Skip to content
The ColumnEditorial· No. 2009

EDITORIAL: LinkedIn as a battlefield — China is recruiting spies from your network, right now

What strikes me about this operation is its brutal elegance. No complex hacking. No high-risk undercover agent. Just a job posting on a platform you open in the morning with your coffee. China has und

Premium reading
MadMax
Key takeaways
  1. What strikes me about this operation is its brutal elegance. No complex hacking. No high-risk undercover agent. Just a job posting on a platform you open in the morning with your coffee. China has und
  2. Introduction: when the professional network becomes a spy trap
  3. June 5, 2026: an unprecedented warning
Transparency

Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.

Introduction: when the professional network becomes a spy trap

June 5, 2026: an unprecedented warning

On June 5, 2026, the five intelligence agencies that form the Five Eyes alliance — the American FBI, the British MI5, the Australian ASIO, the Canadian CSIS, and New Zealand's service — simultaneously published, in identical terms, a warning that several analysts described as "unprecedented." China, according to those five services, is using LinkedIn, Indeed, and other online employment platforms to recruit spies among government, military, academic, and journalism personnel in member countries of the alliance. The title of the joint bulletin: "Safeguarding Our Secrets."

What makes that warning remarkable is not only its content — LinkedIn's use by Chinese intelligence services has been documented since at least 2018, when U.S. counterintelligence chief William Evanina described an "extremely aggressive" campaign. What is remarkable is the simultaneity and coordination: five countries, one date, the same words. That type of coordinated action had never previously occurred on that specific subject. When the Five Eyes speak together, it is because the problem has outgrown what any single agency can manage through quiet diplomacy.

What this bulletin says that you need to read

The Five Eyes bulletin describes a five-step method, clear and ruthlessly simple. Agents of Chinese military intelligence — identified as operating under the Ministry of State Security — pose as recruiters from consulting or human resources firms based outside China. They post fake job listings targeting analysts specializing in diplomacy, defense, and Indo-Pacific security. They ask applicants for "preliminary reports" on subjects such as relations with China or regional security issues. They escalate requests toward increasingly sensitive information. And they pay — sometimes tens of thousands of dollars per report, via PayPal, Wise, or third-party payment applications.

How the operation works: five steps toward betrayal

From fictional recruiter to classified report

The mechanics described by the Five Eyes follow a predictable but effective arc. The operator creates a convincing profile on LinkedIn or Indeed — often under the name of an apparently legitimate consulting firm based in Hong Kong, Singapore, or Europe. The operator identifies candidates whose profile indicates potential access to sensitive information: former military personnel, recently retired civil servants, defense-specialized academics, journalists covering geopolitical issues, think tank researchers. The initial contact is professional, polite, lucrative. The offer is too good to ignore.

The interview — conducted online, with an operator concealing their real identity — begins with general questions about the candidate's background. Military personnel may be asked about past positions. Academics, about their publications and network. Then comes the preliminary report request. On foreign policy. On U.S.-China relations. On security in the Indo-Pacific. "It is standard analytical writing," the fictional recruiter explains. "Our clients are investors, market analysts. Nothing confidential." Payment arrives promptly, via PayPal or Wise, from an account never directly linked to China.

The escalation toward classified information

It is at the second or third assignment that the trap closes. Requests become more specific. Clients "need details on the defense capabilities of a given country." On "the government's real positions in undisclosed negotiations." On "the sources and methods" the candidate may have encountered during their career. At that point, communications shift to encrypted messaging apps — Signal, Telegram, or lesser-known applications recommended by the recruiter. The candidate is now deeply committed: they have signed, taken money, provided information. Breaking away costs more than continuing — or at least, that is what the operator wants them to believe.

MI5 had identified two fictional recruiters in 2025: Amanda Qiu, fictional CEO of "BP-YR Executive Search" in Beijing, and Shirly Shen, of "Internship Union" in Hong Kong. Those profiles had been used to approach British parliamentarians and their staff. Neither responded to verification messages sent by the New York Times in November 2025. They did not exist.

