Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
state-sponsored-espionagegovernment-diplomatic-threatinsider-threat-incidentdata-exfiltration-method

China-Linked Espionage Targeting U.S. Government and Technology Talent

Updated 3mo agoFirst seen Feb 7, 20263 sources

U.S. authorities and researchers are highlighting China-linked espionage that increasingly leverages online recruitment and employment channels to access sensitive information. Reporting on recent federal cases describes foreign intelligence services posing as consulting firms, research groups, or recruiters to approach current and former U.S. government personnel—often starting via email or job platforms and escalating through staged interviews, fake websites, and payment offers—to solicit classified or sensitive information; multiple Justice Department actions in 2025 reportedly involved such virtual-first recruitment approaches.

Separately, a former Google engineer, Linwei Ding, was found guilty of economic espionage and trade secret theft after prosecutors said he exfiltrated over 2,000 pages of confidential AI supercomputing documents (including TPU/GPU architecture details, orchestration software, SmartNIC networking designs, and internal system configurations) and uploaded them to a personal cloud account while maintaining undisclosed ties to China-based companies and engaging with a Shanghai-sponsored talent program. Broader context from CSIS’ long-running survey of Chinese espionage cases underscores that these incidents fit a sustained pattern since 2000 spanning both human intelligence and cyber-enabled theft targeting U.S. government and commercial technologies, while noting open-source case lists likely undercount the true scope.

Share:
China-Linked Espionage Targeting U.S. Government and Technology Talent
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Mar 5, 20264mo ago

CSIS documents long-running Chinese espionage against the United States

CSIS published a survey summarizing alleged and confirmed Chinese espionage and cyber-espionage incidents in the United States from roughly 2000 through 2023. The report highlights sustained targeting of U.S. government, defense, critical infrastructure, healthcare, and commercial entities, along with multiple DOJ indictments and public attributions over the period.

Feb 6, 20265mo ago

Nextgov reports China-linked recruitment targeting laid-off U.S. personnel

Nextgov/FCW reported that foreign intelligence services, primarily linked to China, were exploiting recent U.S. federal layoffs by approaching former and sometimes current government personnel through fake job offers and recruiter-style outreach. The operations used staged interviews, consulting fronts, and payment offers to solicit classified or sensitive information.

OpenClaw patches high-severity RCE flaw CVE-2026-25253

The OpenClaw ecosystem recently patched a high-severity remote code execution vulnerability tracked as CVE-2026-25253. The fix was noted alongside broader concerns about malicious third-party skills in the platform.

Researchers find 200+ malicious skills in OpenClaw AI assistant ecosystem

Security researchers identified more than 200 malicious 'skills' published for the OpenClaw open-source AI assistant. The packages posed as benign utilities but were designed to deliver information-stealing malware, highlighting supply-chain risk in AI assistant plugin ecosystems.

Okta and Mandiant report rise in ShinyHunters-linked vishing intrusions

Okta and Mandiant reported a surge in vishing-driven intrusions tied to ShinyHunters-related clusters that impersonate IT staff to obtain MFA approvals and SSO credentials. The campaigns enabled access to platforms such as Okta, Microsoft Entra, and Google, followed by SaaS data theft and extortion activity.

Google engineer Linwei Ding found guilty of economic espionage

Former Google software engineer Linwei Ding was found guilty of economic espionage and trade secret theft after exfiltrating more than 2,000 pages of confidential AI supercomputing documents. The material was allegedly shared with China-linked technology interests.

FDD identifies broad network of China-linked fake recruiting websites

Analysts at the Foundation for Defense of Democracies assessed a network of fake consulting and recruiting firms likely tied to China that targeted current and former U.S. government personnel. An FDD researcher identified more than 100 related websites showing indicators such as China-based registration, Chinese language packs, and plagiarized content.

