Special Features

Cybersecurity Month

US govt IT help desk techie 'leaked top secrets' to foreign nation

National defense files can earn you $55K … and espionage charges


A US government worker has been arrested and charged with spying for Ethiopia, according to court documents unsealed Thursday.

Abraham Lemma, 50, a Silver Springs, Maryland resident and a naturalized United States citizen who was born in Ethiopia, was detained on August 24 after allegedly sending classified US national defense information to an Ethiopian intelligence agent. He has worked in various American government agencies since 2019.

Crucially, Lemma was an IT help desk technician assigned to the Bureau of Intelligence and Research with the US Department of State (DOS) since at least 2021. In addition to that dept, where he worked at night, he was also a contract management analyst at the US Department of Justice during the day, according to prosecution documents [PDF].

Both of these positions gave him access to classified information, and he's held top-secret security clearance since at least 2020.

Oddly enough, Lemma's alleged espionage activities came to light during an investigation into the DOS's handling of national defense information following the arrest of Air National Guardsman Jack Teixeira, who has been accused of leaking classified Pentagon documents on Discord, earlier this year.

"During this review, information was uncovered indicating that a Department of State information technology contractor may have removed, retained, and transmitted classified national defense information without authorization," DOS spokesperson Matthew Miller said in a statement.

According to a criminal complaint against him, between December 19, 2022 and August 7, 2023, Lemma copied, printed, and downloaded classified and top-secret information from more than 100 US intelligence reports, the majority of these relating to Ethiopia, without authorization.

He then allegedly transmitted classified national defense information, "including documents, photographs, notes, maps," and other data relating to Ethiopia and neighboring countries over an unnamed encrypted messaging app. This included satellite imagery from the region that was marked "top secret," photos of a military compound, and other information detailing military activities in the region.

According to the court documents:

Lemma's communications with the Foreign Official over Encrypted Messaging Application A included a discussion of military activities of a rebel group involved in an armed struggle against the government of the Relevant Country. In one communication, Lemma sent an image relating to events in the Relevant Country and advised the Foreign Official, '[y]our team analyze this and establish some sort of sense to this.'

Lemma also received thousands of dollars that, according to the Feds, coincided with his travels to Ethiopia and dates when he allegedly swiped and shared the classified materials. For example: on July 15, Lemma is said to have tried to deposit $11,773.84 in cash at a Maryland bank, while "angrily discouraging an employee" from filing a currency transaction report, as mandated by the US Treasury.

"Lemma downloaded classified reports from DOS close in time to this July 15, 2023 deposit — specifically, Lemma copied at least 16 reports July 11-14, 2023," court documents claim.

And after returning from a trip to Ethiopia on April 30, 2022, he allegedly deposited $4,300 on the day of his return.

"Review of Lemma's US Bank 1 account records further revealed that Lemma made several large deposits, totaling in excess of $55,000, into US Bank 1 between January 1, 2022 until July 17, 2023," according to the criminal complaint. 

Lemma has been charged with delivering national defense information to aid a foreign government, conspiracy to deliver national defense information to aid a foreign government, and the willful retention of national defense information.

The two espionage charges carry a potential penalty of death or life in prison, while the willful retention charge carries a maximum of 10 years behind bars. ®

Send us news
15 Comments

China's APT41 crew adds a stealthy malware loader and fresh backdoor to its toolbox

Meet DodgeBox, son of StealthVector

Ransomware crews investing in custom data stealing malware

BlackByte, LockBit among the criminals using bespoke tools

'Gay furry hackers' say they've disbanded after raiding Project 2025's Heritage Foundation

Ultra-conservative org funnily enough not ready to turn the other cheek

Privacy expert put away for 9 years after 'grotesque' cyberstalking campaign

Scumbag targeted many victims – and those who tried to help them

You had a year to patch this Veeam flaw – and now it's going to hurt some more

LockBit variant targets backup software - which you may remember is supposed to help you recover from ransomware

Eldorado ransomware-as-a-service gang targets Linux, Windows systems

US orgs bear the brunt of attacks by probably-Russian crew

TeamViewer can't bring itself to say someone broke into its network – but it happened

Claims customer data, prod environment not affected as NCC sounds alarm

Fiend touts stolen Neiman Marcus customer info for $150K

Flash clobber chain fashionably late to Snowflake fiasco party

Google reportedly in talks to buy infosec outfit Wiz for $23 billion

The security industry has never had a clear leader – could it be the Chocolate Factory?

WhisperGate suspect indicted as US offers a $10M bounty for his capture

Russian national accused of attacks in lead-up to the Ukraine war

Feds put $5M bounty on 'CryptoQueen' Ruja Ignatova

OneCoin co-founder allegedly bilked investors out of $4B

UK and US cops band together to tackle Qilin's ransomware shakedowns

Attacking the NHS is a very bad move