Treasury Sanctions Exploit Broker Network for Theft and Sale of U.S. Government Cyber Tools
Full article text is available in the Catalayer news terminal.
Summary
The Treasury Department's OFAC and the State Department jointly sanctioned Russian national Sergey Zelenyuk and his company Operation Zero, along with five associated individuals and entities, for stealing and reselling at least eight proprietary US government cyber tools, marking the first-ever sanctions action under the Protecting American Intellectual Property Act after an Australian former employee of the victimized US company pleaded guilty to trade secret theft in October 2025.
Market Impact
The case originated when Peter Williams, the Australian former employee, stole proprietary cyber tools from his US employer between 2022 and 2025 and sold them to Operation Zero for millions of dollars paid in cryptocurrency, after which Operation Zero resold the stolen tools to at least one unauthorized buyer—illustrating a multi-stage theft-to-resale pipeline for government-grade cyber capabilities. Beyond the core theft, OFAC's designation revealed Operation Zero has separately sought to develop spyware and methods for extracting personal data from users of AI applications including large language models, while explicitly marketing exclusively to customers from non-NATO countries and pursuing relationships with foreign intelligence agencies. The sanctions network extended to associated entities including a UAE-based technology company and a Trickbot-linked Russian national previously
Why It Matters
The first-ever use of the Protecting American Intellectual Property Act, combined with revelations that the sanctioned exploit broker was separately developing methods to extract data from AI and large language model users, signals an expanding legal and threat-intelligence focus on both stolen government cyber tools and emerging AI-targeted data theft techniques.
Key Points
- OFAC and the State Department sanctioned Russian national Sergey Zelenyuk and his company Operation Zero in the first-ever action under the Protecting American Intellectual Property Act
- The stolen tools originated from Australian national Peter Williams, a former employee of a US company who pleaded guilty in October 2025 to stealing proprietary cyber tools and selling them to Operation Zero for millions in cryptocurrency
- Operation Zero separately sought to develop spyware and methods to extract personal data from users of AI applications including large language models
- The sanctions network included a UAE-based technology company and a Russian national linked to the Trickbot ransomware gang, which OFAC had previously sanctioned for attacks on US hospitals
Key Entities
Evidence
OFAC designated Sergey Sergeyevich Zelenyuk and his company, Matrix LLC (doing business as Operation Zero), as well as five associated individuals and entities, for their acquisition and distribution of cyber tools ha...Supports: Confirms the sanctions designation and its core basis
These are the first persons sanctioned under this law, which provides for sanctions against persons who have knowingly engaged in, or benefitted from, significant theft of trade secrets of United States personsSupports: Documents the first-ever PAIPA sanctions designation
Zelenyuk and Operation Zero have also sought to develop other cyber intelligence systems, including spyware and methods to extract personal identifying information and other sensitive data uploaded by users of artific...Supports: Grounds the AI/LLM data-extraction dimension of the case
Kucherov is a Russian national and a suspected member of the Trickbot cybercrime gang. OFAC previously designated members of the Trickbot group in February 2023 and September 2023.Supports: Grounds the connection to the previously-sanctioned Trickbot ransomware infrastructure