Skip to content
The ColumnAnalysis· No. 2927

Hackers Linked to China Increasingly Target Employees at AI Start-ups

The latest report from cybersecurity firm CrowdStrike, published in early June 2026, delivers a chilling verdict: state-linked actors tied to China now

Premium reading
MadMax
Key takeaways
  1. The latest report from cybersecurity firm CrowdStrike, published in early June 2026, delivers a chilling verdict: state-linked actors tied to China now
  2. Introduction: the new front line of technological espionage
  3. A report that reshapes the threat picture
Transparency

Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.

Introduction: the new front line of technological espionage

A report that reshapes the threat picture

The latest report from cybersecurity firm CrowdStrike, published in early June 2026, delivers a chilling verdict: state-linked actors tied to China now account for more than half of all state-sponsored intrusions against the American technology sector. This reality, documented with precision, forces a rethink of how AI start-ups protect their most valuable assets — their models, their training data, and their intellectual property.

This decoding sets out to understand why employees themselves have become the preferred target of this offensive, and what it reveals about the global technology race between the West and its strategic rivals.

Five groups, one shared obsession with artificial intelligence

CrowdStrike identifies five distinct groups linked to Beijing active in this campaign: MURKY PANDA, MUSTANG PANDA, OVERCAST PANDA, SUNRISE PANDA, and WARP PANDA. Together, these actors account for more than 58 percent of state-linked intrusions observed against the technology sector between April 2025 and March 2026. The MURKY PANDA group in particular made its mark through password-spraying campaigns that hit more than 340 American entities.

This multiplicity of groups is no organizational accident. It reflects a coordinated yet compartmentalized Chinese strategy, in which different units specialize by target and technique, making Western defense that much harder to coordinate.

Let's call this what it is: these are not lone hackers working freelance, they are coordinated units acting on behalf of a state. Confusing the two badly understates the scale of the threat.
Five state hacking groups zeroed in on the same American AI start-ups: that alone should give pause to anyone who still thinks the AI race is just a private commercial rivalry between companies.

When the human becomes the most exploitable weakness

The shift toward social engineering and infiltration

The most striking finding in the CrowdStrikereport is not just quantitative — it is qualitative. Attackers increasingly favor exploiting human vulnerabilities over pure technical intrusion. According to information reported by CNBC, North Korea illustrates this shift in spectacular fashion: the FAMOUS CHOLLIMA group alone accounts for 47 percent of state-linked intrusions involving direct hands-on-keyboard activity, often through fake identities of remote IT workers embedded inside Western companies.

This approach exploits a structural weakness of the modern workplace: remote hiring, sometimes superficial identity verification, and the constant pressure on start-ups to bring in scarce technical talent quickly. Every poorly vetted job opening becomes a potential doorway for an agent of a hostile state.

The Agentiq Capital case, a symptom of a wider problem

Brian Abbott, head of Agentiq Capital, told CNBC that an employee hired with ties to Chinese interests deliberately sabotaged company code and the firm's website before being fired, prompting a formal complaint to the FBI. An executive at Copyleaks confirmed a similar trend: new hires are now immediate targets from the moment they are onboarded, well before they gain access to the most sensitive systems.

These are not isolated anecdotes. They illustrate a paradigm shift in how state adversaries approach technological espionage: rather than breaching firewalls, they infiltrate org charts.

The sabotage at Agentiq Capital should serve as a wake-up call for the entire artificial intelligence industry. This is no longer geopolitical science fiction — it is an employee sitting at a desk, with a legitimate access badge, secretly working for a foreign service.

eCrime, the quiet accomplice of state espionage

An increasingly porous line between crime and espionage

The CrowdStrike report also finds that for-profit cybercrime, categorized as eCrime, now accounts for 65 percent of interactive operations observed against the technology sector. That massive share is a reminder that the line between organized crime and state espionage is steadily blurring, with some criminal groups instrumentalized or tolerated by intelligence services to muddy the waters of attribution.

