Five Eyes Warns: Chinese Intelligence Officers Posing as Recruiters to Harvest Government Secrets

A joint advisory flags a persistent social engineering campaign targeting personnel with access to classified material — fake job offers, real espionage.

ThreatVectr Newsdesk· 2 min read
Five Eyes Warns: Chinese Intelligence Officers Posing as Recruiters to Harvest Government Secrets
Share

Chinese intelligence officers are running a coordinated recruitment-lure operation against government and military personnel across Five Eyes member nations. The method is familiar. The scale, apparently, is not.

The joint advisory — issued by intelligence and security agencies spanning the US, UK, Canada, Australia, and New Zealand — describes officers posing as headhunters on professional networking platforms and job boards. Targets hold, or recently held, access to classified or otherwise privileged information. The goal is classic collection: cultivate a source, extract what they know.

This TTPs pattern overlaps with activity attributed at medium confidence to multiple Chinese state-affiliated clusters. Mandiant tracks some of this tradecraft under APT10 and related subgroups; SentinelOne's naming convention maps adjacent activity to different designations. The advisory itself stops short of naming a specific cluster — a deliberate choice that reflects the difficulty of distinguishing MSS-directed operations from PLA Unit campaigns when initial-access tradecraft is this generic.

What the advisory does make clear: capability and intent are both present. These are not phishing amateurs. Officers are building persona depth — professional histories, mutual connections, credible-sounding roles at real or plausible firms. That kind of sustained persona investment suggests organized direction, not opportunistic freelancing.

The social engineering lifecycle here typically runs through four stages: initial contact under cover of a legitimate-seeming opportunity, rapport-building over weeks or months, an elicitation phase disguised as interview prep or consulting work, and eventual requests for information the target should never hand over. Personnel who've recently separated from service or government roles are a particular focus. They still carry knowledge; they may feel undervalued; they're no longer inside security-awareness programs.

Defenders should note the pre-access nature of the threat. There's no CVE here, no patch to deploy. The vector is human. Countering it requires personnel training programs that treat unsolicited recruiter contact — especially from accounts with thin histories or implausible reach — as a reportable event, not an ego boost.

Five Eyes hasn't released the full indicator set publicly, but the advisory urges personnel to verify recruiter identities through independent channels before engaging, and to report suspicious outreach to relevant national security contacts.

© 2026 Threat Vectr