The targets: who Beijing has in its sights

At-risk profiles according to the Five Eyes

The Five Eyes bulletin is explicit about the profiles targeted: government and military personnel holding security clearances, academics and researchers whose work touches on defense or geopolitics, journalists covering China or the Indo-Pacific, think tank members whose analyses inform government decisions, and private sector professionals with connections to influential networks. The bulletin underscores a critical point: even a person with no direct access to classified information can be useful. Non-classified information on government policies or military capabilities can, when combined with other sources, constitute a detailed operational picture.

In 2023, MI5 Director General Ken McCallum declared that more than 20,000 people in the United Kingdom had been approached by Chinese agents via professional online networks — a figure he described at the time as "double" the previous detection count. That number covered only the United Kingdom. Across the Five Eyes, the total is potentially five times higher, and probably underestimated, since the vast majority of approaches are never reported.

The Kevin Mallory case: when the trap closes

The most frequently cited example in Western analyses on this subject is that of Kevin Mallory, a former American contractor convicted in 2018 for attempting to sell classified information to China after being approached on LinkedIn for a consulting offer. Mallory needed money. The offer seemed legitimate. He accepted. He is serving a prison sentence today. His case illustrates a well-identified vulnerability profile: people in career transition, recently laid off or in debt, are priority targets. The Chinese operation targets real needs — financial, professional, social recognition — to create an entry point.

The Foundation for Defense of Democracies identified in 2025 what it described as a probable Chinese intelligence operation specifically targeting American civil servants laid off by the Trump administration in the preceding months. Thousands of people with security clearances and recent access to sensitive information, suddenly unemployed, financially vulnerable. For an espionage operation, that is a target population of exceptional value.

The Five Eyes response: measures and their limits

What the agencies actually recommend

The Five Eyes bulletin does not merely describe the threat. It proposes practical countermeasures. Professionals in sensitive fields are urged to treat any unsolicited contact offering unusually high compensation or pressure toward encrypted messaging apps as a red flag to report to their security officer. Employers are encouraged to integrate social engineering scenarios involving professional networks into their security awareness training. Universities are encouraged to brief students in graduating strategic programs before they enter sensitive employment.

The United Kingdom went further: Security Minister Dan Jarvis announced an "action plan against political interference and espionage" including expanded security briefings for political parties, new guidelines for election candidates, and formal pressure on platforms like LinkedIn to identify and remove fraudulent recruiter accounts. The British government also allocated £170 million (approximately $230 million) to strengthen computer systems at Parliament and government networks.

What LinkedIn does — and what it cannot do

LinkedIn stated in a press release that identity fraud violates its terms of use and that the platform "remains focused on detecting state-sponsored abuse." But the practical reality is more complex: a platform with more than one billion users cannot manually verify the identity of every recruiter. Automated detection techniques struggle to distinguish a sophisticated fake profile from a legitimate one — especially when operators rely on covers using real or seemingly legitimate companies. MI5 identified specific fraudulent profiles and transmitted them to LinkedIn; the platform removed them. But operators create new profiles. It is a cat-and-mouse game whose outcome is uncertain.

China denies — but the evidence accumulates

Beijing's response: "malicious fabrications"

China's official reaction to the Five Eyes warning follows its standard denial model. The Chinese embassy in London described the allegations as "politically motivated." A Foreign Ministry spokesperson called the charges "pure fabrications and malicious slander." Beijing also claimed to be itself the target of foreign intelligence operations — which is probably true, without that fact invalidating the documented evidence of its own operations.

That systematic denial is itself information: it signals that Beijing sees no diplomatic cost in denying against documented evidence. That is an assessment of the balance of power. China judges — probably correctly, up to now — that the commercial, financial, and diplomatic damage its Western partners are prepared to inflict in response to espionage is insufficient to change its behavior. As long as that calculation does not change, the Five Eyes warnings, however well documented, will not alter Chinese strategy.

