# Chinese Intelligence Launches Sophisticated Fake Job Campaign Targeting Five Eyes Personnel
## The Threat
Chinese military intelligence services are running a coordinated and evolving recruitment scam targeting government and military personnel across the United States, United Kingdom, Australia, Canada, and New Zealand. Operating under false identities as recruiters, they post fake job openings on legitimate professional networking platforms, carefully screening candidates based on their access to classified or privileged information.
The campaign represents a textbook example of human-centric intelligence gathering—using social engineering, financial incentive, and the veneer of legitimacy to extract sensitive government, military, and economic intelligence. The Five Eyes intelligence agencies (FBI, MI5, Australian Security Intelligence Organisation, Canada's Security Intelligence Service, and New Zealand's Security Intelligence Service) issued a joint alert on June 5, 2026, warning security-cleared personnel and government employees of the threat.
## Background and Context
Who Is Responsible
China's military intelligence services—specifically the People's Liberation Army Strategic Support Force and related divisions—are orchestrating these campaigns as part of a broader intelligence collection operation. According to the joint alert, "China's military intelligence services ultimately seek to acquire privileged military, political and economic intelligence that can provide China with a strategic and tactical advantage over the Five Eyes."
This is not an isolated incident. The Five Eyes note that China has employed recruitment-based espionage tactics for years. However, the scale and precision of the current campaign—enabled by professional networking platforms—represents a significant evolution in tradecraft.
The Targeting Strategy
The campaigns operate across familiar platforms where government and military personnel congregate:
| Platform | Primary Use |
|----------|------------|
| LinkedIn | Professional networking, recruiter outreach |
| Indeed | Job search and career advancement |
| Upwork | Freelance project platforms |
Chinese operatives post job announcements impersonating:
The positions advertised are deliberately aligned with targets' backgrounds—foreign policy analysts, defense policy specialists, military strategists, and international relations experts. Resumes are then screened and ranked based on indicators of access to classified or sensitive government information.
## Technical Details: How the Scheme Works
The recruitment pipeline follows a methodical progression designed to gradually increase the sensitivity of requested information:
Stage 1: Initial Contact
Selected candidates are contacted and invited to participate in virtual interviews. Importantly, the recruiters actively conceal their true identities and affiliation during these conversations.
Stage 2: Information Probing
During interviews, fake recruiters probe candidates about their current government work, their position titles, agency affiliations, and—critically—their access to sensitive personnel information and classified systems.
Stage 3: Trial Assignment
Once a candidate demonstrates access or knowledge of interest, they receive an assignment: write a trial report on a specified geopolitical topic such as:
The trial report is framed as a writing sample to demonstrate the candidate's analytical abilities.
Stage 4: Escalation and Payment
Following successful completion of the trial report, candidates are informed that additional assignments are available—with a critical catch: the follow-up reports must include "more privileged information." Communication is moved to encrypted messaging platforms (Signal, Telegram, ProtonMail) to create the illusion of increased security.
Payment begins at modest levels—a few hundred to several thousand dollars per report—but increases significantly as requests escalate in sensitivity. Payment methods include:
Critically, payments typically originate from accounts belonging to individuals unconnected to the recruitment process, further obscuring the operation's source.
Stage 5: Long-Term Relationship Building
The goal is to establish an ongoing financial and intelligence relationship, with candidates becoming increasingly comfortable sharing sensitive information over time. Even unclassified information is valuable—Five Eyes intelligence officials warn that "unclassified information provided by candidates is likely collected and combined with more sensitive data."
## Implications for Organizations and Personnel
Intelligence Impact
The scope of information China seeks extends beyond pure military secrets. According to the Five Eyes alert:
The aggregation of even unclassified information—when combined across multiple sources—can reveal patterns, relationships, and strategic priorities that provide China with significant tactical and strategic advantage.
Legal and Career Consequences
Personnel who knowingly disclose classified information face severe legal jeopardy:
Even inadvertent disclosure of properly classified information carries criminal penalties.
Broader Threat Landscape
The campaigns highlight the expanding "insider threat" problem. As security researcher Steve Povolny of Exabeam notes, adversaries are no longer limited to recruiting willing insiders—they're systematically targeting the entire ecosystem of individuals with proximity to sensitive information: contractors, former government employees, academics, researchers, and media professionals.
## Recommendations for Defense and Detection
For Government and Military Personnel:
1. Scrutinize Unsolicited Recruitment Offers
- Verify any job opportunity through official channels and the organization's verified website
- Be skeptical of high-paying short-term assignments
- Legitimate recruiters do not ask candidates to discuss classified work or access levels
2. Report Suspicious Approaches Immediately
- Contact your security officer or counterintelligence office
- Report the recruiter's profile and communications to the platform
- Do not continue engagement with suspicious contacts
3. Limit Professional Information Exposure
- Review LinkedIn and other profile visibility settings
- Avoid discussing current role, clearance level, or access in public forums
- Use generic titles in public professional networks when possible
For Organizations:
1. Enhanced Insider Threat Programs
- Update training to include recruitment-based espionage tactics
- Establish clear reporting mechanisms for suspicious recruitment outreach
- Monitor for candidates who have engaged with suspected intelligence fronts
2. Platform Monitoring
- Audit profiles of cleared employees for excessive information exposure
- Implement alerts for employees receiving outreach from suspicious organizations
- Coordinate with platform security teams to identify and remove fake recruiter accounts
3. Financial Reporting
- Implement systems to detect employees receiving unexplained payments or side income
- Train security personnel to recognize payment methods commonly used in recruitment schemes
---
## HackWire Analysis
This campaign exposes a critical vulnerability in the post-pandemic employment landscape: the normalization of remote recruitment and virtual interviews has eliminated many traditional friction points that once caught intelligence operatives. A government employee interviewing virtually with what appears to be a legitimate think tank has far less ability to verify legitimacy than one conducting in-person interviews at an actual office.
What distinguishes the current campaign is its industrial scale. Chinese operatives are systematically targeting thousands of cleared professionals across five countries simultaneously, using the algorithmic targeting capabilities of professional networks to identify high-value prospects. This is espionage as a numbers game—cast a wide net, filter for access levels, and convert a small percentage into productive assets.
The payment structure is particularly clever: by starting at modest sums ($500-$2,000 per report) and increasing gradually, operatives create a psychological commitment trap. Candidates rationalize initial disclosures as minor and non-classified, but by the time sensitive information is requested, they've already accepted payment and rationalized their participation. The line between "consulting work" and "espionage" blurs conveniently.
For defenders, the uncomfortable truth is that this attack vector is nearly impossible to fully prevent. You cannot stop individuals from being approached. What you *can* do is create organizational cultures where reporting suspicious outreach is normalized and rewarded rather than career-threatening, and where the financial incentive structure makes disclosure less compelling. But that requires sustained commitment—not just one-time training.
The Five Eyes warning should prompt immediate action from any organization employing cleared personnel: security briefings must move beyond theoretical awareness into practical instruction on *how* these schemes actually work. — HackWire Editorial
---
## Related Coverage