LIVE · cybersecurity feed
Live wire
security

Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5

If you've ever received an out-of-the-blue message via LinkedIn from a recruiter offering some well-paid consultancy work, intelligence agencies have a message for you: be very careful. Read more in my article on the Hot for Security blog.

zeroday.news · 57d ago

Intelligence agencies from five allied nations are warning professionals to be wary of unsolicited messages on platforms like LinkedIn, as Chinese military intelligence is reportedly using these channels to recruit individuals for information gathering. The FBI, MI5, and their counterparts in Australia, Canada, and New Zealand have issued a joint advisory detailing a sophisticated operation where Chinese intelligence officers, or those acting on their behalf, pose as recruiters for legitimate-sounding private consultancies.

These deceptive "cover companies" often claim to be based outside of China to enhance their credibility. The primary targets are individuals whose careers have involved government, defense, or foreign policy sectors. The recruitment process begins with job advertisements placed on professional networking and job search sites, including LinkedIn, Indeed, and Upwork. Resumes are then evaluated based on the applicant's potential access to sensitive information.

Following an initial screening, candidates undergo online interviews where the recruiters conceal their true identities and inquire about the applicant's government contacts. For those with military backgrounds, questions may delve into their roles, unit activities, home bases, or even details about naval vessels they serve on.

Successful candidates are then tasked with completing a trial report on seemingly innocuous topics such as China's bilateral relations, regional defense issues, or international trade. Once a working relationship is established, the recruiters inform the recruits that more sensitive materials will be required for future assignments, and the communication typically shifts to encrypted messaging applications.

Payments for these reports can range from several hundred to thousands of dollars, with transactions facilitated through various online payment platforms and cryptocurrency. The agencies emphasize that targets do not necessarily need to possess security clearances to be valuable to Chinese intelligence. Even unclassified information concerning government policy, military strategy, or capabilities can be pieced together with more sensitive data to create a "comprehensive operational picture."

Academics, journalists, freelance writers, and employees of think tanks are identified as potential targets. The advisory also highlights that simply submitting a CV containing employment history, specialized knowledge, and professional contacts can hold intelligence value, even if the applicant does not proceed further in the recruitment process.

The Five Eyes agencies have reportedly identified individuals who have engaged in such activities for China, and these individuals may face consequences including criminal prosecution, job loss, and the revocation of security clearances. Professionals are advised to approach unsolicited job offers with skepticism, especially if the opportunity seems unusually tailored to their background or if the communication quickly moves to encrypted platforms. China has denied the allegations, labeling them as fabricated and malicious slander, and has instead accused the Five Eyes nations of posing a threat to international stability.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.