{
  "id": "case-schulte-vault7",
  "slug": "us-v-schulte-cia-vault-7",
  "title": "U.S. v. Joshua Schulte (CIA Vault 7 Leak)",
  "summary": "Former Central Intelligence Agency software developer convicted of the historic transmission of classified CIA cyber warfare tools, source code, and zero-day exploits (Vault 7) to WikiLeaks, causing catastrophic national security damage.",
  "case_number": "1:17-cr-00548",
  "court": "U.S. District Court for the Southern District of New York",
  "district": "S.D.N.Y.",
  "country": "United States",
  "opened_at": "2017-08-24",
  "status": "sentenced",
  "victim_sector": "Intelligence, National Defense, Federal Government",
  "victim_country": "United States",
  "loss_amount_usd": 500000000,
  "loss_amount_note": "Government loss estimated in hundreds of millions in operational capability destruction across global intelligence activities.",
  "first_seen_at": "2016-04-20T00:00:00Z",
  "last_updated_at": "2026-09-10T11:00:00Z",
  "actor_slug": "insider-threat",
  "defendant_slugs": [
    "joshua-schulte"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Schulte abused his administrative credentials as a CIA Center for Cyber Intelligence software engineer to grant himself backdoor access to secure development servers.",
      "evidence_locator": "Indictment \u00b6 14, Page 8",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Schulte",
      "source_url": "https://www.justice.gov/usao-sdny/pr/former-cia-software-engineer-joshua-adam-schulte-sentenced-40-years-prison-espionage-and",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1070",
      "evidence_excerpt": "Defendant deleted server log files and altered system configuration timestamps to conceal his exfiltration of the CIA development branch.",
      "evidence_locator": "Indictment \u00b6 18, Page 11",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov/usao-sdny/pr/former-cia-software-engineer-joshua-adam-schulte-sentenced-40-years-prison-espionage-and",
      "technique_name": "Indicator Removal",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1560.001",
      "evidence_excerpt": "He compressed the entire CCI codebase into encrypted archives before transferring the files offsite.",
      "evidence_locator": "Trial Transcript Day 8",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Trial Record",
      "source_url": "https://www.justice.gov/usao-sdny/pr/former-cia-software-engineer-joshua-adam-schulte-sentenced-40-years-prison-espionage-and",
      "technique_name": "Archive via Utility",
      "tactic": "Collection"
    }
  ],
  "events": [
    {
      "event_type": "indictment",
      "event_date": "2018-06-18",
      "description": "Grand jury indicts Schulte for illegal transmission of national defense information and computer hacking under the Espionage Act."
    },
    {
      "event_type": "verdict",
      "event_date": "2022-07-13",
      "description": "Jury convicts Schulte on all counts of espionage, computer hacking, and obstruction of justice."
    },
    {
      "event_type": "sentencing",
      "event_date": "2024-02-01",
      "description": "Sentenced to 480 months (40 years) in federal prison."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Intelligence, National Defense, Federal Government networks. Former Central Intelligence Agency software developer convicted of the historic transmission of classified CIA cyber warfare tools, source code, and zero-day exploits (Vault 7) to WikiLeaks, causing catastrophic national security damage.",
    "blast_radius": "Government loss estimated in hundreds of millions in operational capability destruction across global intelligence activities. Impacted Intelligence, National Defense, Federal Government infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Defense Evasion",
        "title": "Defense Evasion & Security Blindfolding",
        "description": "Schulte abused his administrative credentials as a CIA Center for Cyber Intelligence software engineer to grant himself backdoor access to secure development servers.",
        "technical_artifacts": [
          "T1078",
          "Valid Accounts"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Phase 2: Collection",
        "title": "Target Data Harvesting & Archiving",
        "description": "He compressed the entire CCI codebase into encrypted archives before transferring the files offsite.",
        "technical_artifacts": [
          "T1560.001",
          "Archive via Utility"
        ],
        "mitre_technique_id": "T1560.001"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}