Five Eyes Warns of China's Renewed LinkedIn Espionage Campaign Targeting Security Clearance Holders
MI5 and Five Eyes allies warn of renewed Chinese espionage campaigns on LinkedIn, Indeed, and Upwork, targeting security clearance holders with fake job ads and cash payments.
MI5 and its Five Eyes partners issued a fresh advisory on Wednesday, warning that Chinese military intelligence is aggressively recruiting security clearance holders through fake job ads on LinkedIn, Indeed, and Upwork. The campaign targets individuals in defense, security, foreign affairs, and academia, seeking classified economic and military intelligence.
The advisory, published June 3, 2026, states that Chinese operatives posed as HR firms or think tanks to place job advertisements for foreign policy and defense analysts, then pressure successful candidates to provide non-public information for unnamed clients linked to the Chinese government. An estimated 10,000 Britons were targeted in a similar campaign over the past five years, according to MI5's 2021 estimate.
Fake Job Ads and Encrypted Chats
According to MI5, the spies rank resumes by how likely a candidate is to hold sensitive information. Interviews probe for government contacts, military bases, and past responsibilities. After a trial report on China-related topics, conversations shift to encrypted messaging platforms. Payments are made via PayPal, Zelle, Wise, Western Union, or cryptocurrency.
- Targets include defense personnel, military officers, academics, journalists, think tank employees, and those with indirect government access.
- MI5 issued a similar warning in November 2025 to UK parliamentarians, naming two suspected online profiles.
- The 2021 estimate of 10,000 Britons targeted was considered conservative by MI5 Director General Ken McCallum, who said workplace platforms were exploited “on an industrial scale.”
Broader Espionage and Phishing Trends
The LinkedIn campaign is part of a wider push. Cybersecurity firm Proofpoint identified a China-linked group, TA4922, which expanded phishing attacks in June 2026 to the UK, Germany, Italy, and South Africa, using malware families ValleyRAT and AtlasRAT. Separately, Dark Reading reported that Pakistan-based actors deployed Xeno RAT to spy on Afghanistan's Finance Ministry, demonstrating how standard tools still penetrate porous defenses.
MI5 warned that even sending a resume exposes personal information, and that leaking secrets can lead to prosecution under espionage laws. “Certain types of data can place the lives of frontline military or other personnel at risk, can weaken our economic prosperity, and enable interference in our democratic processes,” the advisory stated.
What comes next: The Five Eyes are urging all security clearance holders to report suspicious LinkedIn requests and job offers. Governments are expected to tighten vetting for freelance and consulting roles, while platforms like LinkedIn face pressure to verify corporate accounts more rigorously.
Fact check
-
MI5 and Five Eyes partners issued an advisory on June 3, 2026, warning of Chinese recruitment of security clearance holders via LinkedIn, Indeed, and Upwork.
reported · source
-
MI5 estimated 10,000 Britons were targeted in similar campaigns over the past five years.
reported · source
-
China-linked group TA4922 expanded phishing attacks to the UK, Germany, Italy, and South Africa in June 2026.
reported · source
-
Pakistan-based actors used Xeno RAT to spy on Afghanistan's Finance Ministry.
reported · source
Source reporting (3)
Related Articles
Snowflake hacker pleads guilty to stealing data from 165 organizations, faces 32 years in prison
Aug 5, 2026
AI Agents From OpenAI and Anthropic Breach Real Websites During Security Tests
Aug 5, 2026
AI Agent Security Startups Zenity and Horizon3.ai Raise $375M Combined as SentinelOne Expands Autonomous SOC
Aug 3, 2026
0 Comments
No comments yet
Be the first to share your thoughts on this article.