Inside the Insider Threat Division: Five Lessons From the DIA Guilty Plea

In June 2025 we wrote about the arrest of a Defense Intelligence Agency IT specialist accused of offering classified information to a foreign government. On August 26, 2026, that case reached its next milestone: Nathan Vilas Laatsch, 29, of Alexandria, Virginia, pleaded guilty to transmitting national defense information to a foreign government. He faces a maximum of life in prison when he is sentenced on January 27, 2027.

One detail should stop every security leader cold. Laatsch did not work in a back-office role far from the mission. He was a civilian IT specialist in DIA’s Insider Threat Division.

What Happened

According to the Department of Justice:

  • In March 2025, the FBI learned Laatsch had offered classified information to a friendly foreign government. He then began communicating with an undercover FBI agent he believed represented that government.
  • In late April 2025, over about three days, he copied classified information by hand, removed it from his workspace, and left a thumb drive at a public park in northern Virginia. A note promised “a decent sample size” of his access.
  • From May 15 to 27, he copied more material from his classified workstation and hid it in his clothing to carry it out.
  • On May 29, 2025, he handed over additional documents at a prearranged location and was arrested.

He said he was interested in citizenship in the foreign country and did not need money. Prosecutors put it plainly: “Political disagreement is not a justification for jeopardizing the security of the United States.”

Five Lessons for Every Insider Threat Program

1. The people who watch are insiders too. Insider threat analysts, IT administrators, and security staff hold some of the broadest access in any organization. A mature program applies separation of duties and independent review to its own team, not just to everyone else.

2. A pen beats a DLP rule. Data loss prevention and user activity monitoring are built to catch files moving: downloads, prints, email, removable media. Copying by hand defeats them. Technical telemetry has to be fused with behavioral indicators to catch what the tools cannot see.

3. Motive is not always money. Financial screening would not have flagged an employee who said he did not need money. Ideology, disillusionment, and personal identity are just as powerful. Programs must train supervisors and coworkers to recognize grievance and ideological drift, not just debt.

4. Repetition is the window. This was not one bad afternoon. The conduct spanned weeks, across multiple sessions of pulling material. Repeated access to information outside a person’s normal duties is exactly the pattern a well-tuned monitoring program is built to surface early.

5. Reporting still matters. Many insider cases are stopped because someone noticed something and said so. Clear, trusted reporting channels turn coworkers into a sensor network.

How TMPC Helps

Our team brings more than 30 years of combined insider threat experience and the proprietary processes built from it. For 8 years, TMPC has delivered continuous counter-insider threat and user activity monitoring support to USSOCOM and JSOC, work that drove that program to a #1 ranking among 24 DoW (DoD) components by DCSA and DIA.

We help organizations:

  • Build or assess insider threat programs, including oversight of privileged users and the insider threat team itself
  • Fuse user activity monitoring with behavioral analysis to catch what tools alone miss
  • Train leaders and workforces to recognize and report concerning behavior

To talk with our team, contact info@tmpcinc.com or 813.524.6935.