On June 3, in a rare – and telling – indication of collective alarm, the member states of the “Five Eyes” intelligence-sharing alliance published an unprecedented joint bulletin highlighting China’s use of professional networking sites like LinkedIn to carry out an aggressive, industrial-scale online espionage campaign. Armed with the personal data of millions of U.S. security clearance holders and applicants, acquired during China’s 2014-15 hack of the Office of Personnel Management (OPM), spies from the Chinese Ministry of State Security (MSS) have approached tens of thousands of U.S. and NATO government staffers, military personnel, academics, and others with access to sensitive information through LinkedIn and other professional networking sites over recent years.
The massive scale of China’s spy campaign does not preclude precision: MSS agents use generative AI to craft messages tailored to each individual target’s resume and expertise. Posing as corporate recruiters or business consultants, agents promise their targets easy money in exchange for writing freelance “consulting” reports on seemingly innocuous topics related to their targets’ work. These fictitious identities are often bolstered with AI-generated profile pictures and fake corporate websites. Once the agent has established a relationship with their target, they’ll push the target to divulge more sensitive information or even pass classified documents directly to the agent.
The environment is target-rich. LinkedIn is widely used by current and former U.S. government employees. Spies on the prowl can easily browse lists of users with specific career experience to quickly build a list of viable targets. This makes online espionage recruitment especially appealing to China’s intelligence apparatus, and the extensive use of fake company webpages and AI-generated messages means that targets often don’t initially realize they’re being deftly cultivated by a foreign spy agency.
Although less bombastic than China’s efforts to hack American critical infrastructure or cultivate U.S. politicians as agents of influence, China’s networking site espionage has proven particularly long-running and pernicious. Reports of Chinese intelligence operations using LinkedIn to recruit informants go back to at least 2011. In 2018, then-head of the U.S. National Counterintelligence and Security Center William Evanina publicly called on LinkedIn to address the issue. LinkedIn responded by “restricting” a few dozen fake accounts, but the problem continued. Evanina told the New York Times a year later that China’s espionage activity on the platform had not decreased. Despite periodic media attention and U.S. counterintelligence efforts over the past 15 years, China’s intelligence apparatus has continued to run aggressive online spying campaigns on an industrial scale, obtaining technological, military, and economic secrets through these efforts.
China’s online espionage recruitment poses an urgent threat to the U.S. and allied governments, but solutions for detecting and preventing it have remained frustratingly elusive. Fortunately, there exists a wealth of research and real-world models for cooperation between governments and industry to address a similar threat: transnational online fraud and scam rings. Government and industry stakeholders should draw on this existing body of expertise and best practices and adopt a novel approach to combating China’s network espionage.
China’s online espionage shares some key characteristics with transnational online fraud. Both Chinese espionage recruitment and online romance scams, such as the “pig butchering” operations that earn billions of dollars each year for cybercriminals operating internet scam compounds in Southeast Asia, use deceptive, flattering initial approaches to their target. These initial messages are often written and translated with the aid of generative AI and tailored to fit the target’s profile. MSS spy handlers and online scammers also seek to cultivate a relationship and build trust with their targets before eventually pressuring them to disclose sensitive information, such as military secrets or personal financial details.
Finally, both transnational fraud schemes and China’s online espionage recruitment originate from overseas but use U.S. and partner nation platforms and internet infrastructure to contact their targets. This leaves scammers and spies similarly vulnerable to disruption efforts by law enforcement and counterintelligence authorities in the US and partner nations.
One recent example is “Disruption Week,” organized by the U.S. Department of Justice’s “Scam Center Strike Force.” From May 18 to 21, U.S. law enforcement bodies met and shared information with major private sector firms like Apple, Meta, and Microsoft to identify and shut down fraud activity on over 1.4 million scam-linked social media and email accounts, as well as decommissioning servers, hosting infrastructure, and platforms linked to scam networks operating from Southeast Asia. Law enforcement agencies also identified and opened new investigations into overseas scammers and arrested several suspected cybercriminals with the cooperation of partner nations.
On June 10, the FBI seized 13 web domains used by Chinese intelligence agents to lure targets on LinkedIn and other networking sites. The domains hosted webpages for fake consultancies – fronts for MSS spies posing as recruiters online. The deception paid off. FBI documents show that China’s spies used the fake consulting firms to recruit at least eight current and former U.S. government and military personnel with security clearances.
While U.S. counterintelligence officials’ work in disrupting part of China’s illicit digital intelligence infrastructure is praiseworthy, 13 domains represents a mere drop in the bucket of China’s extensive online espionage. Researchers at the Foundation for the Defense of Democracies (FDD) have already identified over 100 web domains and fake firms likely serving as fronts for Chinese espionage recruitment – none of which were seized during the FBI’s June operation.
One of these fake firms, “Nimbus Hub Consulting,” was also independently identified as a front for Chinese espionage by publicly-available industry and media reports. The U.S. government, think tanks, and industry should establish information-sharing channels to allow law enforcement agencies and professional networking sites like LinkedIn to cross-reference suspicious firms with a list of known front companies and flag or delete profiles linked to these fronts. Authorities should be catching these fraudulent sites as they are identified, not playing catch-up with siloed and incomplete data.