Jan 1, 20251y ago

DOJ announces multiple 2025 cases tied to virtual foreign recruitment efforts

According to Nextgov/FCW, the U.S. Department of Justice announced charges or indictments in at least five cases during 2025 involving current or former U.S. government personnel accused of passing sensitive information to foreign intelligence services. In nearly all of those cases, the initial contact reportedly occurred online through recruiter-style outreach, email, or job platforms.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

178 LINKEDOpen in app
Affected products
4 linked
GithubGmailDocusignPowershell
Organizations
154 linked
Microsoft CorporationGitHubGoogleLucent TechnologiesTrend MicroMicron TechnologyDell TechnologiesLG CorporationGE HealthCareSupervisor Inc.Verizon CommunicationsOhio State UniversityUnited AirlinesEMC CorporationAlcoaAnalog DevicesThe Wall Street JournalChina General Nuclear Power GroupPPG IndustriesUnitedHealth GroupStanford UniversityGeneral ElectricTaiwan Semiconductor Manufacturing CompanyRaytheon TechnologiesBayerInternational Business MachinesSiemensT-Mobile USTrimbleDuPontHuawei TechnologiesFox-ItCrowdStrikePhillips 66Nippon Paint HoldingsLG ElectronicsRSA SecurityGeneral MotorsAppleBroadcomMoody's AnalyticsMonolithic Power SystemsThe Washington PostLockheed MartinAdobeHarvard UniversityDowThe Coca-Cola CompanyYahooPeking UniversityCME GroupBaiduAnthemGlaxoSmithKlineBloombergBoeingMotorolaPennsylvania State UniversityInternational Civil Aviation OrganizationU.S. Chamber of CommerceFord Motor CompanyHytera Communications Corp. LTD.StarwoodQuantum3DChery AutomobileBoyusecOrbit IrrigationNetLogics MicrosystemsChemoursDatang Telecom Technology CompanySinovelAlphabet Inc.Huiyuan Juice GroupMetaldyneHuafuDell EMCDigital BondBeijing Dabeinong Technology GroupTelvent CanadaMonsantoLG SeedsOak Ridge National LaboratoryLos Alamos National LaboratorySiRF TechnologyMetropolitan Water District of Southern CaliforniaMonolithic Microwave Integrated CircuitsPangang GroupThe Climate CorporationHytera CommunicationsUnited States SteelSinovel Wind GroupMedroboticsUnited Technologies Research CenterGeneral Technology Systems Integration, Inc.CBM-Future New Material Science and Technology Co. Ltd.InfoWar MonitorThe Chemours CompanyGreatFireBeijing Automotive GroupAmerican SuperconductorValsparOrbit Irrigation ProductsTexas A&M UniversityStarwood Hotels & Resorts WorldwideLinkOcean Technologies, LTDUnited States Investigations ServicesNationwide Children's HospitalE. I. du Pont de Nemours and CompanyStarwood Hotels and Resorts WorldwideThe New York Times CompanyUnited States Chamber of CommerceGlobexBoeing EngineeringShenyang Institute of AutomationBoeing Defense, Space & SecurityClimate CorporationU.S. Investigations ServicesNorthwestern Polytechnical UniversityMetropolitan Transportation AuthorityAxios MediaMetaldyne Performance GroupPanzhihua Iron and Steel GroupThe Valspar CorporationThe Dow Chemical CompanyFox-IT Holding B.V.Sinovel Wind Group Co., Ltd.Yahoo! Inc.Beijing Dabeinong Technology Group Co., Ltd.Pangang Group Co., Ltd.Boeing Engineer (employer: Boeing)Siemens AktiengesellschaftFox-IT B.V.Ohio State University Wexner Medical CenterDow Jones & CompanyMarriott InternationalBayer AktiengesellschaftKoninklijke PhilipsChengdu GaStone Technology CompanyBayer Crop ScienceAmerican manufacturer of cast-iron productsHuafu Fashion Co., Ltd.LimagrainChina Electronics Technology Group CorporationCommunity Health SystemsSalesforceFoundation for Defense of DemocraciesOktaDocuSignNextgov/FCWThe HillJamestown AdvisorsMemetic WarfareNavigating ConsultingDavis Ryan Consulting
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.