FBI Arrested U.S. Government Contractor Who Allegedly Stole More than $46 Million
On Thu, Mar 4, 2026, an international law enforcement operation resulted in the capture of John Daghita, a U.S. government contractor. Daghita is accused of insider theft, allegedly stealing over $46 million in cryptocurrency from the United States…
On Thu, Mar 4, 2026, an international law enforcement operation resulted in the capture of John Daghita, a U.S. government contractor. Daghita is accused of insider theft, allegedly stealing over $46 million in cryptocurrency from the United States Marshals Service (USMS).
The arrest highlights concerns regarding insider threats and the secure management of seized digital assets by federal agencies. FBI Director Kash Patel confirmed the arrest on Fri, Mar 5, 2026, emphasizing the agency's commitment to pursuing individuals who defraud American taxpayers.
Daghita was apprehended on the Caribbean island of Saint Martin in a coordinated effort involving the FBI and French tactical units. The operation included the International Co-operation Team Serious Crime Unit of the French Gendarmerie Nationale in Saint Martin and the Groupe d'intervention de la Gendarmerie nationale (GIGN) of Guadeloupe. This collaboration demonstrates the global reach of U.S. law enforcement in tracking cybercriminals and rogue insiders.
The rapid coordination between U.S. and French authorities was critical in capturing the suspect before he could further launder or disperse the stolen digital funds. This quick action likely prevented the $46 million in cryptocurrency from disappearing into the dark web or being cleaned through crypto mixers, a common tactic among cybercriminals.
On Thu, Mar 4, 2026, an international law enforcement operation resulted in the capture of John Daghita, a U.S.
The theft from the U.S. Marshals Service underscores a severe insider threat problem. The USMS manages and liquidates cryptocurrency seized during criminal investigations. A breach of this magnitude suggests potential gaps in the agency's digital asset custody protocols, such as privileged access management and multi-signature wallet controls.
Insider threats are challenging to defend against because the actor already possesses legitimate network credentials and system knowledge. When contractors have high-level access to sensitive government financial vaults, organizations must implement strict zero-trust architectures. This incident may prompt a comprehensive security audit of how the USMS and other federal bodies handle, store, and transfer seized digital currencies.
Ensuring no single individual has unilateral access to hardware wallets or private keys is a fundamental defense against insider theft. Moving forward, agencies may need to adopt stricter continuous monitoring and behavioral analytics to detect anomalous asset transfers in real time.
The arrest of John Daghita underscores the importance of robust internal security policies alongside defenses against external cyberattacks.
Based on reporting by Cyber Security News.
