TL;DR: On June 3 and 4, 2026, all five members of the Five Eyes intelligence alliance (the FBI, Britain's MI5, Australia's ASIS, Canada's CSIS, and New Zealand's NZSIS) issued an unprecedented joint warning. Chinese military intelligence is running an industrial-scale recruitment operation on LinkedIn, Indeed, Upwork, and Craigslist. Operatives pose as headhunters and post fake defense analyst jobs, then escalate targets through interviews, "trial reports" on sensitive topics, and payments via PayPal, Zelle, and cryptocurrency. If you hold a security clearance or work anywhere near government policy, that flattering connection request might be a recruitment pitch from Beijing.

Five Agencies, One Message: Check Your Inbox

The Five Eyes alliance almost never speaks with one voice in public. That changed this week.

On June 3, the FBI and its counterparts in the UK, Australia, Canada, and New Zealand published a joint advisory warning that China's military intelligence services are running a coordinated recruitment campaign across professional networking platforms. MI5 followed up on June 4 with a detailed PDF breaking down the tradecraft.[1][2]

The statement didn't mince words: "China's military intelligence services ultimately seek to acquire privileged military, political and economic intelligence that can provide China with a strategic and tactical advantage."[3]

This isn't theoretical. It's happening at scale, right now, on the same platforms where you update your résumé and respond to recruiters.

The Playbook: From Connection Request to Espionage

Forget the Cold War image of a trench-coated figure passing envelopes in a parking garage. Modern spy recruitment looks like a LinkedIn message from a consulting firm you've never heard of.

MI5's advisory lays out the stages:[2]

  1. The job posting. Intelligence officers or their proxies pose as employees of private consultancies, think tanks, or HR firms. They post job ads targeting foreign policy analysts, defense researchers, and security specialists on LinkedIn, Indeed, Upwork, and Craigslist.
  2. The screening. Applicants get ranked, not by qualifications but by how likely they are to have access to classified or sensitive information. Government clearance holders go straight to the top of the pile.
  3. The interview. Candidates are invited to virtual interviews where the questions steer toward their government contacts, military base knowledge, and job responsibilities. It feels like a normal screening call. It isn't.
  4. The trial report. Here's where it crosses the line. Recruits are asked to write a "trial report" on a China-related topic: foreign policy analysis, defense assessments, military capabilities. It looks like a work sample. It's actually intelligence collection.
  5. The pivot. Conversations move to encrypted messaging apps. Payment offers come through PayPal, Zelle, Wise, Western Union, or cryptocurrency. The requests get more specific. The money gets bigger. By this point, you're an asset.

The brilliance, if you can call it that, is that every step feels normal until it doesn't. Job postings, interviews, work samples, payment. It's the exact same pipeline any legitimate consulting firm uses. That's the point.

Who's in the Crosshairs

The target list is broader than you'd expect. The advisory names:[1][2]

  • Security clearance holders (any level)
  • Defense and military personnel
  • Foreign affairs and policy professionals
  • Academics researching China, defense, or international relations
  • Think tank employees
  • Journalists covering national security
  • Anyone with access to government systems or privileged information

That last category is doing a lot of work. It doesn't just mean people with "TOP SECRET" on their badge. It means contractors, IT admins, research assistants: anyone whose day-to-day puts them near sensitive information, even tangentially.

The timing matters too. February 2025's wave of federal layoffs flooded the job market with cleared professionals who are suddenly out of work and actively looking. People under financial stress, scrolling job boards, responding to recruiter messages. Chinese intelligence noticed.[2]

This Has Worked Before

This isn't a warning about something that might happen. It's a warning about something that already has, repeatedly.

Kevin Mallory. In early 2017, a former CIA officer $230,000 in debt received a LinkedIn message from a Chinese headhunter. The "headhunter" was a Ministry of State Security operative who arranged a call, pretended to represent the Shanghai Academy of Social Sciences, and recruited Mallory to provide classified information. He was arrested in June 2017 and convicted under the Espionage Act in 2018. He's serving 20 years.[4]

Dickson Yeo. A Singaporean national who pled guilty in July 2020 to acting as an illegal agent of Chinese intelligence. Yeo used LinkedIn to identify and approach US government employees and military officers. He set up a fake consulting company as cover and used it to solicit reports containing classified and sensitive information. He got 14 months.[5]

These aren't outliers. In 2021, MI5 reported that approximately 10,000 Britons had been targeted on LinkedIn over the previous five years, and called that estimate "conservative."[2]

Why LinkedIn Is Perfect for Spies

Think about what you voluntarily publish on LinkedIn: your employer, your clearance level ("seeking TS/SCI opportunities"), your government contracts, your military unit, your research focus. You tag colleagues, endorse skills, and join groups like "Defense Intelligence Professionals" or "IC Alumni Network."

