Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
state-sponsored-espionagegovernment-diplomatic-threattelecommunications-sector-threatcommand-and-control-method

China-Linked Espionage Targeting Former US Officials and UK Government Communications

Updated 3mo agoFirst seen Jan 27, 20262 sources

Reporting indicates China-linked intelligence activity is targeting current and former Western government officials through both human and technical collection. In the US case, a suspected Chinese influence/collection network using a purported consultancy (Foresight and Strategy) allegedly approached a former senior State Department official and offered payment to produce an assessment of US policy priorities in Venezuela, consistent with prior research describing a nexus of fake companies and websites used to recruit people with government and think-tank policy experience.

In the UK, Chinese state-linked hackers are accused of maintaining years-long access to communications associated with senior Downing Street officials, with reporting alleging compromises affecting phones used by aides to former prime ministers Boris Johnson, Liz Truss, and Rishi Sunak dating back to 2021 and discovered in 2024. The activity has been linked by sources to Salt Typhoon, a China-aligned espionage group associated with telecom-provider intrusions that can enable collection of call metadata and potentially content (texts/calls), allowing intelligence value even without direct handset malware.

Share:
China-Linked Espionage Targeting Former US Officials and UK Government Communications
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Jan 27, 20265mo ago

China denies UK espionage allegations

After the allegations were reported publicly, China's foreign ministry rejected the claims as baseless and accused Western governments of politicizing cybersecurity. The denial came amid renewed scrutiny of Salt Typhoon's alleged telecom-focused espionage activity.

Former State official receives suspicious Venezuela research solicitation

A person using the name 'Keven Lee' and claiming to represent 'Foresight and Strategy' contacted a former senior U.S. State Department official and offered payment for an assessment of U.S. policy priorities in Venezuela. After a virtual interview, the requester asked for a 1,000-word brief drawing on conversations with State Department colleagues, prompting the former official to view it as suspicious and warn others publicly.

China-linked fake firm network targets former U.S. officials and researchers

Prior reporting and FDD research assessed that a network of fake companies and websites, including 'Foresight and Strategy,' was being used to recruit former U.S. government and think-tank personnel for policy insight on issues of interest to Beijing. Analysts tied the infrastructure to China through domain registrations and shared technical indicators.

Jan 1, 20242y ago

UK discovers Salt Typhoon-linked activity affecting officials' phones

The alleged UK phone compromise campaign was reportedly discovered in 2024, after years of suspected access to devices used by senior government figures. UK officials publicly referred to the incident only as a 'cluster of activity' linked to Salt Typhoon.

Jan 1, 20215y ago

Chinese-linked phone compromises of UK officials reportedly begin

Reporting cited by The Register says Chinese state-linked hackers likely began compromising phones used by senior Downing Street officials and aides around former prime ministers as early as 2021. The activity reportedly enabled access to sensitive communications or metadata over multiple years.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

9 LINKEDOpen in app
Threat actors
1 linked
Organizations
8 linked
Foundation for Defense of DemocraciesCenter for Strategic and International StudiesNextgov/FCWForesight and StrategyCisco SystemsThe TelegraphTP-LinkNetgear
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.