← All field notes
insider riskgovernmentcounterintelligence

The spy who is a victim: responding to a coerced insider

A cleared engineer is leaking controlled data to a foreign party - but the evidence says he is being coerced, not paid. Here is why pulling his clearance and referring him for espionage can tip the handler, foreclose counterintelligence, and endanger a victim, and what a covert, CI-led response looks like.

A cleared systems engineer is moving controlled program data to a foreign party. On its face that is espionage, and the reflex it triggers is immediate: pull his clearance, refer him, lock him out. But the evidence is off for a spy. There is no payment and no lifestyle change. The exfiltration is small, reluctant, and inconsistent, not the steady operation of someone doing this for money. There is a near-miss where he opened, then abandoned, a message to the security office. And there is a threat on his personal phone referencing a family member abroad. He is not a spy who chose this. He is being coerced.

The mental model that has to override the espionage reflex is that this is a fourth kind of insider, distinct from the malicious, the negligent, and the mistaken. The compromised insider is a victim whose access is being driven by someone else, often under threat. The adversary you actually need to reach is the handler, and the person in front of you may be the only path to them - and a human being in real danger. Treat him as the perpetrator and you lose the adversary and harm the victim in the same move.

How do you know it is coercion and not willing espionage?

By reading duress against gain, because the two produce very different responses and the mistake between them is severe. A willing recruit is paid: there is a payment trail, a negotiated relationship, coordination that serves his interest. A coerced insider shows the opposite pattern - no enrichment, visible reluctance, an exfiltration that looks forced rather than eager, and above all leverage: a threat, a piece of kompromat, a family member the adversary can reach. The aborted attempt to report is a tell too; a willing spy does not almost turn himself in.

The recipient being a foreign party is common to both and proves nothing about which you are dealing with. So is the sensitivity of the data. The discriminators are the presence of coercion and the absence of gain, and they have to be read before you act, because the disposition toward the person flips entirely on the answer. Get it wrong in the espionage direction and you prosecute a victim; get it wrong in the other direction and you extend trust to a willing adversary. Neither error is recoverable once you have moved.

Why does pulling his clearance first backfire?

Because it is a hostile, visible act against a person whose handler is watching, and it triggers three failures at once. The foreign handler learns the leverage is exposed and the network goes dark, so counterintelligence loses its chance to identify and roll it up. The classified damage assessment gets harder, because the handler’s tasking - what they asked for, what actually left - is no longer observable. And the threat against the victim and his family can escalate the instant he is exposed, because a coerced source who has been “caught” is a liability to the people coercing him.

This is the external-attacker reflex misapplied to the sharpest possible case. Against an intruder, cut-first is correct. Against a coerced insider, the fast confrontation stops a slice of trickled exposure while forfeiting the adversary, the case, and a person’s safety. The move that feels like decisive control is the one that guarantees you never reach the people actually running the operation, and may get someone hurt. Speed is not the goal; reaching the handler and protecting the victim are.

What does the right response look like?

Covert containment, mandatory reporting, and a hand-off to counterintelligence - with the person treated as someone to protect. Contain the classified exposure quietly, without any access change the handler would notice, and confirm nothing catastrophic is transferring right now. Meet the mandatory reporting duty a cleared-contractor compromise carries, and hand the operation to government counterintelligence, because this is a national-security matter and it is not the company’s to run. The company preserves evidence and supports; the CI team works the foreign service.

Coordinated with them, the contractor is approached as a coerced victim who can be helped - with protection for him and his family and a route to cooperate - rather than a cold accusation. This is not softness; it is what works. Duty of care to the person and duty to protect the classified information are not in conflict once you separate the compromise from the individual, and treating him as a victim is frequently what unlocks the cooperation that lets counterintelligence reach the handler and scope the damage. The alternative - a unilateral clearance-pull and confrontation - forecloses all of it.

What if you get the direction wrong?

The reason to read duress carefully is that the error runs both ways, and both directions are costly. Treat a coerced victim as a willing spy and you prosecute a person under threat, tip the handler, and lose the network. But treat a willing spy as a coerced victim and you extend protection, patience, or an amnesty path to a genuine adversary - slowing containment and handing a real leaker room to keep operating. Neither mistake is cheap, and the evidence that separates the two is not always clean at the outset.

