The story published by NASA's Office of Inspector General should worry every organization that holds sensitive knowledge, code, software, engineering designs or valuable business information.
According to the publication, a Chinese citizen named Song Wu posed for years as American engineers, researchers and professors, and approached NASA employees, academic researchers, military personnel and private companies. His goal was not to obtain a password to an account. He asked for something far simpler and far more dangerous: copies of software, source code and sensitive engineering tools that could be used for aeronautical design and the development of weapons systems.
And that is exactly the point.
In many organizations, when people hear the word 'phishing', they immediately think of an email with a suspicious link, a fake website or a request to enter a password.
But in more sophisticated cases, phishing does not look like a cyberattack. It looks like a legitimate professional request from a familiar person. 'Please send me the code'. 'I need the latest version of the software'. 'Send me the file, I'm working on it with the team'.
The victim doesn't feel they are falling for an attack. They feel they are helping a colleague.
And that is precisely the danger.
The professional mistake I see again and again is that organizations treat this threat only as a technological problem. But in this case, the central weakness was not only in the system. It was in human trust, in the work culture, and in the absence of a clear mechanism that requires stopping and checking before sensitive information goes out.
As I see it, there are several important lessons here.
Not every request that comes from a 'familiar' person really comes from them.
Not every sharing of information between colleagues is an innocent act, especially when it involves code, software, plans, data, models or infrastructure.
Employees need to know how to recognize not only suspicious links, but also unusual requests: repeated requests for the same software, no explanation of why the information is needed, a sudden change in the payment or transfer method, the use of unconventional channels, or pressure to hand over material without an orderly process.
And most importantly: in a serious organization, an employee should not decide alone whether sensitive material may be transferred to another party, even if that party appears familiar, senior or professional.
You need a procedure. You need identity verification. You need a permissions check. You need an understanding of the limits of regulation, export, confidentiality and intellectual property. And you need a culture in which stopping to check is not seen as bureaucracy, but as part of professional responsibility.
The NASA story is a sharp reminder that an insider threat does not always begin with a malicious employee. Sometimes it begins with a good, professional employee who wants to help, but doesn't realize they are being manipulated.
And that may be one of the most dangerous threats of all: a human Trojan horse that doesn't know it is one.