Skip to content
The ColumnReportage· No. 1815

REPORT: The Five Eyes sound the alarm — China is recruiting spies via LinkedIn and Indeed

On July 1, 2026, the Five Eyes alliance — bringing together the intelligence agencies of the United States, the United Kingdom, Canada,

Premium reading
MadMax
Key takeaways
  1. On July 1, 2026, the Five Eyes alliance — bringing together the intelligence agencies of the United States, the United Kingdom, Canada,
  2. Introduction: July 1, 2026 — a shadow war goes public
  3. The Five Eyes' joint warning
Transparency

Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.

Introduction: July 1, 2026 — a shadow war goes public

The Five Eyes' joint warning

On July 1, 2026, the Five Eyes alliance — bringing together the intelligence agencies of the United States, the United Kingdom, Canada, Australia, and New Zealand — published an unprecedented joint warning: Chinese military intelligence services are using the professional platforms LinkedIn and Indeed to identify, approach, and recruit Western targets working in government, defense, and scientific research. This kind of coordinated alert among all five alliance members is rare — its publication means the threat is serious enough and well-documented enough to warrant public communication.

ASIO — Australia's counter-espionage service — responded the same day to public attacks from China's ambassador to Australia, Xiao Qian, who had dismissed the Five Eyes warning as political fabrication. ASIO cited two recent judicial convictions — a man from Melbourne and a man from Sydney — for transmitting sensitive information to agents linked to Chinese military intelligence. Evidence, not accusations.

PayPal payments for state secrets

One of the most striking details revealed by the Five Eyes warning concerns the payment methods used by Chinese recruiters: payments of up to tens of thousands of dollars per report, made via PayPal, in exchange for defense and foreign policy intelligence. The mundanity of the instrument — a payment application used daily by millions of people — stands in stark contrast to the gravity of the information being exchanged. Twenty-first century espionage no longer necessarily runs through clandestine meetings in underground car parks — it runs through mass-market mobile apps.

This detail also reveals something about the recruitment strategy: by using PayPal rather than traceable bank transfers or cash, Chinese recruiters seek to normalize the transactions, blend them into the ordinary flow of digital payments, and reduce the likelihood that they will trigger alerts with financial authorities. It is an operational sophistication that deserves to be documented and understood.

LinkedIn and Indeed as recruitment vectors: the operational mechanics

How Chinese agents identify their targets

Professional platforms like LinkedIn and Indeed are a dream for intelligence services: millions of people voluntarily publish detailed information about their career history, skills, current and past employers, and sometimes even their future career plans. For an intelligence service seeking people with access to sensitive information in specific sectors, these platforms are magnificent recruitment databases that do not even need to be hacked — the targets profile themselves.

Chinese agents documented in the judicial cases cited by ASIO used fictitious profiles presenting identities of students, researchers, or consultants seeking paid experts for assignments. The initial approach is made under the cover of a legitimate professional interest — a conference, a consulting report, expertise on a specific subject. The relationship develops, trust is built, and the request for sensitive information only comes once the target has been sufficiently engaged.

The profile of preferred targets

The Five Eyes warning specifies the preferred target categories: civil servants with security clearances in ministries of defense, foreign affairs, and finance; applied science researchers working on dual-use technologies; private defense industry contractors; and public policy experts likely to know unpublished government positions on sensitive files.

Among the most targeted sectors: cybersecurity, military artificial intelligence, advanced weapons systems, government communications networks, and sensitive economic policies such as sanctions and export controls. This target mapping reflects the documented technological and strategic priorities of the People's Republic of China in its five-year plans and published military directives.

Ambassador Xiao Qian vs. ASIO: a revealing confrontation

Beijing's diplomatic counter-attack

The reaction of China's ambassador to Australia, Xiao Qian, to the Five Eyes warning was immediate and offensive. On July 1, 2026, he publicly attacked ASIO and the entire alliance, dismissing their allegations as political fabrication designed to damage Sino-Australian relations and fuel a Cold War mentality. This rhetoric is identical to the language used by Beijing's spokespeople in the face of similar accusations in other Five Eyes member countries.

Beijing's strategy of immediate and aggressive denial in the face of espionage accusations follows a well-documented pattern. Every allegation is automatically presented as a political attack, a manifestation of anti-Chinese racism, or a U.S. conspiracy against China. This type of response is designed to muddy the waters in the public opinion of the countries concerned and to create a division between those who take the accusations seriously and those who see them as Sinophobia.

ASIO's response: the evidence speaks

Faced with Ambassador Xiao Qian's attacks, ASIO did not back down. The agency responded by citing two specific and recent judicial cases: a Melbourne man and a Sydney man were convicted by independent Australian courts for transmitting sensitive information to agents linked to Chinese military intelligence. These convictions are public, verifiable in court records, and cannot simply be dismissed as political fabrication.

This confrontation between Beijing's ambassador and the Australian counter-espionage agency is symptomatic of a broader tension in Australia-China relations — a bilateral relationship that went through major turbulence since 2020, when Canberra called for an independent inquiry into the origins of COVID-19, triggering a series of Chinese economic reprisals. Relations have partially normalized since, but institutional distrust remains deep.

