Special Features

Cybersecurity Month

US govt IT help desk techie 'leaked top secrets' to foreign nation

National defense files can earn you $55K … and espionage charges


A US government worker has been arrested and charged with spying for Ethiopia, according to court documents unsealed Thursday.

Abraham Lemma, 50, a Silver Springs, Maryland resident and a naturalized United States citizen who was born in Ethiopia, was detained on August 24 after allegedly sending classified US national defense information to an Ethiopian intelligence agent. He has worked in various American government agencies since 2019.

Crucially, Lemma was an IT help desk technician assigned to the Bureau of Intelligence and Research with the US Department of State (DOS) since at least 2021. In addition to that dept, where he worked at night, he was also a contract management analyst at the US Department of Justice during the day, according to prosecution documents [PDF].

Both of these positions gave him access to classified information, and he's held top-secret security clearance since at least 2020.

Oddly enough, Lemma's alleged espionage activities came to light during an investigation into the DOS's handling of national defense information following the arrest of Air National Guardsman Jack Teixeira, who has been accused of leaking classified Pentagon documents on Discord, earlier this year.

"During this review, information was uncovered indicating that a Department of State information technology contractor may have removed, retained, and transmitted classified national defense information without authorization," DOS spokesperson Matthew Miller said in a statement.

According to a criminal complaint against him, between December 19, 2022 and August 7, 2023, Lemma copied, printed, and downloaded classified and top-secret information from more than 100 US intelligence reports, the majority of these relating to Ethiopia, without authorization.

He then allegedly transmitted classified national defense information, "including documents, photographs, notes, maps," and other data relating to Ethiopia and neighboring countries over an unnamed encrypted messaging app. This included satellite imagery from the region that was marked "top secret," photos of a military compound, and other information detailing military activities in the region.

According to the court documents:

Lemma's communications with the Foreign Official over Encrypted Messaging Application A included a discussion of military activities of a rebel group involved in an armed struggle against the government of the Relevant Country. In one communication, Lemma sent an image relating to events in the Relevant Country and advised the Foreign Official, '[y]our team analyze this and establish some sort of sense to this.'

Lemma also received thousands of dollars that, according to the Feds, coincided with his travels to Ethiopia and dates when he allegedly swiped and shared the classified materials. For example: on July 15, Lemma is said to have tried to deposit $11,773.84 in cash at a Maryland bank, while "angrily discouraging an employee" from filing a currency transaction report, as mandated by the US Treasury.

"Lemma downloaded classified reports from DOS close in time to this July 15, 2023 deposit — specifically, Lemma copied at least 16 reports July 11-14, 2023," court documents claim.

And after returning from a trip to Ethiopia on April 30, 2022, he allegedly deposited $4,300 on the day of his return.

"Review of Lemma's US Bank 1 account records further revealed that Lemma made several large deposits, totaling in excess of $55,000, into US Bank 1 between January 1, 2022 until July 17, 2023," according to the criminal complaint. 

Lemma has been charged with delivering national defense information to aid a foreign government, conspiracy to deliver national defense information to aid a foreign government, and the willful retention of national defense information.

The two espionage charges carry a potential penalty of death or life in prison, while the willful retention charge carries a maximum of 10 years behind bars. ®

Send us news
15 Comments

Five Eyes nations warn Moscow's mates at the Star Blizzard gang have new phishing targets

The Russians are coming! Err, they've already infiltrated UK, US inboxes

Uncle Sam probes cyberattack on Pennsylvania water system by suspected Iranian crew

CISA calls for stronger IT defenses as Texas district also hit by ransomware crew

Fancy Bear goes phishing in US, European high-value networks

GRU-linked crew going after our code warns Microsoft - Outlook not good

Hershey phishes! Crooks snarf chocolate lovers' creds

Stealing Kit Kat maker's data?! Give me a break

Scores of US credit unions offline after ransomware infects backend cloud outfit

Supply chain attacks: The gift that keeps on giving

Belgian man charged with smuggling sanctioned military tech to Russia and China

Indictments allege plot to shift FPGAs, accelerometers, and spycams

Rogue ex-Motorola techie admits cyberattack on former employer, passport fraud

Pro tip: Don't use your new work email to phish your old firm

'Serial cybercriminal and scammer' jailed for 8 years, told to pay back $1.2M

Crook did everything from SIM swaps to fake verified badge scams

Mirai malware infects routers and cameras for new botnet

Akamai sounds the alarm – won't name the manufacturers yet

MOVEit victim count latest: 2.6K+ orgs hit, 77M+ people's data stolen

Real-life impact of buggy software laid bare – plus: Avast tries to profit from being caught up in attacks

Top Ukrainian cyber officials fired after allegedly pocketing kickbacks from govt IT deals

Duo probed over alleged $2M embezzlement plot

Clorox CISO flushes self after multimillion-dollar cyberattack

Plus: Ransomware crooks file SEC complaint against victim