraud supports President Trump’s Task Force to Eliminate Fraud, a whole-of-government effort chaired by Vice President J.D. Vance to eliminate fraud, waste, and abuse within Federal benefit programs.

An indictment merely contains allegations, and defendants are presumed innocent unless proven guilty in a court of law.

Keep reading

CrowdStrike and Federal Authorities Dismantle Russian Malware That Secretly Stole Crypto for 8 Years

A campaign of malware operated by Russian cybercriminals for eight years was dismantled by federal authorities in conjunction with the cybersecurity firm CrowdStrike on Thursday. The malware, identified by the security firm as “EggJagger” or as Sality malware, preyed upon thousands of users of virtual currency by engaging in “clipboard hijacking.” The most common method that users of virtual currencies such as Bitcoin and Ethereum employ in order to send currency is to copy a virtual currency address from a web page to a computer’s clipboard and then later to paste the virtual currency address into the corresponding field of a wallet application. The malware sat idle on a user’s computer and then, before the user had a chance to discover the substitution, would change the virtual currency address that had been placed in the user’s clipboard to an address controlled by the cybercriminals, reported CoinDesk.

Once the compromised address was pasted into the user’s wallet software, and the resulting transaction had been confirmed, the cryptocurrency was transferred irretrievably to the attacker. While there was no particular attack functionality that triggered any alerts, the single defense against such an attack was for the user to manually verify the address that they had pasted into the sending field. Typically the first and last characters of a wallet address would be verified against what was expected, but in this case all would need to be checked. The reason for this type of attack to have persisted for some eight years is that it is an easy one to implement, and places the onus of security on the end user to perform correctly in these situations.

Analysis by CrowdStrike has uncovered the malfeit cryptocurrency operators amassed 12.1 million rubles ($150,000) in the years the malware was active and operating, however most of the stolen cryptocurrency had been deposited into online wallets, remained untouched by the cybercriminals. However with the recent and ongoing surge in value of many of the world’s most popular cryptocurrencies the hacker’s abandoned stash has appreciated significantly to an estimated $1.35m. The returns on such a relatively simple attack vector to extract cryptocurrency from individuals is significant and in this instance highlights that such malware, whilst still active after eight years, continues to reap significant returns on little more than foraging for victims, capitalizing on default settings and exploiting human nature of individuals utilizing online cryptocurrency services.

A major weakness of the botnet infrastructure behind EggJagger was the minimal security controls in place around the network of infected computers. As long as a compromised computer was responding to commands appropriately, it could be included in the botnet of other compromised systems. In a live demonstration of the vulnerability on Monday at CrowdStrike’s Day Zero summit in Las Vegas, the security team of researchers used the same hole to subvert EggJagger and replace the legitimate peer addresses embedded in the malware with the IP addresses of their own servers. Suddenly, more than 15,000 computers infected with EggJagger around the world lost connection to their command-and-control servers in an instant, bringing the whole operation crashing down.

The high-profile takedown of the long-running Russian malware operation highlighted the persistent cyber threats to financial infrastructure emanating from Russia, as well as the growing role of the private cybersecurity sector working in conjunction with law enforcement to counter threats to the financial system. Despite having developed sophisticated operational security measures over an eight-year period, Sality ultimately relied on a relatively simple vector to steal cryptocurrency from thousands of individuals and businesses – that of exploiting routine human practices. The botnet’s vulnerability to having its peer connections severed by not authenticating the connections was identified by law enforcement and subsequently exploited to dismantle the operation in a single action, bringing an end to a threat that had affected thousands of individuals and businesses across South Florida and the country.

Keep reading

Accused Murderer Out on $600K Bond Recruited USPS Carriers to Steal Nearly $24 MILLION in Checks — Then Sold Them on Telegram

A 28-year-old Houston man already free on a $600,000 bond in a murder case is now accused of running a nearly $24 million check-theft ring, by recruiting U.S. Postal Service mail carriers to steal checks off their own routes and selling the loot on Telegram.

Tryston Tremaine Vaughn, 28, is alleged to have recruited USPS mail carriers to steal checks on their delivery routes, the DOJ said in an August 25 statement.

Those checks were then allegedly bought from the postal workers by Vaughn and others, advertised on a Telegram channel called “slipsandchips,” and shipped to buyers across the country via FedEx.

Prosecutors say the haul totaled approximately $23,973,338.15. One stolen check was for $1.5 million.

And the man accused of running the operation was not locked in a cell while this was happening. He was walking around on bond after a fatal shooting.

A federal grand jury in the Southern District of Texas returned a nine-count indictment charging five people:

  • Tryston Tremaine Vaughn, 28 — alleged recruiter and ringleader
  • Alyssa Nadine Bryant, 27 — accused of helping buy, sell, and ship the stolen checks
  • Catherine Clauzelle Kilpatrick, 29 — USPS mail carrier (Greens North Station)
  • Drakkor Jamar Alexander, 34 — USPS mail carrier (Spring Main Post Office)
  • Malcolm Tiree Joubert, 35 — USPS mail carrier (Windmill Station)

All five face conspiracy to commit bank fraud and bank fraud. The three carriers also face theft of mail matter by a postal employee.

Keep reading