> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Chinese Spies Target U.S. Security Clearance Holders
- URL: https://www.cybrsecmedia.com/chinese-spies-target-u-s-security-clearance-holders/
- Published: 2026-09-10T13:04:04.000Z
- Updated: 2026-09-10T13:05:44.000Z
- Description: Chinese intelligence operatives are using fake consulting firms, job offers and recruiter profiles to target U.S. security clearance holders and other government and defense professionals.
- Author: George V. Hulme
- Tags: Chinese spies, Fake recruiters, Cyber espionage, Article

From mid-2025, the phones at the small Brisbane, Australia consultancy Horizzen began ringing with calls from job seekers. Hopeful candidates emailed, responding to openings for international consultants. The problem? The jobs never existed, and Horizzen never operated in the fields posted.

Someone was hiring. By using the company's name, corporate logo, and website materials, they ran a convincing clone of the business. That fake site, thehorizzen\[dot\]com, turned out to be one of 13 sham consultancy domains seized by the U.S. Department of Justice this past spring, in what federal authorities describe as a Chinese intelligence operation to recruit Americans with access to classified and sensitive government information.

The company had been "drawn into what western intelligence agencies allege is a systematic campaign by Chinese spies to recruit and pressure people into revealing valuable secrets," The Guardian [reported](https://www.theguardian.com/australia-news/2026/aug/17/fbi-investigation-china-alleged-espionage-fake-websites-defence-intelligence-australia?ref=cybrsecmedia.com) in its August 17 exclusive.

[Subscribe to the CYBR.SEC.Media newsletter](#/portal/signup/free)

## Who's being hunted, and why

Anyone who holds, or has ever held, a U.S. security clearance is of active interest to Chinese military intelligence, and the hunting has been happening on the same platforms people use to find work.

In a joint bulletin issued June 3, 2026, the Five Eyes intelligence alliance- the U.S., U.K., Australia, Canada, and New Zealand warned that Chinese intelligence officers are posing as recruiters and consultants for fake "cover companies" on LinkedIn, Indeed, Upwork, and other job platforms. The bulletin, "Safeguarding Our Secrets," said the operatives "seek to acquire privileged military, political and economic intelligence that can provide China with a strategic and tactical advantage."

The target pool is broader than active clearance holders. It includes former government and military personnel, defense contractors, academics, journalists, and think-tank employees: essentially anyone whose career has touched government, defense, or foreign policy.

Security professionals need to understand this threat. The consequences of taking the bait fall on the recruit, not just the recruiter. The Five Eyes bulletin warns that people roped in through these schemes have already faced "criminal prosecutions, job losses, and security-clearance revocation," with potential prosecution under espionage laws.

**Related:**

[HOU.SEC.CON: Cyberwarfare and the Taiwan ConflictDimitri Alperovitch’s keynote warned that cyber operations could be a decisive element in any U.S.-China conflict over Taiwan sovereignty.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-9d8d1230-77cc-4cf4-bb32-0546851dd281.jpg)CYBR.SEC.MediaGeorge V. Hulme![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/image-cbd46abf-d45d-45a0-831e-ec034272e119.png)](https://www.cybrsecmedia.com/hou-sec-con-cyberwarfare-taiwan-conflict/)

[ATA 2026: China, Russia, Iran, North Korea Treat U.S. Infrastructure as a Standing BattlespaceThe Office of the Director of National Intelligence’s 2026 Annual Threat Assessment (ATA) highlights escalating risks to the U.S. from China, Russia, Iran, North Korea, and aggressive ransomware actors, emphasizing pre-positioning in key systems for potential disruption during crises.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-820e6dee-19b5-4455-9baf-9a801c79b832.jpg)CYBR.SEC.MediaGeorge V. Hulme![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/d3ae1cb4-b707-4e63-a9c4-b20826dd3cc2-ed7b7e54-9f6d-4926-b810-0ad270aeb13d.png)](https://www.cybrsecmedia.com/ata-2026-china-russia-iran-north-korea-treat-u-s-infrastructure-as-a-standing-battlespace/)

