Monthly insider risk news recap - August 2026
Welcome to August's Monthly Insider Risk News Recap, your briefing on the most significant insider risk cases and incidents from the past month.
July’s recap centred on targeting, namely when an outside actor such as an intelligence service, a trafficking network, or a competitor, go looking for someone on the inside specifically because of the legitimacy of their access, rather than their skill.
August’s cases shift the focus from who is targeted to how trusted authority is exploited once it is already in place. The recurring weakness is not simply excessive access, but the absence of independent checks capable of detecting legitimate-looking activity before it becomes sustained harm.
Bankrupt Belgian Semiconductor Suffers IP Theft
Belgian authorities are investigating a 52-year-old Belgian-Chinese researcher who previously held a senior role at BelGaN, a now-bankrupt semiconductor company specialising in gallium-nitride technology. Prosecutors allege that the researcher simultaneously became involved with a Chinese semiconductor company and transferred sensitive BelGaN IP and trade secrets to it. He was arrested at Brussels Airport in May while travelling to China, and authorities have seized electronic devices; a second suspect is also being investigated, while the primary suspect denies the allegations.
The case is particularly interesting from an insider-risk perspective because it combines specialist technical knowledge, dual employment/directorship, access to strategically important IP, and an alleged transfer to a foreign competitor.
The case comes admits heightened attention placed by European governments on protecting the competitiveness of the semiconductor industry, with the Netherlands and now Belgian, proving as critical examples of the heightened threats faces.

Former Chinese military personnel accused of running two espionage operations
On August 11th, South Korean police announced the arrest of two former military service members on espionage charges tied to activity near a joint South Korea-US air base. One suspect, a man in his 60s, allegedly set up a radio interception rig, an antenna, a receiver, and a laptop, in a hotel near the base to intercept communications between fighter jets and air traffic control going back to 2024. The second suspect, arrested a day earlier, is accused of collecting information on US-South Korean military drills, troop and equipment movements, and personnel changes among senior US officers stationed near Seoul. Police allege he obtained some of that material through a South Korean woman employed at the US command, whom he paid and with whom he is suspected of having a romantic relationship.
Neither man appears to have held privileged access themselves; the exposure ran through someone who did. This is a recruitment case more than an access-control failure in the conventional sense, and it is a powerful reminder that insider risk programmes built around monitoring credentialed users can miss the person being cultivated rather than hacked. A romantic or financial relationship with someone outside the organisation is not something badge logs or DLP tools are designed to catch, and the base itself likely had no visibility into a civilian employee’s personal life until the information was already gone. For programs that only trigger an anomalous system behaviour, this is the case that falls through: the access used was entirely normal, and the person using it had every reason to be there.
Former Apple Employee Access Retention
Apple is suing OpenAI and two former Apple employees, alleging that confidential Apple hardware and product information was taken to OpenAI as employees moved between the companies. The most striking allegation concerns former Apple engineer Chang Liu: Apple says he retained access to Apple systems after leaving, downloaded dozens of confidential hardware files, including a circuit schematic, and subsequently used the information while working at OpenAI. Apple has recently sought expedited discovery, alleging that evidence on Liu’s MacBook could be lost. OpenAI strongly disputes the allegations, arguing that Apple failed to properly revoke Liu’s access and that there is no evidence OpenAI misused Apple’s secrets.
This case serves as a stark reminder that insider risk can often extend beyond an employee’s contract engagement, with the offboarding processes requiring specific attention.

Former hedge fund CFO pleads guilty to embezzling over $3 million
On August 11th, prosecutors in New York announced that the former CFO of a Miami-based hedge fund managing over $100 million in client assets pleaded guilty to securities fraud after admitting to a multi-year embezzlement scheme that began shortly after he was hired and continued until his termination in March. As CFO, Theodore Woo, had the authority to approve reimbursement requests and direct transfers on the fund’s behalf. He used that authority to instruct the fund’s administrator to pay millions of dollars to two shell entities he secretly controlled and executed over 100 fraudulent transfers into accounts in his own name. To keep the fund’s external auditor from catching on, he reportedly described one of the companies as an independent research firm the fund had hired. He also opened credit cards in the fund’s name and charged personal expenses, including international vacations, to them.
The mechanism is almost identical to the case below, despite the very different industries, as in both cases a single finance executive held both the authority to approve a payment and the ability to control wo received it, with no structural separation between the two. A basic segregation-of-duties control, requiring a second signature on payments to third parties, or an independent check on vendors before onboarding, would have surfaced two shell companies with no operating history months into the scheme rather than years. Instead, it took the fund’s own termination of Woo to end it, not the controls meant to catch this kind of self-dealing.