On the industry side, professional networking and job site operators can draw on recent advances in scam detection and prevention to combat Chinese espionage on their platforms. Online scammers often create and follow AI-generated scripts that function as templates for enticing and exploiting victims, even across language barriers. These scripts allow the scammers to automate and expand the scope of their operations, targeting victims en masse. China’s cyber spies use similar techniques to quickly generate personalized messages, allowing them to approach thousands of targets with minimal time and effort.
But AI cuts both ways for scammers: recent anti-scam research has demonstrated that AI models can effectively identify scam messages. Google has already developed tools to detect and flag likely scams in real time on its Android devices, and this technology could be easily adapted to detect likely Chinese espionage recruitment approaches, which make similar use of AI models to generate and customize approach messages for each target. LinkedIn and other professional networking platforms should implement a similar feature in their chat functions to detect likely espionage attempts and warn users in real time.
The U.S. government shouldn’t be shy about pressing LinkedIn to take this much-needed step to address rampant espionage recruiting on the platform. The Department of Defense’s Transition Assistance Program (TAP) explicitly encourages servicemembers to use LinkedIn to search for their next role, and the platform’s well-established ecosystem of professionals and employers has attracted a significant community of current and former U.S. government employees and clearance holders. All fo this makes it a particularly appealing target for Chinese intelligence. If the platform’s operators drag their feet on improving security and addressing rampant abuse by China’s spy agencies, authorities could strip it from federal programs like DOD’s TAP. Legislators could even move to treat the platform similarly to pre-divestiture TikTok or WhatsApp, banning its use on government-issued devices. It would also behoove the House Select Committee on the CCP to use its subpoena power to call recalcitrant platform operators to account. After all, MSS spies targeted the Committee itself in December 2025, using a fake consulting firm (complete with a falsified LinkedIn presence) in an attempt to solicit sensitive information from a Committee staffer.
A hardball approach would create predictable headaches for both parties, though, and a more cooperative arrangement based on establishing information-sharing channels, clear efforts towards identifying and banning spies from the platform, and improved safeguards against espionage recruitment in LinkedIn’s chat client would be preferable.
While detection and disruption are the most immediate concerns for authorities and platform operators, the ease with which Chinese intelligence agents can create new front companies and fake identities means that preparing platform users to protect themselves is also crucial. Preventative measures warning potential targets and equipping them to recognize the signs of espionage recruitment attempts are urgently needed.
Much like China’s AI-enabled online espionage recruitment, phishing and other traditional cybersecurity threats use social engineering techniques to manipulate targets into engaging with malicious messages. An extensive body of scholarship, including anti-fraud research sponsored by the Federal Trade Commission, has explored the effectiveness of anti-phishing cybersecurity education and has identified some best practices for helping internet users protect themselves from malicious actors.
One surprising and relevant finding from this research concerns the effectiveness of regular cybersecurity trainings. Multiple large-scale studies concluded that formal cybersecurity trainings are largely ineffective in preventing users from engaging with phishing messages, indicating that oft-repeated calls for more or intensified counterespionage training sessions for U.S. government and military personnel, while well-intentioned, are unlikely to be effective.
Researchers studying anti-phishing training found that simple reminders about cyber threats are likely to provide an equivalent benefit to detailed cybersecurity trainings, while being much less costly and time-consuming. With this in mind, LinkedIn and other professional networking sites should implement occasional short, attention-grabbing, and user-friendly reminders about espionage recruitment threats to warn users while avoiding desensitizing them through the overuse of warning messages.
Fortunately, more robust preventative measures are available to platform operators: anti-phishing research has identified prominent warnings that flag probable scam messages within email clients as an effective tool for alerting users to malicious activity. LinkedIn and other professional networking sites should implement highly-visible warnings embedded within their chat functions to warn users about likely espionage recruitment attempts. LinkedIn has already introduced an optional feature designed to detect and flag malware and harassment in chat messages; adding espionage recruitment to the list of threats is an obvious next step. TAP and programs like it should also highlight and explain this feature to DOD and other federal personnel when discussing LinkedIn use.
Research on phishing prevention also found that simple, user-friendly reporting functions to flag phishing attempts can help organizations rapidly identify and disrupt likely phishing campaigns without putting significant strain on the organization’s operational load. LinkedIn should implement a user-friendly reporting feature directly into the chat function to enable users to quickly and easily report likely espionage recruitment attempts. This feature could also support information-sharing and collaboration between LinkedIn and law enforcement agencies, allowing for faster and easier cross-referencing and identification of likely Chinese intelligence agents and front companies.
Chinese espionage recruitment may be occurring on an unprecedented scale, but the U.S. is far from powerless to stop it. Easy wins are readily available in the form of research-backed measures for dramatically reducing the effectiveness of Chinese intelligence activities online. LinkedIn announced in March that it had joined (alongside Meta, OpenAI, and other major tech firms) an industry accord dedicated to combating online scams and fraud. Signatories promised to increase their cooperation with law enforcement and government bodies, develop scam detection tools that utilize advanced AI, and create user-friendly reporting channels to flag likely scams. Meta has also publicly discussed its cooperation with OpenAI to crack down on online transnational scam and fraud activity operating across their respective platforms. Taking advantage of these tools, techniques, and channels to address China’s online espionage operations is a clear next step for policymakers, law enforcement authorities, and professional networking platforms.

