U.S. accuses China of 'super aggressive' spy campaign on LinkedIn

By Warren Strobel and Jonathan Landay

The United States' top spy catcher said Chinese espionage agencies are using fake LinkedIn accounts to try to recruit Americans with access to government and commercial secrets, and the company should shut them down.

William Evanina, the U.S. counter-intelligence chief, told Reuters in an interview that intelligence and law enforcement officials have told LinkedIn, owned by Microsoft Corp., about China’s "super aggressive" efforts on the site.

He said the Chinese campaign includes contacting thousands of LinkedIn members at a time, but he declined to say how many fake accounts U.S. intelligence had discovered, how many Americans may have been contacted and how much success China has had in the recruitment drive.

German and British authorities have previously warned their citizens that Beijing is using LinkedIn to try to recruit them as spies. But this is the first time a U.S. official has publicly discussed the challenge in the United States and indicated it is a bigger problem than previously known.

Evanina said LinkedIn should look at copying the response of Twitter, Google and Facebook, which have all purged fake accounts allegedly linked to Iranian and Russian intelligence agencies.

"I recently saw that Twitter is cancelling, I don’t know, millions of fake accounts, and our request would be maybe LinkedIn could go ahead and be part of that," said Evanina, who heads the U.S. National Counter-Intelligence and Security Center.

It is highly unusual for a senior U.S. intelligence official to single out an American-owned company by name and publicly recommend it take action. LinkedIn says it has 575 million users in more than 200 counties and territories, including more than 150 million U.S. members.

Evanina did not, however, say whether he was frustrated by LinkedIn's response or whether he believes it has done enough.

LinkedIn's head of trust and safety, Paul Rockwell, confirmed the company had been talking to U.S. law enforcement agencies about Chinese espionage efforts. Earlier this month, LinkedIn said it had taken down “less than 40” fake accounts whose users were attempting to contact LinkedIn members associated with unidentified political organizations. Rockwell did not say whether those were Chinese accounts.

“We are doing everything we can to identify and stop this activity,” Rockwell told Reuters. "We’ve never waited for requests to act and actively identify bad actors and remove bad accounts using information we uncover and intelligence from a variety of sources including government agencies."

Rockwell declined to provide numbers of fake accounts associated with Chinese intelligence agencies. He said the company takes “very prompt action to restrict accounts and mitigate and stop any essential damage that can happen” but gave no details.

LinkedIn "is a victim here," Evanina said. "I think the cautionary tale ... is, 'You are going to be like Facebook. Do you want to be where Facebook was this past spring with congressional testimony, right?'" he said, referring to lawmakers' questioning of Facebook CEO Mark Zuckerberg on Russia's use of Facebook to meddle in the 2016 U.S. elections.

China's foreign ministry disputed Evanina's allegations.

"We do not know what evidence the relevant U.S. officials you cite have to reach this conclusion. What they say is complete nonsense and has ulterior motives," the ministry said in a statement.

But Senator Mark Warner, the top Democrat on the Senate Intelligence Committee, said Beijing's exploitation of LinkedIn"demonstrates the length to which Chinese intelligence will go, and the 21st Century counter-intelligence challenges facing us in a world where everybody's got an online footprint."

Evanina said he was speaking out in part because of the case of Kevin Mallory, a retired CIA officer convicted in June of conspiring to commit espionage for China.

A fluent Mandarin speaker, Mallory was struggling financially when he was contacted via a LinkedIn message in February 2017 by a Chinese national posing as a headhunter, according to court records and trial evidence.

The individual, using the name Richard Yang, arranged a telephone call between Mallory and a man claiming to work at a Shanghai think tank.

During two subsequent trips to Shanghai, Mallory agreed to sell U.S. defense secrets - sent over a special cellular device he was given - even though he assessed his Chinese contacts to be intelligence officers, according to the U.S. government’s case against him. He is due to be sentenced in September and could face life in prison.

While Russia, Iran, North Korea and other nations also use LinkedIn and other platforms to identify recruitment targets, the U.S. intelligence officials said China is the most prolific and poses the biggest threat.

U.S. officials said China’s Ministry of State Security has“co-optees” - individuals who are not employed by intelligence agencies but work with them - set up fake accounts to approach potential recruits.

They said the targets include experts in fields such as supercomputing, nuclear energy, nanotechnology, semi-conductors, stealth technology, health care, hybrid grains, seeds and green energy.

Chinese intelligence uses bribery or phony business propositions in its recruitment efforts. Academics and scientists, for example, are offered payment for scholarly or professional papers and, in some cases, are later asked or pressured to pass on U.S. government or commercial secrets.

Some of those who set up fake accounts have been linked to IP addresses associated with Chinese intelligence agencies, while others have been set up by bogus companies, including some that purport to be in the executive recruiting business, said a senior U.S. intelligence official, who requested anonymity in order to discuss the matter.

The official said “some correlation” has been found between Americans targeted through LinkedIn and data hacked from the Office of Personnel Management, a U.S. government agency, in attacks in 2014 and 2015.

The hackers stole sensitive private information, such as addresses, financial and medical records, employment history and fingerprints, of more than 22 million Americans who had undergone background checks for security clearances.