Initial access brokers — the middlemen who sell entry points into compromised networks — targeted 277 technology organizations in the period studied alone, a 30 percent increase over the prior period. In total, 572 technology entities were identified on data leak sites, a figure that speaks to the industrial scale of this underground economy.

Why AI start-ups are high-value targets

Young companies specializing in artificial intelligence often combine high financial valuations, critical intellectual property, and cybersecurity resources still far less mature than those of established tech giants. That combination makes them especially lucrative targets, both for cybercriminals chasing a quick financial payoff and for state intelligence services looking for a technological shortcut.

Adam Meyers, a CrowdStrike executive, summed up the situation in a striking line reported by Reuters: China is positioning itself in an artificial intelligence arms race with the openly stated goal of achieving global dominance by 2030.

This convergence between cybercrime and Chinese state espionage is not an accident of circumstance — it is a strategy. Beijing has no qualms about weaponizing criminal networks when doing so serves its long-term technological ambitions.

2030, the deadline that obsesses Beijing

A long-standing ambition, now accelerating

China's goal of achieving global dominance in artificial intelligence by 2030 is nothing new rhetorically, but its recent acceleration, documented through intensified espionage campaigns, suggests a fresh strategic urgency in Beijing. That urgency may be linked to American restrictions on the export of advanced semiconductors, which limit China's ability to build its own cutting-edge computing capacity without resorting to espionage or sanctions evasion.

Each technological restriction imposed by Washington appears to produce a paradoxical effect: rather than durably slowing Chinese ambitions, it intensifies espionage efforts aimed at closing the gap by other means — faster and cheaper than fundamental research.

A strategic dilemma for Western decision-makers

This reality places Western governments in a genuine bind: tightening export controls further risks accelerating espionage efforts even more, while loosening those controls would hand China, on a plate, the very technologies it struggles to develop on its own. There is no simple answer to this equation, only costly trade-offs among competing risks.

What is certain is that a purely defensive response, however technically robust, will never be enough unless it is paired with heightened human vigilance inside the very organizations being targeted.

I don't believe there is a magic solution to this dilemma. But I am convinced that passively accepting Chinese espionage in the name of frictionless business would be a major strategic mistake for the technological future of the West.

Start-ups facing an impossible choice

Maximum security versus speed of execution

Young artificial intelligence companies operate in an environment where speed of execution is often seen as the key to survival against the competition. Slowing down hiring processes to more rigorously vet every candidate, or investing heavily in cybersecurity from the earliest stages of development, is a cost that many founders wrongly treat as a luxury reserved for large, established companies.

This tension between speed and security is precisely what state adversaries exploit. A fast-growing start-up, under pressure to hire qualified engineers in an extremely tight labor market, is structurally more vulnerable than a multinational with mature security departments.

Concrete measures are starting to emerge

Facing this mounting pressure, some start-ups are now strengthening their identity-verification procedures, particularly for roles offering remote access to sensitive systems. Solutions such as real-time video verification, cross-checking professional references, and post-hire behavioral monitoring are gaining ground, though adoption remains uneven depending on each company's size and resources.

These measures, however, amount to only a partial response. Without a collective awakening across the industry, paired with stronger government support for sharing threat intelligence, the most vulnerable start-ups will keep offering valuable entry points to adversaries of the West.

It's time for the AI industry to stop treating cybersecurity as a regulatory box to check. This is a matter of national strategic survival, not just corporate compliance.

The Volt Typhoon precedent, a warning ignored

Critical infrastructure infiltration already documented

Even before the current wave targeting artificial intelligence start-ups, American authorities had already sounded the alarm over groups like Volt Typhoon, linked to China, accused of infiltrating American critical infrastructure, from power grids to drinking-water systems. That precedent should have served as a sufficient warning to massively strengthen cybersecurity across the American private sector, particularly in strategic technology industries.

Yet the CrowdStrike report suggests the lessons of that episode were only partially absorbed. Artificial intelligence start-ups, often fixated on rapid growth rather than resilience against state-linked threats, remain a preferred target despite repeated warnings from Western intelligence agencies.

