A former employee at the Energy Department and Nuclear Regulatory Commission pleaded guilty to targeting his former colleagues in a spear-phishing campaign with the ultimate goal of infecting federal networks and selling secrets to foreign governments.
Charles Harvey Eccleston, 62, worked for the NRC until he was fired in 2010. In 2013, while living in the Philippines, he entered an unnamed foreign embassy in Manila and offered to sell access to more than 5,000 Energy Department officials’ email accounts.
According to the indictment, Eccleston asked for $18,800 for the accounts, which he said were “top secret.” He also told the foreign officials that if they weren’t interested, he would make the same offer to China, Iran or Venezuela.
The foreign officials took him up on the offer, however they were actually undercover FBI agents.
Over the course of a year, the undercover agent purchased thousands of email accounts from Eccelston, most of which were later determined to be publicly available.
During a meeting in June 2014, Eccleston gave the agent a list of 30,000 emails and also offered to design a spear-phishing campaign to bore deeper into Energy’s networks and exfiltrate more sensitive information.
Eccleston crafted a form email pretending to be from the organizers of an upcoming conference and embedded a supposedly malicious link provided by the FBI agent. He sent the email to 80 Energy employees, a number of whom worked at nuclear laboratories.
He then went to a meet to collect $80,000 for his efforts; instead he was taken into custody and later extradited to the U.S.
“Eccleston admitted that he attempted to compromise, exploit and damage U.S. government computer systems that contained sensitive nuclear weapon-related information with the intent of allowing foreign nations to gain access to that information or to damage essential systems,” Assistant Attorney General John Carlin said. “Protecting our national assets from cyber intrusions is one of our highest priorities. We must continue to evolve and remain vigilant in our efforts and capabilities to confront cyber-enabled threats and aggressively detect, disrupt and deter them.”
On Feb. 2, Eccleston pleaded guilty to charges of attempted unauthorized access and intentional damage to a protected computer. That is down from the three counts of unauthorized access and a count of wire fraud he was originally charged with.
Eccleston faces a prison sentence of 24 to 30 months and fines of up to $95,000. He is scheduled for sentencing on April 18.
“This prosecution underscores our commitment to prosecute those who carry out or plan cyberattacks against our government, whether they are in the United States or in remote locations overseas,” said U.S. Attorney Channing Phillips. “Thanks to the work of the FBI, this former federal employee was arrested before he could do any damage and he now is being held accountable for actions that could have threatened our national security.”




