US Seizes 13 Fake Consulting Websites Involved in CCP Intelligence Recruitment
The U.S. Department of Justice and the FBI announced on June 10, 2026, that federal law enforcement seized 13 internet domain names. The DOJ stated that these domains were used to impersonate consulting firms, targeting current or former U.S. government and military personnel, especially those who hold or have held security clearances and have access to classified and sensitive government information.
The 13 domains are: centrikglobalconsulting.com, rightinfoconsult.com, finnaclevesperconsulting.com, cydfconsulting.com, pulsewaveglobal.com, catalystglobalsolutions.com, thehorizzen.com, geoindopacific.com, gpf-ina.org, safesec-group.com, thetruthinfo.com, Vandercons.com, and gulfpeace.org. The DOJ stated that the FBI will place takeover pages on the seized websites to warn visitors that the sites have been shut down, in order to disrupt related illegal activities and money laundering.
According to the affidavit supporting the seizure warrants, this operation has been ongoing since at least November 2023. The individuals involved established fake consulting firm websites, posting generic "consulting" and "analysis" positions on recruitment platforms and social media, claiming to recruit current or former U.S. government and military personnel to provide expertise to unidentified clients. Job titles included "Senior Analyst" and "International Affairs Consultant."
These websites are not crude phishing pages. The DOJ reported that the operators used aliases, fictional identities, stolen real identities, and AI-generated photographs to package the websites as normal commercial entities, using contracts and non-disclosure agreements to give the alleged consulting work a veneer of legitimacy. They also approached targets through platforms such as Upwork, Expertia AI, Hubstaff Talent, Wellfound, and Post Job Free, disguising intelligence recruitment as remote work, expert consulting, and research reports.
The key to the recruitment process is not "finding a job," but step-by-step testing of the targets' boundaries. Applicants were asked to write reports related to their work experience, and were subsequently pressured to provide "exclusive" information, "internal" information, or materials from "internal sources." The DOJ stated that these requests may violate the targets' official duties. Money flowed into the United States through online payment accounts under fictitious personal names, cryptocurrency, and overseas accounts to conceal the source of payments and the identity of the operators.
The U.S. Department of Justice stated in its briefing that these websites are "backed by suspected Chinese operatives." Daniel Wierzbicki, head of the Counterintelligence and Cyber Division at the FBI Washington Field Office, said that the Chinese government has long attempted to contact U.S. government employees through fake companies and fraudulent recruitment. Dominique Evans, head of the FBI Norfolk Field Office, stated that the Chinese government continues to pursue U.S. innovation, research, and sensitive information through deceptive techniques. The individuals involved have denied any foreign government involvement. The Chinese Embassy in Washington denied the allegations to the media, calling the so-called "Chinese spy threat" fabricated and slanderous.
This seizure corroborates previous public warnings from the Five Eyes alliance. In early June 2026, intelligence and security agencies from the United States, United Kingdom, Canada, Australia, and New Zealand warned that Chinese intelligence personnel are increasingly using professional platforms such as LinkedIn, Indeed, and Upwork, impersonating recruiters, consulting firms, or think tank project leaders, targeting government employees, military personnel, security clearance holders, journalists, think tank researchers, and those with access to sensitive policy information. Fake positions are typically packaged as foreign policy, defense, security, and geopolitical analysis, with the bait of easy side jobs, high pay, and remote consulting.
This is not a scam by a single group of websites, but a small exposed pipe of the CCP's overseas intelligence network. The CCP's overseas operations are never of a single form: there are fake consulting firms recruiting security clearance holders, hacker organizations long attacking governments, businesses, journalists, and dissidents, overseas police stations monitoring diaspora communities, "Operation Fox Hunt" packaging cross-border coercion as fugitive recovery, and United Front organizations turning community service into political infiltration. Although they appear scattered, they actually share the same institutional logic: the party-state treats overseas society as a space that can be managed, penetrated, intimidated, and bought off.
In 2024, the U.S. Department of Justice indicted seven APT31 hackers associated with the Chinese government, stating they had long attacked U.S. and British officials, lawmakers, journalists, dissidents, and businesses. In May 2026, Bronx, New York resident Lu Jianwang was convicted by a federal jury in lower Manhattan for illegally acting as an agent of the Chinese government and obstruction of justice for helping operate an overseas police station for China's Ministry of Public Security. In December 2024, Chen Jinping also pleaded guilty to conspiring to act as an illegal agent of the Chinese government in the same overseas police station case. In 2025, the DOJ also announced the sentencing of individuals related to "Operation Fox Hunt," a case involving tracking and harassing Chinese targets within the United States to force them to return to China.
When these cases are pieced together, the outline is clear: the CCP's overseas intelligence and influence system is not as simple as traditional "spies stealing secrets." It steals national security intelligence as well as technological and commercial secrets; it targets the U.S. government as well as Chinese communities, dissidents, scholars, journalists, and corporate employees; and it relies on the Ministry of State Security, Ministry of Public Security, military intelligence systems, as well as outsourced hackers, community leaders, fake companies, recruitment platforms, social media accounts, and online payment systems.
What the CCP excels at is disguising state operations as civic activities. Fake consulting firms claim to be commercial recruitment, overseas police stations claim to be overseas Chinese services, United Front organizations claim to be cultural exchanges, and transnational coercion claims to be anti-corruption fugitive recovery. Every layer is respectable, but once torn open, they are all part of the party-state machine. The openness of free societies, the convenience of professional platforms, the trust relationships of immigrant communities, and the employment anxieties of former government employees are all exploited by the CCP as entry points.
The FBI's seizure of 13 domains this time is merely cutting off a set of exposed front-end pages. The real system does not reside on these 13 websites, but in the CCP party-state system's continuous mobilization capacity for overseas resources. As long as Beijing continues to mix intelligence, United Front work, overseas Chinese affairs, public security, commerce, media, and academic exchanges into a single pot, similar websites will continue to appear under new names, avatars, platforms, and payment methods once a batch is shut down. Externally, the CCP claims it is being "smeared," while internally it never stops treating the entire world as its intelligence hunting ground.