Volt Typhoon should have been a collective wake-up call. The fact that AI start-ups remain this vulnerable today shows the American tech industry still has not grasped the real scale of the Chinese threat.

What Europe must learn from the American experience

European start-ups are not immune

While the CrowdStrike report focuses on American companies, nothing suggests European artificial intelligence start-ups are spared similar tactics. The same structural vulnerabilities — rapid hiring, insufficient identity checks, limited cybersecurity resources — exist just as much on European soil, amid an innovation race that is every bit as fierce.

The West as a whole, not just the United States, must draw the necessary conclusions from this report to strengthen transatlantic coordination on sharing cyber threat intelligence tied to China, North Korea, and, to a lesser but growing extent, Iran and Russia.

Europe would be making a strategic mistake if it assumed this report only concerns the United States. The AI race is global, and Chinese espionage does not respect transatlantic borders.

The role of American agencies in the response

CISA and the FBI on the front line

Facing this wave of espionage, American agencies like CISA and the FBI are issuing more frequent warnings to the private sector, particularly to young technology companies that often lack the internal resources to interpret these alerts on their own. Agentiq Capital's complaint to the FBI illustrates a still-too-rare reflex: reporting a suspicious incident promptly rather than trying to handle it internally out of concern for reputation.

This cooperation between the private sector and federal agencies remains uneven depending on the size and maturity of the companies involved. Large artificial intelligence firms often have direct channels to authorities, while smaller start-ups are largely left to fend for themselves against adversaries backed by considerable state resources.

It is unfair, and strategically dangerous, that the smallest artificial intelligence start-ups are left alone to face adversaries backed by entire states. Federal support should scale with vulnerability, not with the size of a company's lobbying budget.

Conclusion: collective vigilance is no longer optional

A challenge that goes beyond corporate responsibility alone

The threat described by CrowdStrike cannot be countered by artificial intelligence start-ups alone, however vigilant they may be. It demands stronger coordination between the private sector, American intelligence agencies, and their Western allies, in order to share indicators of compromise and profiles of identified malicious actors more quickly.

The stakes go beyond technical cybersecurity alone

This story illustrates, once again, that the technological rivalry between the West and China is not fought solely in research labs or data centers, but also in the human resources departments of the most innovative companies. Protecting the West's lead in artificial intelligence now requires vigilance that begins at the very first job interview.

By Maxime Marquette, columnist

Columnist's transparency note

Sources and limits of this decoding piece

This article draws on the public CrowdStrike report published in June 2026, as well as verifiable news reporting. I had no access to confidential information and I make no claim to know the precise identity of the individuals mentioned in the cases reported by third parties.

No invention, no fabricated testimony

The facts, statistics, and quotes come exclusively from the sources listed below. The italicized passages reflect my personal opinion as a columnist and are clearly distinguished from the rest of the factual text.

Sources

Primary sources

CrowdStrike — 2026 Technology Threat Report, June 2026

CNBC — Chinese cyberattacks targeting AI start-ups, July 1, 2026

Secondary sources

Reuters — Chinese hackers pose biggest espionage threat, CrowdStrike says, June 9, 2026

TechBuzz — China widens its AI espionage beyond technology theft

CISA — joint advisory on Volt Typhoon activity against American critical infrastructure

CNBC — accounts from companies targeted by China-linked espionage, July 1, 2026

Get the geopolitics analyses

Conflicts, powers, alliances: the MadMax thread without the noise.

Cite this article

Maxime Marquette (2026). Hackers Linked to China Increasingly Target Employees at AI Start-ups. MadMax. https://mad-max.co/en/article/les-pirates-lies-a-la-chine-ciblent-de-plus-en-plus-les-employes-des-start-ups-d

How does this piece make you feel?
MM
Maxime Marquette
Independent columnist

Maxime Marquette writes most of the analyses and columns published on MadMax — geopolitics, technology, and current events, no filler.

The Newsletter

Enjoyed this piece? Get the next one.

One chronicle a week, straight to your inbox. No noise.

Comments

0 / 2000

Be the first to weigh in.

This article was generated with AI assistance, under human supervision.

Analysis2040 words10 min read