The two convicted Australians: the cases that confirm the alert

The Australian judicial context on espionage

Australia has significantly strengthened its anti-espionage and foreign interference legislation since 2018, with the adoption of the Foreign Influence Transparency Scheme and amendments to the Security Legislation Amendment Act. These new laws broadened the legal definitions of espionage and foreign interference, making prosecutions possible in cases that could not have been pursued under previous legislation. The recent convictions cited by ASIO are the direct product of this legislative strengthening.

These judicial cases represent the cases that could be documented and proven beyond a reasonable doubt in court. Counter-espionage services generally assess that the actual number of cases is significantly higher than those that result in prosecutions. The convictions are the visible — and confirmed — part of a much broader activity.

Pressure on Australian diaspora communities

Beyond strictly defined espionage cases, ASIO has documented broader pressure exerted by agents and organizations linked to Beijing on Chinese diaspora communities in Australia. This pressure aims to monitor and intimidate pro-democracy activists, defenders of Taiwanese and Tibetan independence, journalists critical of the regime, and members of the Uyghur refugee community.

These influence operations — documented notably by the Australian parliamentary committee on foreign interference — are distinct from pure intelligence collection operations, but they use some of the same networks and vectors. They illustrate the global reach of Beijing's influence apparatus, which does not stop at the borders of the People's Republic of China.

AI as a recruitment tool: the next frontier of Chinese espionage

AI as both target and recruitment tool

The Five Eyes warning of July 1, 2026 comes in a context where U.S. Congressional hearings revealed the previous week that Chinese economic espionage now primarily targets artificial intelligence sectors. This dual dimension — AI as a target of espionage and as a recruitment tool — is particularly concerning.

On AI as a recruitment tool: intelligence services are already using algorithms to analyze professional networks, identify people in situations of financial or professional vulnerability, and personalize approaches. Deepfakes and AI-generated avatars can be used to create more convincing fake recruiters. These technological capabilities transform the effectiveness and reach of recruitment operations — a documented problem that Five Eyes counter-intelligence services are working to track.

AI researchers: priority targets

Artificial intelligence researchers working in universities or defense laboratories represent prime targets for Chinese military intelligence. Their research can have direct military applications — autonomous weapons systems, intelligence analysis, large-scale deception and disinformation, cyber defense. A researcher approached by what appears to be an academic consulting offer may unknowingly provide information on unpublished work representing years of technological lead.

The United States, the United Kingdom, and other Five Eyes member countries have developed awareness programs specifically targeting AI and applied science researchers, alerting them to the risks of approach via professional networks. These training and awareness programs are documented in the annual reports of national security agencies.

Clandestine Chinese police posts and the global reach of the apparatus

A documented network of extraterritorial operations

The recruitment operations via LinkedIn are part of a broader picture of extraterritorial activities by the Chinese security apparatus abroad. Organizations like Safeguard Defenders have documented the existence of at least 100 clandestine Chinese security bureaus operating in Europe and other parts of the world, including at least four in the United Kingdom. These structures, sometimes disguised as cultural or commercial associations, operate without official diplomatic status — and therefore without the corresponding legal protections — but function with the implicit or explicit backing of Beijing's official consulates and embassies.

In the United States, the Department of Justice prosecuted several individuals accused of operating undeclared police posts on behalf of Beijing in cities like New York. These cases — some resulting in convictions, others still in progress — illustrate the scale and diversity of Chinese extraterritorial operations in Western democracies.

Cybersecurity as a complementary dimension

The human recruitment documented by the Five Eyes on July 1, 2026 is only one dimension of Chinese operations against Western governments and companies. The cyber dimension is complementary and often linked: agents recruited via LinkedIn can provide access to protected networks that facilitate the work of hacking teams. Both vectors — human and cyber — frequently work in tandem within an integrated intelligence strategy.

Cybersecurity reports — notably those published by firms like Mandiant, CrowdStrike, and Recorded Future — have documented how hacking groups linked to the PLA sometimes use information obtained through human recruitment to refine their cyber targeting. This integration of human intelligence and cyber intelligence is a hallmark of the most sophisticated services.

Conclusion: a necessary wake-up call in open democracies

What this warning asks of institutions

The Five Eyes' joint warning of July 1, 2026 is not just an information bulletin — it is a call for institutional action. The governments of member countries must strengthen verification procedures for people with access to sensitive information, develop training programs on approaches via professional networks, and cooperate with digital platforms to identify and block malicious recruitment operations.

Private sector companies, particularly those working in sensitive sectors, also have a responsibility: train their employees on the risks of approach via professional networks, establish clear reporting protocols, and cooperate with counter-espionage authorities when suspicious activities are identified. National security is no longer only the business of government agencies — in an economy where private innovation is a strategic resource, it concerns all economic actors.

