MI5 has issued an espionage alert to members of the UK Parliament, warning that Chinese intelligence operatives are using fake recruitment agents and social media platforms, particularly LinkedIn, to target individuals with access to sensitive government information. The alert, circulated by the speakers of both the House of Commons and House of Lords, specifically identified two LinkedIn profiles believed to be operated by Chinese Ministry of State Security (MSS) officers posing as legitimate headhunters. These efforts are part of a broader campaign to cultivate relationships with MPs, peers, parliamentary staff, and professionals involved in policy development, including economists and think tank staff.
Security Minister Dan Jarvis emphasized that this activity represents a covert attempt by a foreign power to interfere in the UK's sovereign affairs and highlighted previous Chinese cyber-operations targeting parliamentary emails and other interference attempts. In response, the UK government is investing £170 million to upgrade encrypted technology for government business and introducing new measures to counter Chinese cybercrime and influence operations. Intelligence agencies in other countries, such as Australia, have also warned about the use of professional networking sites for espionage, underscoring the global nature of this threat.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
MI5 warned that Chinese intelligence operatives were using fake headhunters and professional networking platforms such as LinkedIn to approach UK lawmakers and other politically connected individuals for intelligence-gathering purposes. The warning highlighted a state-backed social-engineering effort aimed at cultivating targets online.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.