Convictions, firings, revoked clearances

Several individuals who cooperated with Chinese operators have already been identified and face criminal charges, dismissals, and security clearance revocations, according to the Five Eyes bulletin. Those cases are not named in the public document — for operational and legal reasons. But their existence is confirmed. What the bulletin does not say is the true scale of the problem: the number of currently undetected active operations, the volume of information already compromised, the government or military decisions potentially influenced by stolen data.

What this reveals about China's espionage strategy in the 21st century

Industrial espionage at an "industrial scale"

MI5 Director General Ken McCallum described Chinese espionage as operating at an "industrial scale." That is not rhetorical flourish. It is an operational description: thousands of simultaneous approaches on LinkedIn, hundreds of active operators, cover companies in dozens of countries, an industrialization of deception that no longer resembles the artisanal espionage of the Cold War. The FBI estimated as early as 2018 that 70% of Chinese espionage activity targeted the American private sector rather than the government — confirming that China's strategy extends well beyond military intelligence.

That strategy follows a coherent logic. China wants to acquire in a single generation what Western democracies developed over decades: technological advantages, industrial expertise, geostrategic positions. Espionage is faster and less costly than legitimate research and development. And in a digital world where millions of professionals expose their expertise on public networks, targets are infinitely more accessible than they have ever been.

The link to Taiwan, the Indo-Pacific, and war preparation

The themes of the reports requested from recruits — relations with China, security in the Indo-Pacific, military capabilities of American allies — are not random. They correspond to the most critical intelligence gaps for Chinese military planning in the context of a potential confrontation over Taiwan. Understanding the real positions of U.S. allies in the region, their red lines, their undisclosed commitments, their genuinely deployable capabilities — that is information of considerable strategic value for the People's Liberation Army.

That context makes the Five Eyes warning even more urgent. This is not merely a question of protecting commercial data or bureaucratic intelligence. It is potentially the collection of intelligence in preparation for a future conflict. Every report purchased on LinkedIn may be one piece of a puzzle far larger than the fictional recruiter reveals to their target.

What Western democracies must do — and have not yet done

Insufficient measures and blind spots

Despite repeated warnings since 2017 — German services detected thousands of Chinese approaches via LinkedIn that year — systemic countermeasures remain insufficient. Few companies have integrated social engineering scenarios via professional networks into their security training. Few universities explicitly brief their graduates on that risk before they enter sensitive sectors. And few governments have imposed real identity verification obligations on platforms for recruiters.

The Foundation for Defense of Democracies proposed a counterintuitive but potentially effective measure: creating "lure" accounts matching the profiles Chinese operators seek — former cleared civil servants, recently retired military — to attract operators off the platforms and identify them. That is reverse espionage. It is legal in some jurisdictions, problematic in others. And it requires resources that counterintelligence agencies do not prioritize for that tactic.

The structural response: what the Five Eyes report actually demands

The coordinated Five Eyes warning of June 5, 2026 signals that the five governments have decided to address this problem publicly — something they had never collectively done before. That is an escalation in diplomatic pressure on Beijing and an attempt to mobilize the public. But the structural response must go further: requiring digital platforms to apply enhanced verification obligations for accounts posting jobs in strategic sectors, coordinating databases of identified fictional operators across all five countries, and substantially raising the costs for China when operations are proven — not just press statements, but targeted economic sanctions and diplomatic expulsions.

What governments can learn from Ukraine to counter digital espionage

Ukraine's lessons on information warfare

Ukraine, which has been waging a total war against Russia since 2022 — including a war of information, intelligence, and cybersecurity — has developed defensive reflexes that Western democracies struggle to adopt in peacetime. Ukrainian services have identified and thwarted dozens of influence and recruitment operations organized from Moscow using the same social network and fake professional identity tactics. Ukrainian experience demonstrates that a national culture of vigilance — not just institutional structures — is indispensable to countering these threats.

What the Five Eyes are attempting with their June 5, 2026 bulletin is precisely that: creating collective awareness of the risk. Ukraine learned to identify warning signs because its very existence depended on it. Western democracies have not yet experienced that level of existential urgency — and that is partly why the repeated warnings about LinkedIn and the Chinese threat have not yet produced the systemic behavioral change they deserve.

