Full Report
Under the U.K.'s National Security Act 2023, junior intelligence specialist Teddy Young, 24, was charged with two offenses for allegedly trying to pass protected information to a foreign power between November 2024 and May 2025.
Analysis Summary
# Incident Report: Insider Threat Espionage Case (Teddy Young)
## Executive Summary
A Royal Navy junior intelligence specialist, Teddy Young, was charged under the U.K. National Security Act 2023 for allegedly attempting to pass protected defense information to Russia. The subject leveraged his security clearance and position aboard a warship to access sensitive data, subsequently attempting to transmit it via the Dark Web. The incident highlights the persistent risk of insider threats within military intelligence frameworks.
## Incident Details
- **Discovery Date:** Investigation concluded/charges filed October 2025
- **Incident Date:** November 2024 – May 2025
- **Affected Organization:** Royal Navy / Ministry of Defence (MoD)
- **Sector:** Government / Defense
- **Geography:** United Kingdom / HMS Deployment (Warship)
## Timeline of Events
### Initial Access
- **Date/Time:** November 2024
- **Vector:** Authorized Insider Access
- **Details:** The subject utilized his legitimate security clearance as a junior intelligence specialist to access classified systems while deployed on a Royal Navy warship.
### Lateral Movement
- **Details:** As a specialist, the subject had authorized access to specific sensitive intelligence repositories; movement was likely within the scope of his assigned duties or via abuse of existing privileges on defense networks.
### Data Exfiltration/Impact
- **Details:** The subject accessed sensitive defense and intelligence information. He attempted to exfiltrate this data to Russian authorities using the Dark Web.
### Detection & Response
- **How it was discovered:** Joint investigation by London’s Counter Terrorism Policing unit and the Ministry of Defence.
- **Response actions taken:** Subject was monitored, investigated, and subsequently arrested. Mitigation measures were implemented by the MoD to address risks linked to the compromised data.
## Attack Methodology
- **Initial Access:** Authorized user (Insider).
- **Persistence:** Maintained through active-duty deployment and valid military credentials.
- **Privilege Escalation:** Not applicable; relied on existing high-level security clearance.
- **Defense Evasion:** Use of the Dark Web to mask communication with foreign intelligence services.
- **Credential Access:** Utilized personal government-issued credentials.
- **Discovery:** Internal reconnaissance of classified defense systems.
- **Lateral Movement:** Accessing cross-departmental intelligence files available within the Navy’s classified environment.
- **Collection:** Gathering protected defense and intelligence information.
- **Exfiltration:** Attempted transfer via Dark Web platforms.
- **Impact:** Compromise of national security secrets and potential exposure of naval operations.
## Impact Assessment
- **Financial:** Undisclosed (Investigation and mitigation costs).
- **Data Breach:** Protected defense and intelligence information.
- **Operational:** Potential compromise of warship movements and intelligence-gathering tactics.
- **Reputational:** Significant; first member of the British armed forces charged under the National Security Act 2023.
## Indicators of Compromise
- **Network indicators:** Activity involving Tor or Dark Web routing from sensitive environments (defanged: hxxps[://]check[.]torproject[.]org).
- **File indicators:** Unauthorized copying or printing of classified materials.
- **Behavioral indicators:** Accessing sensitive data outside of specific mission requirements; attempts to establish contact with foreign nationals.
## Response Actions
- **Containment measures:** Revocation of security clearances and physical detention of the subject.
- **Eradication steps:** Ministry of Defence "mitigation measures" to neutralize the utility of the leaked information.
- **Recovery actions:** Full forensic audit of the systems accessed by the subject.
## Lessons Learned
- **Key takeaways:** Technical controls cannot entirely replace the need for behavioral monitoring of personnel with high-level clearances.
- **What could have been done better:** Enhanced monitoring of outgoing traffic from naval vessels and stricter "need-to-know" silos even within intelligence specialties.
## Recommendations
- **Prevention measures:** Implementation of User and Entity Behavior Analytics (UEBA) to flag anomalous data access patterns.
- **Continuous Evaluation:** Moving from periodic clearance reviews to continuous automated vetting of personnel in sensitive roles.
- **Egress Filtering:** Stricter blocking of anonymizing software (Tor/VPNs) on all military hardware and networks.