FBI Dismantles 13 Sites Tied to Chinese Influence Operation Targeting Cleared US Personnel

The seized domains posed as consulting firms advertising jobs, a tradecraft pattern consistent with state-directed recruitment campaigns against intelligence community insiders.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 2 min read
FBI Dismantles 13 Sites Tied to Chinese Influence Operation Targeting Cleared US Personnel
Share

Key points

  • The FBI seized 13 websites posing as consulting companies that advertised jobs to attract current and former holders of U.S. Security clearances.
  • The tradecraft mirrors documented foreign recruitment patterns: fictitious firm, plausible listings, low-friction initial contact.
  • Attribution to a specific Chinese intelligence unit remains harder than attributing malware campaigns.
  • At medium confidence, the targeting profile points toward Ministry of State Security tasking rather than military intelligence units.
  • Domain infrastructure is cheap to replace; the durable outcome depends on whether prosecutions follow.

What did the FBI actually seize?

Thirteen websites, each posing as a consulting firm with job openings calibrated to attract precisely the professionals a foreign intelligence service would want: people with access, or recently lapsed access, to classified U.S. National security information. Building fake storefronts credible enough to draw in cleared professionals takes time and operational discipline. Thirteen domains running simultaneously suggests a coordinated, resource-backed effort, not a one-off probe.

Is this a new playbook?

No. The pattern is familiar to anyone tracking foreign recruitment infrastructure. Three days before the Five Eyes issued a joint advisory on 5 June warning that Chinese intelligence officers were posing as recruiters to target personnel with access to classified material, we covered that campaign; this seizure looks like a parallel operational track. The tradecraft here overlaps with what multiple vendors track under the APT cluster associated with Chinese state intelligence tasking, though proving which directorate wrote the job posting is a different problem from attributing a malware campaign entirely.

At medium confidence: the targeting profile points toward Ministry of State Security tasking rather than military intelligence. That distinction matters for understanding what recruited assets were actually expected to deliver.

Will this stop the campaign?

Unlikely on its own. Operators can reconstitute under new registrars and hosting providers within days. The more durable outcome, if the investigation yields prosecutions, would be establishing legal precedent around foreign-directed cyber-enabled recruitment, a space where U.S. Law has historically struggled to keep pace with operational tempo.

Should security teams act now?

Yes. Employees hunting for work, particularly those recently separated from government roles, represent a persistent social engineering surface that most awareness programs underserve. Programs focused on phishing lures rarely address foreign recruitment approaches, and that gap is exactly what this infrastructure was built to exploit. Cleared contractor environments are the highest-priority place to close it.

© 2026 Threat Vectr