This is another reason the covert, counterintelligence-led process is the right frame rather than a fast unilateral call. The process is built to resolve exactly this ambiguity: preserve evidence, scope the behavior and the leverage, and let the people whose job is coercion and recruitment assess which one you have before anyone acts irreversibly. A rushed decision in either direction forecloses that. Reading duress-versus-gain is the first cut, but confirming it - and choosing the disposition that matches - is work you do deliberately and with the right authorities, not in the first hour on a hunch.

It is worth naming the tell that most often gets missed: the absence of gain. Investigators primed to look for espionage look for the payment, the motive, the tradecraft, and when a case has none of that they can force it into the spy template anyway because the data is leaving. The missing payment is not exculpatory noise; it is a signal. A leak with no enrichment and clear leverage is far more likely coercion than a cleverly hidden sale, and treating the anomaly as evidence rather than an inconvenience is what keeps you from mislabeling a victim.

Why is the company’s lane so narrow here?

Because acting outside the counterintelligence and mandatory-reporting process can breach reporting duties, taint a federal case, and exceed the company’s authority - turning a cooperating reporter into part of the problem. A cleared-contractor compromise is not an internal HR matter or a standard security incident; it is a national-security event with its own rules. Running your own investigation to “keep control,” keeping it inside the insider-threat team, or referring the person to local police for arrest are all ways to tip the foreign handler and mishandle a federal matter.

The lane is: preserve, contain covertly, report, and support - and let counterintelligence run the operation against the foreign service. Staying in that lane is both the legal obligation and what protects the case, and a mishandled compromise invites government scrutiny of the insider-threat program and the facility clearance itself, a review that can outlast and outweigh the original leak. The discipline of doing less, and handing off, is the discipline that keeps the firm and the case intact.

Why does personnel safety belong in the security response?

Because when a foreign handler holds leverage over real people, safety is an operational variable that shapes every decision, not a concern to pass to HR afterward. The leverage is, by definition, a threat to the victim and his family, and a hostile or poorly timed move can escalate that threat or push the victim further under the handler’s control. So the timing and manner of any action - when he is approached, how, by whom - are coordinated with counterintelligence and with protective resources, and the response weighs human safety alongside the classified exposure from the start.

That is the final way the compromised insider inverts the playbook. The maturity of an insider program shows in whether it can hold three things at once: the duty to protect classified information, the counterintelligence hand-off, and the safety of a coerced human being. Programs built only to catch bad actors miss all three, because this person is not a bad actor - he is the adversary’s victim, and the response that protects the mission also has to protect him.

The through-line across every insider type reaches its extreme here: acting fast against a person with legitimate access is usually the wrong move, and when that person is a coerced victim with a handler, the reflexive lockout does not just lose the case - it can cost a life.

Frequently asked questions

How do you tell a coerced insider from a willing spy?

By duress versus gain. A willing recruit negotiates and is paid, with a handler relationship that serves their interest. A coerced insider shows no enrichment, visible reluctance, a threat or leverage against them or their family, and sometimes an aborted attempt to seek help. The recipient being foreign is common to both; the presence of coercion and the absence of gain are the discriminators.

Why not immediately pull the clearance and refer for espionage?

Because it is the external-attacker reflex and it backfires here. The moment you confront a coerced insider you tip the foreign handler, who goes dark - foreclosing counterintelligence's chance to identify and roll up the network - and the threat against his family can escalate. You also may not have contained the classified exposure or done the mandatory reporting. Speed against a victim with a handler loses the case and endangers a person.

Whose job is it to run this - the company or the government?

A cleared-contractor compromise is a national-security matter that carries a mandatory reporting duty and belongs with government counterintelligence. The company's role is to preserve evidence, contain the classified exposure covertly, meet the reporting duty, and support - not to run a CI operation, freelance a confrontation, or arrest via local police, all of which can tip the adversary and exceed the company's authority.

Does treating him as a victim mean ignoring the classified data he leaked?

No. You contain the classified exposure and run the damage assessment in parallel with protecting the person - the duties are not in conflict once you separate the compromise from the individual. Treating him as a coerced victim is often what unlocks his cooperation, which is exactly what helps counterintelligence work the handler and contain the damage.

Why does personnel safety belong in the security response?

Because the handler's leverage is a threat to real people, so a clumsy move can get the victim or his family hurt or push him deeper under the handler's control. Safety therefore shapes the timing and manner of every action and is coordinated with counterintelligence and protective resources - it is an operational factor, not something to hand off to HR after the fact.