Former Williams-Sonoma VP pleads guilty to $16.3 million scheme
On August 11th, Eric Marsiglia, former vice president of engineering, projects, planning, facilities, and real estate at Williams-Sonoma, pleaded guilty to fraud and money laundering charges. As the executive overseeing warehouse leasing and equipment procurement, Marsiglia steered contracts to three New Jersey vendors supplying forklifts and racking systems in exchange for kickbacks, which he funnelled through a shell company he controlled, REM Group, netting over $12.2 million. Separately, from 2020 to 2022 he diverted more than $4.1 million in real estate broker commissions tied to Williams-Sonoma’s distribution centres into the same shell company. He is scheduled for sentencing in November, while three co-conspirators have also pleaded guilty in connection with the scheme.
Again, this case displays the issues connected with concentrated authority without a corresponding checks: one person-controlled vendor selection, contract approval, and the underlying real estate relationships for a major piece of Williams-Sonoma’s physical footprint, with no indication that a second set of eyes was required at any stage. Supply chain and procurement roles are a recurring soft spot for digital trail, a kickback scheme built around vendor selection can look, on paper, like ordinary business judgement for years, since inflated pricing and preferential vendor selection do not trigger the same alarms as unauthorised downloads. It too a four-year run and a federal investigation to surface the extent of it, not merely an internal audit.
Former DIA insider threat specialist pleads guilty to attempting to give classified information to a foreign government
On August 26th, Nathan Vilas Laatsch, a former IT specialist for the Defense Intelligence Agency (DIA), pleaded guilty to transmission of national defence information to a foreign government. Laatsch had worked at the DIA since 2019, held Top Secret security clearance and worked in the Insider Threat division. In March 2025, the FBI learnt he had offered classified information to a friendly foreign government and had began communicating with him posing as an agent of that country. Over three days in April 2025, Laatsch transcribed classified material onto a notepad at his desk, carried it out of his secure workspace, and left it on a thumb drive at a public park in northern Virginia, along with a note describing the sample as large enough to “decently demonstrate the range of types of products” he could access. He told his contact he wanted citizenship in the foreign country rather than payment, though he said he was not opposed to other forms of compensation as well. In May he repeated the same pattern, hiding transcribed pages in his clothes to carry them past his workstation, and was arrested when he delivered a second batch of documents on May 29th.
This case presents a distinct type of disgruntled insider. Laatsch volunteered and his main motive for acting was not financial gain, but rather citizenship, which would point to disgruntlement and alienation with his own government. Without a single event to tie a grievance too, disgruntlement is one of the trickier motives to screen for in advance. Where issues such as financial stress tend to leave a trail, for example, of debt or lifestyle changes, a decision rooted in a personal grievance may leave no trace until action has been taken.
Key takeaways and what to watch
This month’s throughline is authority. In most cases, the person responsible was not recruited or manipulated from the outside, but already held all the access they needed to achieve their own goals, exploiting it well before anyone could notice. Case in point is brough about by the DIA former employee, which raises a few questions for insider risk programmes going forward. It constitutes a reminder that insider risk expertise not a safeguard in and of itself, as someone who is hired to create such programmes would also know which thresholds to stay below of to avoid detection in case they ever turned malicious. As insider risk programmes professionalise and are brought in-house, the risk of employees using their expertise against their own organisation increases consequently. Among the solutions offered by the cases in this edition is to avoid concentration of authority by separating approval, execution, and oversight responsibilities, while applying enhanced monitoring to high-trust roles and requiring independent review of activity that appears legitimate because it falls within an individual’s formal remit.
Ultimately, effective insider risk management depends on pairing trusted access with independent oversight, meaningful segregation of duties, and scrutiny of activity that appears routine precisely because it is authorised.
Disclaimer: The cases discussed in this publication are based solely on publicly available information at the time of writing. They are intended for educational and illustrative purposes and should not be interpreted as definitive investigative findings. In some instances, official investigations may still be ongoing, and information may emerge that could alter the understanding of the events described. Signpost Six makes no claims regarding the actions, intentions, or liability of any individuals or organisations mentioned. While every effort has been made to ensure accuracy, Signpost Six accepts no responsibility for any errors, omissions, or misinterpretations arising from the use of publicly sourced information.
-1.png?width=750&height=500&name=Untitled%20design%20(36)-1.png)