## A campaign years in the making

The Horizzen case is the visible edge of an operation that, according to the FBI affidavit underlying the seizures, began no later than November 2023\. The conspirators built at least 13 fake consulting firms. Among them, Centrik Global Consulting, Rightinfo Consulting, Finnacle-Vesper Consulting, Pulse Wave Global, Catalyst Global Solutions, GeoIndopacific, SafeSec Group, and the Gulf Peace Foundation all advertised generic "consulting" and "analyst" roles aimed at current and former U.S. government and military employees.

The sites used a mixture of aliases, stolen identities, and AI-generated photographs to appear legitimate, the FBI told the court. The fake Horizzen site was registered in India; other domains in the network were traced to Pakistan and Thailand, despite all of them posing as Western-based firms. Operators used cryptocurrency and online payment systems to obscure their identities.

The recruitment itself follows a patient, staged funnel rather than an immediate ask for secrets:

> Fake job ads are posted on legitimate platforms, and applicants' CVs are ranked by their likely access to sensitive information.

> Concealed-identity virtual interviews probe candidates about government contacts and areas of access.

> Recruits are asked to write paid "trial reports" on topics such as China's international relations or defense — initially open-source work, paid at up to a thousand dollars per report.

> The conversation migrates to encrypted apps like Telegram, the requests grow more sensitive, and the payments grow larger.

The fake Horizzen operation even told recruits they would "establish a formal relationship" with another firm in the network, Catalyst Global Solutions and in doing so layering one front company in front of another to build credibility.

"The fake consulting company domains seized by the FBI illustrate the lengths the Chinese government's intelligence services will go to as they try to use AI-generated content to trick, recruit, or coerce current and former U.S. security clearance holders into sharing sensitive information," said Roman Rozhavsky, assistant director of the FBI's Counterintelligence and Espionage Division.

## The operations are ongoing

The campaign has repeatedly surfaced at moments of maximum vulnerability in the U.S. workforce. Reuters reported in March 2025 that a similar network of fake consulting firms was attempting to enlist federal employees who had just been fired in the Trump administration's government downsizing. The FBI, the National Counterintelligence and Security Center, and the Defense Counterintelligence and Security Agency issued joint guidance on deceptive online recruitment in April 2025, more than a year before the more recent Five Eyes bulletin. 

British authorities, meanwhile, had been tracking pieces of this network for months before the public warning. Security Minister Dan Jarvis said in November 2025 that MI5 had [identified](https://www.bbc.com/news/articles/cq6peqrnzpro?ref=cybrsecmedia.com) two LinkedIn profiles operating on behalf of China's Ministry of State Security. "This is when this issue came to the forefront," says James Turgal, VP of cyber risk and board relations at cybersecurity consultancy Optib.

The takedown hasn't removed the threat. A July 2026 analysis by the Foundation for Defense of Democracies found that suspicious new consulting sites, including ieass.com, easi-policy.com, and sgas-strategy.com, registered in 2026 exhibit profiles and behaviors similar to the seized network while sharing nearly identical infrastructure and registration patterns with one another, concluding that Beijing is "likely continuing the tactic unabated." The FBI itself has not [confirmed](https://www.yahoo.com/news/politics/articles/fbi-warns-chinese-spies-using-134500555.html?guccounter=1&ref=cybrsecmedia.com) whether the broader recruitment scheme has stopped, and is soliciting tips on additional sites.

The consultancy-recruitment model also sits alongside a separate, technically distinct Chinese [campaign](https://www.securityweek.com/chinese-hackers-target-energy-firms-south-china-sea/?ref=cybrsecmedia.com): the MSS-linked group TA423 (also tracked as Red Ladon and APT40) ran fake Australian news websites in 2022 to silently plant the ScanBox keylogger on the browsers of Australian government, energy, and defense-adjacent workers. Different operators, different techniques but the same logic of exploiting trust in familiar-looking websites to reach people with access.

