July 10, 2026 | Policy Brief
Suspicious Firms Still Seek Professionals With Military and Government Experience
July 10, 2026 | Policy Brief
Suspicious Firms Still Seek Professionals With Military and Government Experience
Suspicious consulting sites continue to target Western security experts despite U.S. efforts to curb suspected Chinese virtual espionage.
On June 30, China specialist Bill Hayton publicly asked on X whether a Singapore-based geopolitical advisory firm approaching Western security analysts was a Chinese intelligence front. This question led FDD’s Center on Cyber and Technology Innovation (CCTI) to discover a wider network of suspicious consulting websites.
This find comes less than a month after the FBI seized 13 fake consulting and nonprofit websites that it assessed Chinese intelligence had employed to recruit American security clearance holders. The newly discovered network of sites, all registered in 2026, exhibits similar profiles and behaviors, suggesting that Beijing is likely continuing the tactic unabated.
Geopolitical Advisories With Curious Features
CCTI reviewed ieass[.]com, the site Hayton flagged as suspicious, and found that it shares nearly identical infrastructure and registration patterns with two nearly identical sites — easi-policy[.]com and sgas-strategy[.]com — both of which likewise present themselves as geopolitical advisory firms. None of the three websites acknowledges any relationship to the others.
A fourth site, northriver-asia[.]org, shares some but not all of the same technical markers and shows the clearest signs of fabrication: It cites a UK charity registration number belonging to an unrelated London charity; it lists London and Washington phone numbers reserved by regulators for film, television, and advertising use; and it advertises “recent” publications dated months in the future. Most strikingly, the site’s “People” page appears to mistakenly include simplified Chinese-language text repeating the title of one of its claimed employees.
An Established Chinese Intelligence Playbook
The available evidence does not concretely tie the websites to Chinese intelligence. However, the websites’ profiles and behaviors match a well-documented Chinese intelligence tactic: Fictitious consulting firms and think tanks, often citing Singapore addresses, approach Western analysts online, offer paid “research” opportunities, and gradually solicit nonpublic information.
A decade ago, Singaporean national Dickson Yeo built similar front companies on LinkedIn to recruit intelligence assets, and CCTI previously exposed a Chinese operation targeting recently laid-off federal employees. In May, a House Select Committee on the Chinese Communist Party staffer was reportedly offered $10,000 by a purported Singaporean consultant to share information about the committee’s work and U.S. foreign policy. The FBI’s June seizure of websites engaged in similar activity notably followed a Five Eyes intelligence bulletin warning that China is targeting security clearance holders across allied countries through fake job postings.
U.S. Should Pair Proactive Outreach With Infrastructure Analysis
This case shows how quickly a single flagged website can be traced into a broader network, thereby enabling the disruption of malign infrastructure at its early stages — possibly before recruitment succeeds. Notably, the four domains were registered in March, May, and June of this year.
Washington should encourage this model: pairing open-source, social-listening tips from analysts and journalists with technical infrastructure analysis, such as shared nameservers, hosting patterns, and registration dates, to identify and disrupt related front operations early.
Notably, all four websites also used Lovable, an AI-enabled website builder. This pattern illustrates how AI can accelerate the creation of new malicious infrastructure, making early-stage disruption even more critical. Building partnerships with international governments and private-sector organizations, especially professional networking and freelancing platforms, in addition to hosting and website-building platforms, can help enable early-stage detection and disruption.
While disrupting infrastructure is necessary, it is not sufficient. The United States needs to continually brief current and former government officials, in addition to private and nonprofit professionals who frequently interact with government, such as think tank analysts, to build awareness of the threat and warn of the costs of witting cooperation.
Max Lesser is a senior analyst on emerging threats at the Foundation for Defense of Democracies’ (FDD’s) Center on Cyber and Technology Innovation (CCTI), where Thomas Crehan is an intern. For more analysis from the authors and FDD, please subscribe HERE. Follow FDD on X @FDD and @FDD_CCTI. FDD is a Washington, DC-based, nonpartisan research institute focusing on foreign policy and national security.