CRBC News
Security

13 Domains Seized in Suspected Job‑Recruitment Espionage Targeting U.S. Personnel

13 Domains Seized in Suspected Job‑Recruitment Espionage Targeting U.S. Personnel
File photo of a website address bar.

On June 10, 2026, the DOJ and FBI seized 13 domains allegedly used in a suspected Chinese intelligence scheme that posed as consulting firms to recruit current and former U.S. government personnel. The operation reportedly used AI photos, fake identities, encrypted messaging (Telegram), and payment routing through foreign accounts or cryptocurrency to conceal its activity. Authorities replaced the sites with FBI warning pages and urge anyone contacted to report it through the FBI tip line.

On June 10, 2026, the U.S. Department of Justice and the FBI announced the seizure of 13 internet domains that prosecutors say were part of a sophisticated operation posing as legitimate consulting firms to obtain sensitive information from Americans — including current and former U.S. government employees and people with security clearances.

What Officials Say

Authorities tied the domains to suspected Chinese intelligence activity. Investigators say the sites advertised vague, high‑paying roles such as “Senior Analyst” or “International Affairs Consultant,” and recruited candidates through job platforms and social media to produce research reports that were in fact designed to extract insider or classified information.

Domains Seized

  • centrikglobalconsulting.com
  • rightinfoconsult.com
  • finnaclevesperconsulting.com
  • cydfconsulting.com
  • pulsewaveglobal.com
  • catalystglobalsolutions.com
  • thehorizzen.com
  • geoindopacific.com
  • gpf-ina.org
  • safesec-group.com
  • thetruthinfo.com
  • vandercons.com
  • gulfpeace.org

How The Scheme Allegedly Operated

  • Recruiting via job platforms and social media (investigators cited Upwork and Wellfound).
  • Use of AI‑generated profile photos and stolen or fabricated identities to build credibility.
  • Written contracts, confidentiality agreements, and payment offers for “research reports” to create the appearance of legitimacy.
  • Encrypted communications (for example, Telegram) and payments routed through foreign accounts or cryptocurrency to obscure origins.
  • Pressure on recruits to provide “exclusive” information that could violate professional obligations or security rules.

Who Was Targeted

Investigators say the operation focused on people likely to possess valuable information: current and former government employees, military personnel, and holders of security clearances. Court documents indicate the conspirators began establishing fake consulting companies as early as November 2023.

“These domain seizures offer a glimpse at how foreign actors can use promises of easy money to lure Americans into revealing sensitive or classified information,” Assistant Attorney General John Eisenberg said.

Aftermath And Advice

The seized domains now display FBI warning pages to prevent further use. Authorities urge anyone who interacted with these sites — or who received similar recruitment approaches — to report the contact to the FBI tip line, preserve any communications and payment records, and avoid sharing additional confidential information.

Security experts recommend extra caution when job offers are vague but unusually lucrative, rely primarily on encrypted apps for communication, request insider or confidential information, or come from organizations with generic branding and little verifiable history.

Bottom line: Treat unsolicited, high‑paying consulting offers that ask for sensitive information with extreme skepticism. If you were contacted, report it to the FBI and do not provide any further information.

Help us improve.

Related Articles

Trending