# Chinese Intelligence Launches Sophisticated Fake Job Campaign Targeting Five Eyes Personnel


## The Threat


Chinese military intelligence services are running a coordinated and evolving recruitment scam targeting government and military personnel across the United States, United Kingdom, Australia, Canada, and New Zealand. Operating under false identities as recruiters, they post fake job openings on legitimate professional networking platforms, carefully screening candidates based on their access to classified or privileged information.


The campaign represents a textbook example of human-centric intelligence gathering—using social engineering, financial incentive, and the veneer of legitimacy to extract sensitive government, military, and economic intelligence. The Five Eyes intelligence agencies (FBI, MI5, Australian Security Intelligence Organisation, Canada's Security Intelligence Service, and New Zealand's Security Intelligence Service) issued a joint alert on June 5, 2026, warning security-cleared personnel and government employees of the threat.


## Background and Context


Who Is Responsible


China's military intelligence services—specifically the People's Liberation Army Strategic Support Force and related divisions—are orchestrating these campaigns as part of a broader intelligence collection operation. According to the joint alert, "China's military intelligence services ultimately seek to acquire privileged military, political and economic intelligence that can provide China with a strategic and tactical advantage over the Five Eyes."


This is not an isolated incident. The Five Eyes note that China has employed recruitment-based espionage tactics for years. However, the scale and precision of the current campaign—enabled by professional networking platforms—represents a significant evolution in tradecraft.


The Targeting Strategy


The campaigns operate across familiar platforms where government and military personnel congregate:


| Platform | Primary Use |

|----------|------------|

| LinkedIn | Professional networking, recruiter outreach |

| Indeed | Job search and career advancement |

| Upwork | Freelance project platforms |


Chinese operatives post job announcements impersonating:

  • Think tanks and policy research organizations
  • Private defense consultancies
  • Human resources firms
  • International business advisory groups

  • The positions advertised are deliberately aligned with targets' backgrounds—foreign policy analysts, defense policy specialists, military strategists, and international relations experts. Resumes are then screened and ranked based on indicators of access to classified or sensitive government information.


    ## Technical Details: How the Scheme Works


    The recruitment pipeline follows a methodical progression designed to gradually increase the sensitivity of requested information:


    Stage 1: Initial Contact

    Selected candidates are contacted and invited to participate in virtual interviews. Importantly, the recruiters actively conceal their true identities and affiliation during these conversations.


    Stage 2: Information Probing

    During interviews, fake recruiters probe candidates about their current government work, their position titles, agency affiliations, and—critically—their access to sensitive personnel information and classified systems.


    Stage 3: Trial Assignment

    Once a candidate demonstrates access or knowledge of interest, they receive an assignment: write a trial report on a specified geopolitical topic such as:

  • China's bilateral relations with Five Eyes countries
  • Strategic developments in the Indo-Pacific region
  • Defense policy and military capabilities
  • International trade and economic competition

  • The trial report is framed as a writing sample to demonstrate the candidate's analytical abilities.


    Stage 4: Escalation and Payment

    Following successful completion of the trial report, candidates are informed that additional assignments are available—with a critical catch: the follow-up reports must include "more privileged information." Communication is moved to encrypted messaging platforms (Signal, Telegram, ProtonMail) to create the illusion of increased security.


    Payment begins at modest levels—a few hundred to several thousand dollars per report—but increases significantly as requests escalate in sensitivity. Payment methods include:

  • PayPal, Payoneer, and similar third-party payment services
  • Zelle and other direct transfer platforms
  • Cryptocurrency (Bitcoin, Ethereum)
  • Western Union and e-transfer services
  • Wise (TransferWise)

  • Critically, payments typically originate from accounts belonging to individuals unconnected to the recruitment process, further obscuring the operation's source.


    Stage 5: Long-Term Relationship Building

    The goal is to establish an ongoing financial and intelligence relationship, with candidates becoming increasingly comfortable sharing sensitive information over time. Even unclassified information is valuable—Five Eyes intelligence officials warn that "unclassified information provided by candidates is likely collected and combined with more sensitive data."