You've built a detailed intelligence profile of yourself. And you did it for free.

LinkedIn also normalizes cold outreach. Getting a message from a stranger offering consulting work isn't suspicious; it's Tuesday. The platform's entire business model is built on connecting strangers. Chinese intelligence just plugged into that system.

Microsoft, which owns LinkedIn, hasn't commented on the Five Eyes advisory. The platform has previously said it works with law enforcement and removes fake accounts, but the sheer volume of the problem (10,000 known targets in Britain alone) suggests that whatever they're doing isn't enough.

How to Spot a Spy on LinkedIn

Check the Company

Search for the consulting firm or think tank independently. Fake fronts typically have minimal web presence, no real employees on LinkedIn besides your contact, and vague descriptions of their work. If the company website was registered three months ago, that's a red flag.

Watch for the Escalation

Legitimate recruiters don't ask about your security clearance in the first conversation or request you write analysis on foreign military capabilities as a "work sample." If the questions shift from your qualifications to your access, stop responding.

Be Suspicious of Unusual Payment

Real consulting firms pay through invoices and bank transfers, not Zelle, PayPal personal payments, Wise, or crypto. If someone offers to pay you through any of these for analytical work, report it immediately.

Report It

If you suspect a recruitment approach, contact the FBI's field office or your agency's counterintelligence unit. In the UK, report to MI5. In Australia, ASIO. In Canada, CSIS. In New Zealand, NZSIS. These agencies want to hear from you; that's the whole point of the advisory.

Clean Up Your LinkedIn Profile

You don't have to delete your account. But if you work anywhere near government or defense, tighten your profile today:

  • Remove clearance references. Phrases like "active TS/SCI" or "cleared for SAP" are recruitment magnets. Your cleared status should be in your résumé, not on a public profile.
  • Limit job details. "Program analyst at a federal agency" is enough. "Lead analyst for [specific classified program] at [specific three-letter agency]" is a gift to foreign intelligence.
  • Audit your connections. That recruiter from a think tank you've never heard of who connected two years ago? Look at their profile again. Check their other connections. If they're all government workers, that's not a coincidence.
  • Turn off public visibility. LinkedIn lets you hide your profile from non-logged-in users and control who can see your connections list. Settings → Visibility → Edit your public profile. Do it now.
  • Don't list skills you shouldn't advertise. "Chinese language analysis," "SIGINT," "counterproliferation": these are skills that attract the exact wrong kind of attention.

The Bigger Picture: Espionage Goes Remote

Spy recruitment used to require geography. You needed a handler in the same city, a dead drop within driving distance, a diplomatic cocktail party to make first contact. That limited the scale.

LinkedIn removed the geography problem. A single intelligence officer in Shanghai can simultaneously run recruitment operations against targets in Washington, London, Canberra, Ottawa, and Wellington. The Five Eyes advisory explicitly acknowledges this: the platforms give Chinese intelligence reach they never had before.[1]

It also lowered the bar for who gets targeted. When you had to physically approach someone, you focused on high-value targets: senior officials with direct access to critical intelligence. Online, the marginal cost of sending another connection request is zero. So the net gets wider. Junior analysts, recent graduates, contractors, academics: anyone who might have something useful becomes worth a try.

The joint nature of this warning is itself the message. Five Eyes doesn't issue joint public advisories for minor threats. The fact that five intelligence agencies in five countries decided this problem was serious enough to coordinate a public response tells you the scale is significant, and growing.

References

  1. Bloomberg: US, Five Eyes Warn of Chinese Spies Using LinkedIn for Recruitment
  2. The Register: Five Eyes: Watch out for odd LinkedIn connection requests, China's back on the hunt for state secrets
  3. SCMP: US and Five Eyes allies warn of LinkedIn China spying threat
  4. NBC News: How a $230,000 debt and a LinkedIn message led an ex-CIA officer to spy for China
  5. The Quint: How a Chinese Agent Weaponised LinkedIn to Steal Sensitive US Information