He is basically a walking profile of insider threat behaviour modeling.
I don’t think it was anything other than his stupidity that put him on the radar so quickly. Reading the indictment it’s clear he was a bit of an idiot.
Given that his access of the documents was logged anyway, it wouldn't surprise me if the misconfiguration was itself a honeypot, using documents that are relatively low-value but still classified.
I could never get anything done in espionage. I’m far too paranoid.
https://www.namecheap.com/domains/registration/results/?doma...
It doesn't even need to be true, just needs to be compelling.
Occasionally, though, it does work like you say. I think there was some Asian(?) politician that they tried to blackmail after something like this, and he basically said: "Hey, could you send me a copy of the sex tape? She was smokin' hot, and I'd love to have the video."
https://medium.com/war-is-boring/the-cia-and-kgb-tried-to-bl...
I'm looking at this to be possible more like when you have company wide phishing tests going through the emails, and it catches Brenda the new person in accounting who's still on their probationary period.
People email that account with offers of providing information to the russian government, and then the FBI goes and sees who had access to the documents which get sent over. In this case, only one person accessed all the documents, so even if he doesn't identify himself to I_AM_A_RUSSIAN_SPY@gmail.com, they still get him.
It doesn't seem like this person was specifically targeted or had an operation against him. He just fell into the honey pot.
Say you are the CTO or engineering security staff of say Google.
What is the first 3 months of employment called behind the scenes?
Probation.
It's not just a nickname, as one would track all accesses to anything and higher access rights would obvious follow proven trust. And one might even set up honey pot traps to weed out the bad actors even.