    ## Implications for Organizations and Personnel


    Intelligence Impact


    The scope of information China seeks extends beyond pure military secrets. According to the Five Eyes alert:


  • Military intelligence: Operational capabilities, personnel deployments, strategic vulnerabilities
  • Political intelligence: Government decision-making, policy debates, diplomatic strategy
  • Economic intelligence: Trade policy, sanctions regimes, industrial competitiveness
  • Personnel data: Contact information for government and military officials

  • The aggregation of even unclassified information—when combined across multiple sources—can reveal patterns, relationships, and strategic priorities that provide China with significant tactical and strategic advantage.


    Legal and Career Consequences


    Personnel who knowingly disclose classified information face severe legal jeopardy:


  • Federal espionage charges carrying up to life imprisonment
  • Automatic security clearance revocation
  • Permanent termination from government service
  • Civil liability and asset seizure
  • Reputational damage and career destruction

  • Even inadvertent disclosure of properly classified information carries criminal penalties.


    Broader Threat Landscape


    The campaigns highlight the expanding "insider threat" problem. As security researcher Steve Povolny of Exabeam notes, adversaries are no longer limited to recruiting willing insiders—they're systematically targeting the entire ecosystem of individuals with proximity to sensitive information: contractors, former government employees, academics, researchers, and media professionals.


    ## Recommendations for Defense and Detection


    For Government and Military Personnel:


    1. Scrutinize Unsolicited Recruitment Offers

    - Verify any job opportunity through official channels and the organization's verified website

    - Be skeptical of high-paying short-term assignments

    - Legitimate recruiters do not ask candidates to discuss classified work or access levels


    2. Report Suspicious Approaches Immediately

    - Contact your security officer or counterintelligence office

    - Report the recruiter's profile and communications to the platform

    - Do not continue engagement with suspicious contacts


    3. Limit Professional Information Exposure

    - Review LinkedIn and other profile visibility settings

    - Avoid discussing current role, clearance level, or access in public forums

    - Use generic titles in public professional networks when possible


    For Organizations:


    1. Enhanced Insider Threat Programs

    - Update training to include recruitment-based espionage tactics

    - Establish clear reporting mechanisms for suspicious recruitment outreach

    - Monitor for candidates who have engaged with suspected intelligence fronts


    2. Platform Monitoring

    - Audit profiles of cleared employees for excessive information exposure

    - Implement alerts for employees receiving outreach from suspicious organizations

    - Coordinate with platform security teams to identify and remove fake recruiter accounts


    3. Financial Reporting

    - Implement systems to detect employees receiving unexplained payments or side income

    - Train security personnel to recognize payment methods commonly used in recruitment schemes


    ---


    ## HackWire Analysis


    This campaign exposes a critical vulnerability in the post-pandemic employment landscape: the normalization of remote recruitment and virtual interviews has eliminated many traditional friction points that once caught intelligence operatives. A government employee interviewing virtually with what appears to be a legitimate think tank has far less ability to verify legitimacy than one conducting in-person interviews at an actual office.


    What distinguishes the current campaign is its industrial scale. Chinese operatives are systematically targeting thousands of cleared professionals across five countries simultaneously, using the algorithmic targeting capabilities of professional networks to identify high-value prospects. This is espionage as a numbers game—cast a wide net, filter for access levels, and convert a small percentage into productive assets.


    The payment structure is particularly clever: by starting at modest sums ($500-$2,000 per report) and increasing gradually, operatives create a psychological commitment trap. Candidates rationalize initial disclosures as minor and non-classified, but by the time sensitive information is requested, they've already accepted payment and rationalized their participation. The line between "consulting work" and "espionage" blurs conveniently.


    For defenders, the uncomfortable truth is that this attack vector is nearly impossible to fully prevent. You cannot stop individuals from being approached. What you *can* do is create organizational cultures where reporting suspicious outreach is normalized and rewarded rather than career-threatening, and where the financial incentive structure makes disclosure less compelling. But that requires sustained commitment—not just one-time training.


    The Five Eyes warning should prompt immediate action from any organization employing cleared personnel: security briefings must move beyond theoretical awareness into practical instruction on *how* these schemes actually work. — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)