Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

FBI shuts down 13 ‘consulting’ websites used for suspected Chinese espionage

The FBI has disrupted a Chinese espionage campaign using 13 fake consulting websites to recruit current and former U.S. government and military personnel with security clearances. The threat actors used fictitious personas, AI-generated photographs, and job postings on legitimate platforms to lure targets, then moved communications to encrypted apps like Telegram and offered cryptocurrency payments for sensitive information. The operation highlights a persistent threat vector where adversaries leverage professional networking and AI-generated content to conduct recruitment and illicit information gathering.
Read Full Article →

Threat Intelligence FBI shuts down 13 ‘consulting’ websites used for suspected Chinese espionage June 11, 2026 Share By Laura French FBI seizure notice displayed on the website for “Centrik Global Consulting.” The U.S. Federal Bureau of Investigation (FBI) shut down 13 websites suspected to be tied to a Chinese espionage campaign involving the recruitment of current and former government security clearance holders. The websites promoted fake consulting services, such as Centrik Global Consulting, Rightinfo Consulting, Pulse Wave Global and Catalyst Global Solutions, to lend legitimacy to job postings seeking current and former U.S. government and military employees for “consultant” and “analyst” jobs, the U.S. Department of Justice said in a press release Wednesday. The suspected Chinese operatives used a combination of fictitious personas, stolen identities and AI-generated photographs to build up the façade of legitimate businesses seeking candidates’ expertise for unspecified “clients,” officials said. The operation ran since at least November 2023, utilizing encrypted applications such as Telegram for communications and cryptocurrency to make payments in exchange for confidential information. “The fake consulting company domains seized by the FBI illustrate the lengths the Chinese government’s intelligence services will go to as they try to use AI-generated content to trick, recruit, or coerce current and former U.S. security clearance holders into sharing sensitive information,” Roman Rozhavsky, assistant director of the FBI’s Counterintelligence and Espionage Division, said in a statement. “The FBI and our partners have observed China’s intelligence services resort to using AI, professional networking sites, and only payment platforms to target Americans.” The alleged conspirators made job postings on sites like Upwork, Expertia AI, Hubstaff Talent, Wellfound and Post Job Free to entice targets with government expertise to apply. After contacting the targets, the conspirators pressed them to provide sensitive “insider” information and offered large payments for “research reports” containing such information, officials said. The website operators are accused of conspiracy to commit bribery, identity theft and international money laundering, according to an affidavit supporting the domain seizures. While the DOJ attributes the campaign to the Chinese government, the alleged conspirators denied foreign government involvement, according to the press release. The website seizures come one week after the FBI released a joint alert with other Five Eyes intelligence agencies warning of such recruitment schemes targeting Five Eyes government and military personnel. The alert said recruiters typically conduct interviews with candidates and ask them to write a trial report before moving them to encrypted messaging platforms and requesting more privileged information. Recruits have received payments from between a few hundred dollars to several thousands of dollars for each report, with payment methods also including PayPal, Payoneer, Zelle, Skrill, Wise and Western Union, in addition to cryptocurrency, officials said. “Even unclassified information on government policy, or on military strategy, capabilities and installations, can be collected and combined with more sensitive reporting to form a comprehensive operational picture,” the alert stated. “[…] Applicants who provide their resumes and other personality identifiable information risk compromises of personal privacy.” Laura French Related Threat Intelligence OceanLotus targets stock investors and construction firm with SPECTRALVIPER backdoor SC Staff June 11, 2026 Vietnam-aligned threat actor OceanLotus has been linked to two distinct campaigns targeting domestic entities and stock investors with a backdoor known as SPECTRALVIPER, according to ESET. Threat Intelligence Russian national charged in connection with Void Blizzard cyberespionage campaign SC Staff June 11, 2026 Federal prosecutors have charged a Russian national, Denis Nikolayevich Obrezko, with conspiracy to commit unauthorized computer access in connection with a widespread cyberespionage campaign attributed to the Russia-aligned threat group Void Blizzard, according to a recent report by CyberScoop. Threat Intelligence JDY botnet expands, enabling rapid exploitation of disclosed vulnerabilities SC Staff June 10, 2026 Initially flagged as part of the KV-botnet, JDY has evolved into an independent reconnaissance capability following the U.S. government's takedown of KV in early 2024. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Virtual Conference Securing the Future of Finance: Strategies to Counter Modern Cyber Threats On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Account Harvesting Backdoor DNS Spoofing Deepfake Denial of Service Disruption Distributed Scans Domain Hijacking Hybrid Attack Reconnaissance You can skip this ad in 5 seconds

Share this article