CASE DOSSIER sentenced

U.S. v. Joshua Schulte (CIA Vault 7 Leak)

Docket: 1:17-cr-00548 Court: U.S. District Court for the Southern District of New York Opened: 2017-08-24 Sector: Intelligence, National Defense, Federal Government

Key Facts

Status
SENTENCED
Legal disposition
Loss Amount
$500.0 million
Government loss estimated in hundreds of millions in operational capability destruction across global intelligence activities.
Techniques
3
Verified mappings
Defendants
1
Named in charges
  • Legal Status: SENTENCED in U.S. District Court for the Southern District of New York.
  • Primary Target Sector: Intelligence, National Defense, Federal Government.
  • Documented Financial Loss: $500.0 million.
  • 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Former Central Intelligence Agency software developer convicted of the historic transmission of classified CIA cyber warfare tools, source code, and zero-day exploits (Vault 7) to WikiLeaks, causing catastrophic national security damage.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Unauthorized intrusion originating from targeted infiltration directed against Intelligence, National Defense, Federal Government networks. Former Central Intelligence Agency software developer convicted of the historic transmission of classified CIA cyber warfare tools, source code, and zero-day exploits (Vault 7) to WikiLeaks, causing catastrophic national security damage.

Operational & Financial Fallout

Government loss estimated in hundreds of millions in operational capability destruction across global intelligence activities. Impacted Intelligence, National Defense, Federal Government infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SENTENCED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Unauthorized intrusion originating from targeted infiltration directed against Intelligence, National Defense, Federal Government networks. Former Central Intelligence Agency software developer convicted of the historic transmission of classified CIA cyber warfare tools, source code, and zero-day exploits (Vault 7) to WikiLeaks, causing catastrophic national security damage.

Adversary Kill Chain Flow

2 Documented Phases
1
Phase 1: Defense Evasion Defense Evasion & Security Blindfolding
MITRE ATT&CK T1078 →

Schulte abused his administrative credentials as a CIA Center for Cyber Intelligence software engineer to grant himself backdoor access to secure development servers.

Artifacts & Tooling: T1078 Valid Accounts
2
Phase 2: Collection Target Data Harvesting & Archiving
MITRE ATT&CK T1560.001 →

He compressed the entire CCI codebase into encrypted archives before transferring the files offsite.

Artifacts & Tooling: T1560.001 Archive via Utility
Real-World Blast Radius & Operational Fallout

Government loss estimated in hundreds of millions in operational capability destruction across global intelligence activities. Impacted Intelligence, National Defense, Federal Government infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2018-06-18 indictment

Grand jury indicts Schulte for illegal transmission of national defense information and computer hacking under the Espionage Act.

2022-07-13 verdict

Jury convicts Schulte on all counts of espionage, computer hacking, and obstruction of justice.

2024-02-01 sentencing

Sentenced to 480 months (40 years) in federal prison.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Joshua Adam Schulte United States sentenced 480 mo None Former CIA engineer who leaked Vault 7 cyber tools to WikiLeaks. Sentenced to 40 years in federal prison.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"Schulte abused his administrative credentials as a CIA Center for Cyber Intelligence software engineer to grant himself backdoor access to secure development servers." Indictment ¶ 14, Page 8 reviewed
T1070 Indicator Removal
Defense Evasion
"Defendant deleted server log files and altered system configuration timestamps to conceal his exfiltration of the CIA development branch." Indictment ¶ 18, Page 11 reviewed
T1560.001 Archive via Utility
Collection
"He compressed the entire CCI codebase into encrypted archives before transferring the files offsite." Trial Transcript Day 8 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Joshua Schulte (CIA Vault 7 Leak), No. 1:17-cr-00548 (U.S. District Court for the Southern District of New York 2017), https://cybercaselibrary.com/cases/us-v-schulte-cia-vault-7/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-schulte-cia-vault-7" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>