The United States identified China as the leading suspect in the massive hacking, an assertion China’s foreign ministry at the time dismissed as


About 70 percent of China’s overall espionage is aimed at the U.S. private sector, rather than the government, said Joshua Skule, the head of the FBI’s intelligence branch, whose responsibilities include ensuring the flow of intelligence to the bureau's counter-espionage operations.

"They are conducting economic espionage at a rate that is unparalleled in our history," he said.

Evanina said five current and former U.S. officials - including Mallory - have been charged with or convicted of spying for China in the past two and a half years.

He indicated that additional cases of suspected espionage for China by U.S. citizens are being investigated, but declined to provide details.

U.S. intelligence services are alerting current and former officials to the threat and telling them what security measures they can take to protect themselves.

Some current and former officials post significant details about their government work history online - even sometimes naming classified intelligence units that the government does not publicly acknowledge.

LinkedIn "is a very good site," Evanina said. "But it makes for a great venue for foreign adversaries to target not only individuals in the government, formers, former CIA folks, but academics, scientists, engineers, anything they want. It’s the ultimate playground for collection."

© (c) Copyright Thomson Reuters 2018.

©2018 GPlusMedia Inc.

Login to comment

Interestingly I had someone contact me on Linkedin requesting an interview to ask about certain policies at my company for 30,000 yen. I declined.

1 ( +3 / -2 )

With Trump the Chump steering America, nobody is going to take this talking seriously.

-7 ( +2 / -9 )

With Trump the Chump steering America, nobody is going to take this talking seriously

So refreshing to see the masses reacting

2 ( +6 / -4 )

Reckless: I've had a few like that (although usually from "western" accounts), claiming to be from subcontractor agents and asking things totally unrelated to me scope of work as published on Linkedin. I would say that more than half the unsolicited requests I get there are from Chinese manufacturing companies...could be legit but some of the accounts have very strange histories etc. and my company is probably fairly attractive for industrial espionage type activities.

1 ( +2 / -1 )

They learned it from America...... Cmon, you should be proud of your student, America!

-7 ( +0 / -7 )

I've been asked for interviews where it is common to provide challenging technical questions to be answered. But sometimes the questions are extremely specific, clearly not just "what if" scenarios.

I've kept my linkedin profile fairly generic and not connected to any other online accounts, anywhere, but people I've worked with, in my network, don't always do that. We don't say what we've actually done, but if you list the commercial tools used in an experience section, then is a pretty clear as to the sort of work.

A friend works at a Chinese University teaching cyber security. He has lots of stories. After looking for a position in the USA for 2 yrs, he got that offer and took it. Claims that everything he does is tracked and monitored. He is only allowed to have 1 bank account, for example. He's never bothered to learn Manderin, which seems odd to me for all the years he's spent in China now - over 5. All his students are required to turn in assignments in English. Most can write English, but not speak it. I guess that's good enough to gather intel over the internet.

1 ( +3 / -2 )

Why would anyone still believe anything this government says?

-1 ( +3 / -4 )

China is hurting. Why not squeeze the last bit of info out of the US before they get blocked. Isn’t this the way they got all their other technology?

2 ( +3 / -1 )

They need to change their names to Russian names and the US government will have no problem with it.

1 ( +4 / -3 )

China is waging what they themselves call an "all fronts war" that combine military, economic, strategic, diplomatic, cultural aspects against all western nations with the United States being the most prominent target. China influences Hollywood to make movies to paint China as a friendly nation, has established Confucious Institutes at numerous US universities to "brainwash" American students under the guise of spreading the Chinese culture. Every news website with a discussion forum is loaded with real, and not so real, posters whose sole purpose is to advance China's position and denigrate the US and it's allies. Sound familiar?

1 ( +2 / -1 )

talaraedokkoSep. 1 08:12 pm JSTChina is hurting. Why not squeeze the last bit of info out of the US before they get blocked. Isn’t this the way they got all their other technology?

During the Labor Day weekend in 2016, Russia hacked the electoral college networks to 'test the fields' before they struck full force that November in favor of Douchebag Traitor. China also hacked a textile mill in New England to steal manufacturing secrets but they weren't successful.

-1 ( +2 / -3 )

Recruitment is a tool to vacuum up technology. Nothing new, except web makes it easier.

Foreign controlled firms act as the agent or agents target firms where infiltrators get access to trade secrets, patent proposals, and proprietary code.

0 ( +0 / -0 )

Well we can look at how the geezers from Communist China treat the TIBETANS and the country of Tibet....with morally upstanding respect of course?

Even companies doing business in Communist China dare not mention Tibet as a separate entity or suffer sever punishment.

Bulldozing Washington DC and other places of Western power to the ground would give these geezers immense satisfaction.

2 ( +2 / -0 )

Login to leave a comment

Facebook users

Use your Facebook account to login or register with JapanToday. By doing so, you will also receive an email inviting you to receive our news alerts.

Facebook Connect

Login with your JapanToday account

User registration

Articles, Offers & Useful Resources

A mix of what's trending on our other sites