Ex-CIA Officer Pleads Guilty in $194M Fake Secret Program Fraud

Former CIA officer David J. Rush, 49, pleaded guilty to one count of wire fraud for inventing a top-secret government program to divert almost $200 million in federal funds to himself.
Rush, of Ashburn, Virginia, entered the plea in federal court in Alexandria, Virginia. The case centers on about $194 million in attempted fraud, described in later filings as a $195 million scheme. Justice Department
Rush worked since 2010 for a CIA division that develops hacking tools and techniques for espionage. He lied about his education and military experience to gain employment at the CIA. TechCrunch
Over the course of 2025, Rush fabricated a so-called special access program, a project kept to a small cleared list by design, under the guise of a fake continuity of government plan, the emergency setup meant to keep government operating in a crisis. He used his access as a CIA employee to set up the top-secret, highly compartmentalized program to funnel government funds to himself.
Court filings said Rush effectively acted as his own approving official, which let him spend large sums without meaningful scrutiny. Special access programs restrict knowledge to a cleared roster by design. Rush used that secrecy to isolate the money flow from normal review.
Rush used a second forgery to move the funds. He used the fake program and a fake government contract to trick an unnamed defense contractor into buying large amounts of gold that Rush then pocketed. He admitted he devised a fake classified assignment to have the government buy 298 gold bars worth about $46 million. Washington Post
Investigators recovered more than $46 million worth of gold bars at Rush's house during his arrest. They also found over $2 million in cash, plus cars and watches. He had been in custody since his arrest in May while his defense team negotiated a possible plea deal with federal prosecutors. TechCrunch
Prosecutors and attorneys for Rush disclosed a tentative plea agreement in a joint filing on Sept. 11 in federal court in Alexandria. A federal judge had extended the deadline to formally indict Rush until Oct. 8 to allow time for both sides to pursue a plea deal.
Rush is scheduled to be sentenced in late January 2027. He faces up to 20 years in prison.
The broader context here will be familiar to anyone who builds or audits privileged systems. Compartmentalization, limiting who can see information, reduces exposure to outside collection. It increases insider risk unless paired with separation of duties, tamper-proof audit logs, and financial approval outside the secret channel. Rush's years in an offensive tooling unit likely gave him fluency in access controls and cover stories.
In my view, the failure was less about tradecraft than about control design, with one person able to create the program, approve the spending, and direct the contractor.
Worth flagging for security and infrastructure teams is the contractor step. The government did not buy gold directly in this account. A cleared vendor made the purchase under what it believed was a valid classified requirement. That pattern mirrors delegated-procurement risk in companies, where a trusted supplier acts on instructions that look authenticated but were never verified elsewhere. Verification has to live outside the compartment that issues the order.
The broader lesson here points toward tools that tighten that loop without breaking legitimate secrecy. Tamper-proof approval records, multi-person approval to create a compartment, and automatic reconciliation between contracting, payment, and inventory would not expose program content. They would expose program existence to a small, independent oversight function.