What this demands of individuals

For professionals working in sensitive sectors — government, defense, research, dual-use technologies — the Five Eyes warning is a concrete reminder. A LinkedIn approach offering a paid assignment on topics related to your work deserves rigorous verification before any engagement. PayPal payments for professional information should immediately trigger alarm. Common sense and adequate training are the first lines of defense against these operations.

Western democracies have a structural advantage over authoritarian regimes: their ability to publicly inform their citizens of threats, create accessible reporting mechanisms, and process proven cases judicially in a transparent manner. The warning of July 1, 2026 is an exercise of that democratic advantage — a transparency about threats that authoritarian regimes can never offer their own populations.

Final verdict

A well-founded warning, a documented threat

The joint Five Eyes warning published on July 1, 2026 is based on documented factual elements: proven judicial convictions, verified recruitment methods (fictitious LinkedIn profiles, PayPal payments), and an espionage doctrine consistent with the known strategic priorities of Chinese military intelligence. Ambassador Xiao Qian's attack did not invalidate these facts — it revealed Beijing's strategy: deny, accuse, divide.

ASIO's response — factual, citing specific judicial convictions — illustrates what democratic institutions do best when they function properly: respond to accusations with facts. This model deserves to be followed by all security agencies in Five Eyes member countries and beyond.

Vigilance: a necessary collective investment

The fight against foreign espionage is not a discretionary budget item in democracies — it is a first-order strategic investment. Intellectual property losses, classified information compromises, and interference in political processes have real, measurable, and lasting costs. Every dollar invested in awareness, training, and counter-espionage capabilities generates returns that far exceed the initial cost.

The Chinese espionage documented on July 1, 2026 is not an abstract or hypothetical threat. These are individuals convicted by independent courts, traced payments, compromised information. Faced with this reality, democracies do not have the luxury of indifference.

What the West must do now

Coordination among allies must accelerate

The joint Five Eyes warning of July 1, 2026 is a model to be extended. NATO, EU, and Quad member countries should adopt similar mechanisms for intelligence sharing and coordinated public alerts on documented espionage threats. Coordination among allied intelligence services on these matters already exists — bringing it partially into the public sphere, as the Five Eyes did on July 1, is a strategic decision that deserves to be generalized.

France, Germany, and other European countries outside the Five Eyes face the same threats — their own domestic security agencies have published similar reports on recruitment operations via social media. Greater integration of these assessments into a coordinated public communication framework would strengthen the signal sent to Beijing.

The regulation of professional platforms in the face of espionage

LinkedIn and Indeed have a role to play in the response to this threat. Detecting fictitious profiles used for espionage recruitment operations, cooperating with counter-espionage agencies in democratic countries, and establishing accessible user reporting mechanisms are concrete measures that these platforms can and must develop. The freedom of professional online connection cannot exist without safeguards when state actors use it as a vector for illegal operations.

This platform responsibility is also a regulatory issue that democratic governments must address directly — through adapted legislation, cooperation requirements with national security authorities, and transparency obligations on detected malicious activities. The regulation of digital platforms does not stop at personal data protection — it now extends to national security.

By Maxime Marquette, columnist

Columnist's transparency note

My sources, my method, and my biases

This report is based on publicly available sources: the public Five Eyes warning of July 1, 2026, the public statements of ASIO and Ambassador Xiao Qian, the reports of security agencies in Five Eyes member countries, and analyses from independent research institutes in cybersecurity and counter-intelligence. I do not have access to the full court records of the two Australian convictions cited — I report the public elements, not the detail of evidence presented in court.

My position is pro-democracy and pro-institutional transparency. I am skeptical of Beijing's systematic denials in the face of espionage accusations, for a simple reason: these denials have been systematically contradicted by independent judicial proceedings in several countries. That does not mean every accusation is true — but it requires that available judicial evidence be taken seriously.

What this report cannot cover

The precise operational details of Chinese recruitment operations remain largely classified. The exact scale of ongoing operations, the number of individuals currently targeted or recruited, and the precise technical capabilities being used are information that security agencies do not make public — for sound operational reasons. This report describes the known and documented contours of a reality whose submerged portion is probably larger than what public sources allow us to grasp.

I have no confidential source in Five Eyes agencies, in the governments concerned, or in the Australian judicial proceedings cited. All my claims are based on public documents and statements.

Sources

Primary sources

Secondary sources

Get the geopolitics analyses

Conflicts, powers, alliances: the MadMax thread without the noise.

Cite this article

Maxime Marquette (2026). REPORT: The Five Eyes sound the alarm — China is recruiting spies via LinkedIn and Indeed. MadMax. https://mad-max.co/en/article/reportage-les-cinq-yeux-sonnent-l-alarme-la-chine-recrute-des-espions-via-linked

How does this piece make you feel?
MM
Maxime Marquette
Independent columnist

Maxime Marquette writes most of the analyses and columns published on MadMax — geopolitics, technology, and current events, no filler.

The Newsletter

Enjoyed this piece? Get the next one.

One chronicle a week, straight to your inbox. No noise.

Comments

0 / 2000

Be the first to weigh in.

This article was generated with AI assistance, under human supervision.

Reportage2732 words4 min read