# US Department of Justice and FBI seize 13 domains used by China-linked hackers targeting Americans with security clearances

> Source: <https://cryptobriefing.com/doj-fbi-seize-china-hacker-domains/>
> Published: 2026-08-26 14:25:45+00:00

Photo: Towfiqu barbhuiya / Pexels

# US Department of Justice and FBI seize 13 domains used by China-linked hackers targeting Americans with security clearances

Federal authorities dismantled a network of fake consulting firms designed to recruit US security clearance holders for espionage using AI-generated content and stolen identities.

Federal authorities pulled the plug on 13 internet domains that were quietly doing some of the most old-school spy work imaginable, just dressed up in a digital costume. The US Department of Justice and FBI announced the seizure of domains linked to suspected Chinese state-sponsored operatives who were posing as legitimate consulting firms and nonprofit organizations to recruit Americans with government and military security clearances.

The operation wasn’t about breaking into servers or deploying malware. It was about breaking into people’s inboxes with fake job offers and cash incentives, then walking away with sensitive information.

## How the scheme worked

The seized domains, which included names like centrikglobalconsulting.com and rightinfoconsult.com, were designed to look like run-of-the-mill professional services firms. Behind the polished landing pages, though, the sites existed for one purpose: luring individuals who held US security clearances into sharing classified or sensitive information in exchange for payment.

The operators posted fake job opportunities that promised monetary compensation for writing “reports” and providing “consulting insights.” In practice, those reports were requests for the kind of information foreign intelligence services would pay handsomely for.

What made this campaign particularly modern was its use of AI-generated content to build convincing fake personas. The FBI noted that Chinese intelligence services have increasingly relied on AI-generated materials, from profile photos to biographical details, to create the illusion of real people running real businesses. These fabricated identities were then deployed on platforms like LinkedIn to make initial contact with targets.

The domain registrations spanned from November 2023 through October 2025, meaning this wasn’t a quick hit. It was a sustained, nearly two-year campaign operating right under the noses of the intelligence community.

## A counterintelligence problem, not just a cybersecurity one

Assistant Attorney General for National Security John A. Eisenberg framed the seizures as a warning about the persistent danger of foreign entities exploiting financial incentives to compromise Americans holding sensitive positions.

“These seizures illustrate the tactics foreign actors use to target those who hold or have held U.S. security clearances,” Eisenberg stated.

The timing also aligns with broader warnings from the Five Eyes intelligence alliance, the partnership between the US, UK, Canada, Australia, and New Zealand. The alliance has cautioned that similar recruitment tactics are being employed to target personnel across all five member countries, suggesting the campaign wasn’t limited to American targets.

## The AI dimension

The use of AI-generated content in espionage recruitment deserves its own moment. A fake LinkedIn profile with an AI-generated headshot, a plausible work history, and even AI-written thought leadership posts can now pass a casual smell test. The FBI has flagged this as an emerging signature method of Chinese intelligence services, and this case is one of the clearest public examples of the tactic in action.

**Disclosure:** This article was edited by Editorial Team. For more information on how we create and review content, see our

[Editorial Policy](https://cryptobriefing.com/editorial-policy/).
