By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Chinese cyber spooks lure laid-off US government workers | Computer Weekly
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Chinese cyber spooks lure laid-off US government workers | Computer Weekly
News

Chinese cyber spooks lure laid-off US government workers | Computer Weekly

News Room
Last updated: 2025/05/19 at 8:53 PM
News Room Published 19 May 2025
Share
SHARE

A Washington DC-based think tank claims it has discovered evidence of a covert network of digital front companies operated by the Chinese intelligence services that are targeting laid-off US government employees.

Since Donald Trump’s inauguration in January, thousands of people have been let go across the US government – including many in cyber security threat intel and research functions – following audits by the Elon Musk-led Department of Government Efficiency (Doge).

The mass lay-offs, which the White House says are being done in the name of saving money, have dramatically slowed and even halted many government functions. In some places – such as at the Food and Drug Administration (FDA), they are being reversed.

Now, the Federation for the Defence of Democracies (FDD), a research institute that focuses primarily on America’s national security and foreign policy, says that Beijing is moving to try to exploit the lay-offs for its own intelligence-gathering purposes.

FDD senior analyst on emerging threats Max Lesser said these fraudulent organisations were posing as geopolitical risk consultancies and headhunting firms that appeared to be based in Japan, Singapore and the US.

“The tactics employed by this network closely resemble previous Chinese intelligence operations targeting US government officials and other high-value targets across the US, Europe and beyond,” said Lesser.

“Despite the network’s efforts to create the illusion that several separate firms outside of China are seeking to recruit laid-off federal employees, the network’s technical features point both to its Chinese origins and the role of a single entity in creating all of its components,” he said.

The FDD named the companies as Smiao Intelligence, Dustrategy, RiverMerge Strategies, Tsubasa Insight and Wavemax Innov.

Of these, said Lesser, only Smiao Intelligence appears to be a real company. The others are alleged to be little more than digital fronts operating cloned websites, with artificial intelligence (AI)-generated text and clearly fake customer references.

Lesser said it was likely that individuals associated with Smiao created the network themselves for intelligence-gathering purposes, because they all rely on the same China-hosted Tencent server to run their websites, and all but one of them are using – or once did – a China-based email service called chengmail. Additionally, he said, four out of five of the sites share the same SSL certificate.

The FDD was also able to ascertain Smaio was likely the nexus of the covert operation. It has the oldest domain in the group, dating back eight years, and its homepage directs to an apparent parent company, Beijing Simiao Intelligent Information Technology Co Ltd, which is apparently a trademark application agency, officially recognised by China’s State Intellectual Property Office, and was registered as a company in 2012.

Notably, one of the companies, RiverMerge, appeared for a while to have an office in the US – the state of Colorado, to be precise – as well as Singapore, although these references were scrubbed from its website some time before 26 March 2025. US registries do show a company called RiverMerge Strategies LLC, formed in 2024, with a domain registered in Beijing and evidence of a shared phone number with Smiao.

Tried-and-tested tactics

The Chinese state has form dating back the best part of a decade when it comes to using recruitment websites to gather intelligence on US targets. Back in 2020, a Singapore national, Jun Wei Yeo, was sentenced to jail after obtaining more than 400 resumes, 90% of them from American military and government officials with some level of security clearance, and passing them to Beijing.

Nor have European targets been immune – a German intelligence report from eight years ago revealed how China was able to obtain data on 10,000 German citizens as potential intelligence sources, while in 2019, the French told a similar story. Two years ago, in 2023, British intelligence chief Ken McCallum revealed that 20,000 Britons had been approached in a similar manner.

In many cases, this targeting was conducted using legitimate job websites, including social network LinkedIn, which has been described as the “ultimate playground” for intelligence gathering.

It is not known if the operation targeting laid-off federal workers was successful, but the effort certainly comes at a dangerous time for the US, and an opportune moment for China as it seeks to exploit Trump’s unique approach to government and policymaking.

“This threat is heightened at a time when thousands of former and current federal workers are seeking new employment,” said Lesser. “If the public and private sectors do not act quickly to address these vulnerabilities, China and other adversaries will continue preying on former public servants who may not be aware of the threat and face pressure to find new jobs quickly.”

He called on the US government to take more active measures to raise awareness of this gathering cyber threat – such as sending representatives to discuss the issue in the media. It should also proactively work with the likes of LinkedIn and other networking sites to monitor potentially suspicious activity, such as job postings that explicitly seek out ex-government employees. LinkedIn could also implement more stringent Know Your Customer policies for people creating company pages on its site.

Lesser also called for Congress to exercise additional oversight through the Senate Select Committee on Intelligence and the House Permanent Select Committee on Intelligence.

Finally, Washington could also turn the situation to its advantage by creating sock puppet accounts to bait Chinese intelligence operatives into coming out of the shadows to make contact.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article The Best Way To Save on Apple Products Is With These Early Memorial Day Deals
Next Article The HackerNoon Newsletter: There’s No TensorFlow Without Tensors (5/19/2025) | HackerNoon
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Best Laptop Deal of the Day: 27% Off the AI-Infused Yoga Slim 7i Touch
News
Amazon has slashed 40% off one of our current favourite tumble dryers
Gadget
T-Mobile gets a green light to build 190-Foot cell tower despite resident pushback
News
7 Ways to Secure More Engaged Social Media Leads
Computing

You Might also Like

News

Best Laptop Deal of the Day: 27% Off the AI-Infused Yoga Slim 7i Touch

4 Min Read
News

T-Mobile gets a green light to build 190-Foot cell tower despite resident pushback

3 Min Read
News

Driverless cars need to be more human, study finds

2 Min Read
News

‘Every second counts’: Why FX’s The Bear is a must-watch for anyone who creates for a living

7 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?