Intelligence cooperation as a long-term response

The coordinated Five Eyes publication is itself a lesson about what multilateral intelligence cooperation can accomplish. The five agencies share information on identified operators, fictional profiles, and contact methods. That shared database — of which the public sees only the surface — makes it possible to identify patterns that no national agency could detect alone. That is the appropriate response architecture for a threat operating at global scale.

But cooperation has its limits: it remains confined to the Five Eyes. The European Union, whose members include major targets of Chinese espionage, is not in that direct loop. Countries like France, Germany, and the Netherlands have their own services, but systematic sharing of information on Chinese operations is less formalized than within the Five Eyes. Extending that cooperation — without compromising sources — is one of the most significant structural challenges of the decade ahead.

Conclusion: your LinkedIn profile may already be on a list

What you do tomorrow morning with this information

To anyone reading this editorial who works in a field related to defense, diplomacy, critical technologies, investigative journalism, or geopolitical research: your LinkedIn profile is visible. Your expertise is readable. Your network is mappable. And if you have ever worked in government, military, or academic roles touching on strategic issues, you fit exactly the profile that the operators identified by the Five Eyes are targeting. That is not paranoia. It is a factual reading of the June 5, 2026 bulletin.

The practical response is simple: be wary of unsolicited offers of value above what the market justifies, particularly those involving security or geopolitical subjects. Report to your security officer any contact that pressures you to move to a private messaging app. Verify the genuine existence of your recruiter's company before responding. And if you have doubts about a past contact, speak to your security service before speaking to anyone else. In 2026, the line between a professional opportunity and a spy trap runs through LinkedIn. And that line is far less visible than you might think.

What this moment reveals about the nature of the Chinese threat

China is not only an expanding military power, an economic rival, or a complex trading partner. It is, in this precise dimension, an espionage machine operating at a scale and with a sophistication that only a state decision can sustain. The Five Eyes warning is the public acknowledgment of what was known confidentially for years: the platforms that democracies built to connect professionals are now being used against them. And the response will not come from LinkedIn, not from companies, not from individuals alone — it must come from a collective political will to treat Chinese espionage with the gravity it deserves.

By Maxime Marquette, columnist

Columnist's transparency note

What I know and what I don't

This editorial is based on the joint Five Eyes bulletin of June 5, 2026 titled "Safeguarding Our Secrets," as reported and analyzed by several independent sources: Japan Forward (June 10, 2026), Bloomberg (June 3, 2026), Indoneo (June 5, 2026), ABC Australia (June 4, 2026), and the Wall Street Journal (June 4, 2026). The original text of the bulletin is public and cited by those sources. I do not have access to classified information on the active cases mentioned in the bulletin. The convictions and dismissals referenced are those publicly confirmed by the agencies.

My editorial position

I believe China represents the most serious long-term strategic threat to liberal democracies — not because it is evil, but because it is systematic, patient, and consistent in its strategy of expanding power. Espionage via LinkedIn is a manifestation of that strategy, not an anomaly. I acknowledge that China is itself the target of Western intelligence operations — but that reciprocity does not change the risk assessment for citizens and civil servants of Five Eyes member countries.

Sources

Primary sources

Secondary sources

Get the geopolitics analyses

Conflicts, powers, alliances: the MadMax thread without the noise.

Cite this article

Maxime Marquette (2026). EDITORIAL: LinkedIn as a battlefield — China is recruiting spies from your network, right now. MadMax. https://mad-max.co/en/article/editorial-linkedin-comme-champ-de-bataille-la-chine-recrute-des-espions-chez-vou

How does this piece make you feel?
MM
Maxime Marquette
Independent columnist

Maxime Marquette writes most of the analyses and columns published on MadMax — geopolitics, technology, and current events, no filler.

The Newsletter

Enjoyed this piece? Get the next one.

One chronicle a week, straight to your inbox. No noise.

Comments

0 / 2000

Be the first to weigh in.

This article was generated with AI assistance, under human supervision.

Editorial1 reads3005 words4 min read