China [denied](https://apnews.com/article/fbi-china-espionage-justice-department-dfc7b1c5b1eb2b2f55e1a497117b363b?ref=cybrsecmedia.com) the allegations. A spokesperson for the Chinese embassy in Washington called the espionage claims "entirely fabricated" and "malicious slander."

## What security pros should look for

  
Cybersecurity professionals in targeted industries need to stay cautious. "For U.S. professionals, the tell is often not how the relationship starts, but how it evolves, from flattery and harmless analysis to requests for nonpublic details, insider sourcing, discretion, and concealed payments," explains Turgal. "In these scenarios, the approach is unsolicited and unusually flattering, applauding and emphasizing government service, clearance history, military experience, research access, or particular education or skills," he says. 

 "The assignment is vague, unusually lucrative, urgent, or presented as confidential without a convincing business reason," he says. "The early assignments seem harmless, asking for public-source summaries or white papers. However, over time, the requests shift toward nonpublic procedures, internal assessments, names of knowledgeable colleagues, unpublished research, controlled technology, or "what insiders really think," Turgal continues. 

"Another red flag from the employee perspective is requests to approach former coworkers and the communication channels are asked to be moved to encrypted or personal channels; meetings are proposed overseas; the client's identity remains hidden; or payment comes from unrelated people, foreign accounts, shell entities, cash, or cryptocurrency," he says.

 Drawing on the NCSC-FBI-DCSA [guidance](https://archive.dni.gov/files/NCSC/documents/products/2025-04-08-NCSC-FBI-DCSA-OnlineTargetingUSGEmployees.pdf?ref=cybrsecmedia.com) and the Five Eyes bulletin, the red flags follow a recognizable pattern:

> Pay that doesn't match the work. High compensation for vague "research" or "analyst" tasks with minimal hours or effort required.

> Flattery with a targeting signature. Recruiters who overpraise a target as a "top candidate" and explicitly reference a clearance or government background — a level of emphasis legitimate recruiters rarely use. Treat any unsolicited approach that seems peculiarly well-matched to a specific background with skepticism.

> A fast move to encrypted channels. Pressure to shift the conversation from the job platform to Telegram, Signal, or WhatsApp early in the contact. 

> A company that doesn't check out. Newly registered domains, no verifiable leadership, no client history, and details that shift between the website and the recruiter's claims.

> Escalating assignments. Innocuous writing tasks that gradually morph into requests for non-public, proprietary, or sensitive information framed as "research reports.”

> Synthetic faces. Recruiter profile photos that fail a reverse image search: a quick check that frequently exposes AI-generated or stolen identities.

> Odd payment rails. Cryptocurrency or peer-to-peer transfers instead of standard payroll.

> Compressed timelines. A hire-to-payment cycle measured in weeks, not the months a genuine consulting engagement takes.

"In my experience, spotting these wolf-in-sheep's-clothing consultancies means looking past the digital paint job. A genuine opportunity never demands unvetted technical bake-offs under the table," says Rafay Baloch, CEO and founder of REDSECLABS. "I advise professionals to trust their spider-sense; if a recruiter rushes you to an encrypted app or asks about your network before your skills, that is a trap," he says.

The authorities are clear about what to do if the checkboxes above get checked: disengage, don't interact further, and report the contact — to a security officer where one is available, and to the FBI at [tips.fbi.gov](https://tips.fbi.gov/?ref=cybrsecmedia.com) or 1-800-CALL-FBI. Current federal employees should route any outside consulting offer through their agency's review process before accepting anything.

[ ![HOU.SEC.CON CTA](https://s3.us-east-1.amazonaws.com/assets.cybersecmedia.com/HSC+CTA.jpg) ](https://houstonseccon.com/?ref=cybrsecmedia.com)