Skip to content
EternaEdge

Counterintelligence

Procurement networks are the quiet front of economic espionage

12 August 2026 · 2m read · By EternaEdge

Two guilty pleas a week apart sketch the demand side of technology theft. In early August, Estonian national Andrey Shevlyakov pleaded guilty in Brooklyn to running a procurement network that supplied sensitive U.S. electronics to Russian military and government contractors for nearly a decade, using front companies and fake identities to evade Entity List restrictions, per the Department of Justice. On August 10, PRC citizen Dingwei Chen pleaded guilty in Salt Lake City to attempting to buy export-controlled satellite modems and radios manufactured for the U.S. military — paying a $40,000 down payment plus $30,000 in cryptocurrency for ten modems that could never be licensed for export to China.

Neither case involved an intelligence officer in a trench coat. Both involved something more scalable: commercial-looking buyers working the seams of ordinary sales channels. The FBI, for its part, has been publicizing a broader enforcement surge — its director claimed 113 foreign-spy arrests and a 53% increase in counterintelligence arrests this year, figures the bureau has not yet backed with released case data.

Why this lands on companies, not just agencies

Export enforcement happens after the attempt. The attempt happens at a company — a sales inquiry, a distributor order, a new customer with a plausible story and an address one hop from a freight forwarder. The Shevlyakov network operated for the better part of a decade because each individual transaction looked routine to the firm processing it.

  • Front companies are entities before they are orders: registration history, beneficial ownership, shared addresses and phone numbers with known diverters — visible to screening that resolves entities rather than matching names.
  • Diversion patterns repeat: transshipment hubs, mismatched end-user stories, payment structures like split cash-and-crypto deals that exist to stay under thresholds.
  • The same screening discipline the government is extending to contractors — beneficial ownership under the proposed DFARS FOCI rule — applies in reverse to customers and distributors.

OBSIDIAN — Counterintelligence treats vetting as continuous protective intelligence: beneficial-ownership analysis, sanctions and adverse-media screening, and pattern indicators resolved to one entity picture, with audit-ready output when a decision needs defending. Humans make the call on every flagged relationship; the platform is designed to surface the pattern while the order is still pending, not after the indictment.

The prosecutions will keep coming. The cheaper outcome is the sale that never ships — and that is a decision made inside a company's own screening, months before any agent gets involved.

Next step

See it run on your domains of protection.

A demo walks the full arc — signal to case to defensible record — with the domains you protect in the room.