The Five Eyes intelligence alliance has warned that Chinese military intelligence services are using professional networking, recruitment, and freelance platforms including LinkedIn, Indeed, and Upwork to identify and cultivate people with access to sensitive government and military information. According to the joint bulletin, Chinese operatives pose as recruiters, consultants, think tanks, or HR firms, then build relationships with targets and gradually request increasingly sensitive reporting. The campaign is aimed not only at security clearance holders and active military personnel, but also at academics, journalists, freelance writers, think tank staff, and others whose unclassified knowledge of policy, strategy, capabilities, or installations can be combined into actionable intelligence.
The advisory says communications often shift from mainstream platforms to encrypted messaging apps, while payments may be routed through services such as PayPal, Zelle, Wise, Western Union, and cryptocurrency. Officials said some targets have already provided information, leading in some cases to criminal prosecutions, revoked security clearances, and job losses. The warning builds on earlier MI5 alerts, including concerns about Chinese approaches to parliamentarians and a prior estimate that roughly 10,000 Britons were targeted over five years, while similar tactics have also been reported in the United States through fake consulting firms seeking information from former federal workers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The FBI and U.S. Department of Justice seized 13 websites allegedly used by Chinese intelligence operatives to target current and former U.S. officials and military personnel with security clearances. According to the DOJ, the domains posed as consulting firms offering vague, well-paid jobs to elicit research reports and sensitive insider information.
The Five Eyes intelligence alliance issued a joint bulletin warning that Chinese military intelligence services are using LinkedIn, Indeed, Upwork, and similar platforms to recruit government and military insiders in Western countries. The advisory described a multi-step scheme in which operatives pose as recruiters or consultants and solicit increasingly sensitive non-public information.
MI5 previously warned that Chinese agents had used LinkedIn and similar recruitment approaches to target members of parliament and parliamentarians.
According to DOJ details cited by Nextgov, the Chinese intelligence-linked recruitment operation began in November 2023. The campaign used fake consulting firms, job and freelance platforms, false personas, stolen identities, AI-generated profile photos, encrypted messaging, and covert payment methods to target U.S. clearance holders.
An earlier UK alert cited by The Register said that by 2021, around 10,000 Britons had been approached over a five-year period as part of Chinese intelligence-linked recruitment efforts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
19 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcegovinfosecurity.com
Open sourcehelpnetsecurity.com
Open sourcebankinfosecurity.com
Open sourcemi5.gov.uk
Open sourcebitdefender.com
Open sourcemi5.gov.uk
Open sourcemi5.gov.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.