FBI Dismantles 13 Sites Tied to Chinese Influence Operation Targeting Cleared US Personnel
The seized domains posed as consulting firms advertising jobs — a tradecraft pattern consistent with state-directed recruitment campaigns against intelligence community insiders.

The FBI has seized 13 websites the U.S. government says Beijing used to identify, approach, and recruit current and former holders of American security clearances. The sites posed as consulting companies, each advertising positions tailored to attract precisely the kind of targets a foreign intelligence service would want: people with access, or recently lapsed access, to sensitive national security information.
This is patient work. Building fake storefronts that look credible enough to draw in cleared professionals takes time and operational discipline.
The tradecraft here overlaps with what multiple vendors track under the broader APT cluster associated with Chinese state intelligence tasking — though attribution of influence and recruitment infrastructure to a specific unit remains harder than attributing malware campaigns. Capability is one thing. Proving which directorate wrote the job posting is another.
Recruitment-front operations targeting cleared personnel aren't novel. The pattern — fictitious consultancy, plausible job listings, low-friction initial contact — mirrors methods analysts have documented for years across Chinese, Russian, and North Korean intelligence programs. What makes the current seizure notable is scale. Thirteen domains operating simultaneously suggests a coordinated, resource-backed effort, not a one-off probe.
The FBI's action is disruptive but not necessarily decisive. Domain infrastructure is cheap to replace. Operators can reconstitute under new registrars and hosting providers within days. The more durable outcome, if the investigation yields prosecutions, would be establishing legal precedent around foreign-directed cyber-enabled recruitment — a space where U.S. law has historically struggled to keep pace with operational tempo.
At medium confidence: the targeting profile — clearance holders, intelligence adjacent — points toward collection priorities consistent with Ministry of State Security tasking rather than military intelligence units. That distinction matters for understanding what the adversary actually wanted out of recruited assets.
For security teams supporting government contractors or cleared facilities, the immediate takeaway is straightforward. Employees hunting for work — particularly those recently separated from government roles — represent a persistent social engineering surface. Awareness programs that address foreign recruitment approaches, not just phishing lures, remain underinvested across the cleared contractor ecosystem.



