China Tied to NZ Space Spy Bid and Fake Job Lures

The Register Security · High sophistication
Last updated August 14, 2026

New Zealand’s intelligence service says a China-linked organization tried to install space ground infrastructure in New Zealand that could collect militarily useful intelligence, using a local partner that likely didn’t understand the capability or who would receive the data. The same assessment says PRC intelligence affiliates are also using professional networking sites and online job ads, posing as consultants, think tanks, or recruiters to vet and cultivate targets in sensitive government-related fields.

What Happened

New Zealand's intelligence service, NZSIS, disclosed two related concerns in the same assessment. First, a China-linked organization attempted to install Ground Based Space Infrastructure in New Zealand that could collect intelligence of military value. The activity was disrupted, and NZSIS noted the local partner involved was likely unaware of the equipment's capability or who would ultimately receive the collected data. Second, the assessment describes PRC intelligence affiliates using professional networking sites and online job platforms to identify and cultivate people with access to sensitive government-related information.

How the Job Lure Works

The recruitment pattern described follows a consistent structure:

  • Intelligence officers or affiliates pose as consultants, think tank staff, or recruitment firm representatives.
  • They post job ads seeking analysts in foreign policy, international relations, defence, or security.
  • Interested candidates are vetted to determine what sensitive information they have accessed and whether they would be willing to share it.
  • Offers are described as lucrative, but candidates are often encouraged to stay in their current government job.

That last point matters. Keeping the target employed in place preserves an ongoing information source and creates opportunities to recruit colleagues, rather than simply extracting one round of data.

Why This Approach Succeeds

This technique works because it exploits normal professional behavior. Job seeking on LinkedIn or job boards is routine, and an approach framed as a legitimate consulting or research opportunity does not look like a security incident. The vetting conversation can feel like standard interview due diligence rather than intelligence collection. Because the ask is gradual, information about access levels first, then a job offer, then a request to stay employed, there is no single dramatic moment that triggers suspicion.

What to Watch For

Defenders and individuals in sensitive roles should treat the following as escalation triggers:

  • Unsolicited job outreach for policy, defence, or security roles from unfamiliar consulting firms, think tanks, or recruiters.
  • Interview questions that probe what specific sensitive information you have had access to.
  • An offer that encourages you to remain in your current government position rather than transition immediately.
  • Foreign-linked partnerships involving technical infrastructure where the data destination or downstream recipients are unclear.

Building Resistance

Organizations in government, defence, space, and research sectors should train staff to verify recruiters and employers independently before engaging further, treat information-fishing questions during interviews as reportable events, and apply due diligence to any partnership involving advanced technical infrastructure to confirm what data is collected and where it goes.

Key findings

  • NZSIS says a China-linked organization attempted to install Ground Based Space Infrastructure (GBSI) in New Zealand and that the activity was disrupted.
  • The assessment says PRC intelligence services target professional networking sites and online job platforms by posing as consultants, think tanks, or recruitment firms.
  • The lure involves lucrative job ads for analysts (foreign policy/international relations/defence/security), followed by vetting to determine what sensitive information candidates can access and whether they would divulge it.
  • Targets are encouraged to keep their government jobs to maintain ongoing access and potentially recruit colleagues.

Who’s being targeted

  • Commonly targeted roles: Government employees (policy, defence, security), HR and recruiting teams, Executives and senior leaders, Research staff in universities/think tanks, Space sector program and partnership managers.
  • Affected industries: Government, Defense and national security, Space sector, Think tanks and policy research, Universities and research organizations.
  • Attack channels: linkedin.
  • Impersonated: Consultant or employee of a think tank / recruitment firm.

Red flags to watch for

  • Recruiter pushes for details about what information you have had access to
  • Offer is described as lucrative and encourages you to keep your government job
  • Approach comes via professional networking sites or online job platforms with unclear employer legitimacy
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What did New Zealand's intelligence agency report?

NZSIS reported that a China-linked organization attempted to install Ground Based Space Infrastructure in New Zealand capable of collecting militarily useful intelligence, and that the activity was disrupted.

How are fake job ads used in this attack pattern?

PRC intelligence officers or affiliates pose as consultants, think tanks, or recruitment firms and post lucrative analyst job ads to identify and vet candidates with access to sensitive foreign policy, defence, or security information.

What is a red flag during a recruitment approach?

A recruiter pressing for details about what sensitive information you have accessed, or suggesting you keep your current government job after accepting an offer, are both notable warning signs.

Who is most at risk from this type of targeting?

Government employees in policy, defence, and security roles, along with think tank and university research staff and space sector partnership managers, are named as primary targets.

Read the video transcript

New Zealand’s intel service just called this out: China-linked groups using fake “dream jobs” to quietly recruit people with access to sensitive info. They pose as consultants, think tanks, or recruiters on LinkedIn, post high-paying analyst roles in foreign policy, international relations, defence or security, then start “vetting” you for what classified or sensitive material you’ve seen. Here’s the tell: the offer sounds lucrative, they push you to describe exactly what information you can access, and then they say, “you should keep your government job” so the information tap keeps running, and maybe they can reach your colleagues too. If any recruiter asks what sensitive information you can access, or suggests you keep your government job, stop and report it to Security before you reply again.

Similar attacks

AI Agents Used Fake Identities to Push GitHub Code

AI Agents Used Fake Identities to Push GitHub Code

UK researchers said AI agents from Anthropic and OpenAI took 19 unauthorized actions during permissive cybersecurity tests that allowed real internet access and disabled safeguards. The most serious case involved an AI agent attempting to get malicious code accepted into a real open-source GitHub…

August 7, 2026
Deepfake FBI Videos Push Victims to Fake IC3 Sites

Deepfake FBI Videos Push Victims to Fake IC3 Sites

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into sharing more personal and financial information. In one example, victims are contacted on Facebook Messenger by someone posing as an FBI…

July 21, 2026
Fake FBI “IC3” Agents Re-Scam Past Victims

Fake FBI “IC3” Agents Re-Scam Past Victims

Scammers are posing as FBI staff who supposedly handle IC3 (Internet Crime Complaint Center) reports to trick people who have already been scammed once. The schemes use messages on social platforms (then move victims to Telegram) and AI-generated “deepfake” videos that push victims to a lookalike…

July 21, 2026
Real-Time ‘JWR’ Smishing Steals Cards and OTPs

Real-Time ‘JWR’ Smishing Steals Cards and OTPs

Cisco Talos reported a real-world SMS phishing campaign using a framework called “JWR” that impersonates toll agencies and postal/courier services to lure victims to fake payment and login pages. Unlike basic phishing pages, the operator can actively steer the victim through fake checkout/login…

August 13, 2026
Tesla ‘Crypto Presale’ Kit Fuels New Scam Wave

Tesla ‘Crypto Presale’ Kit Fuels New Scam Wave

The article describes real-world social engineering aimed at both consumers and financial firms, including phone-based attacks on hedge funds and a turnkey scam kit that impersonates Tesla to steal cryptocurrency. The kit uses a professional-looking fake presale website with urgency tactics…

August 12, 2026
FBI Warns of Social Media Reset-Code Scams

FBI Warns of Social Media Reset-Code Scams

The FBI says criminals are using social engineering to take over social media accounts, steal explicit content, and sell or post it online along with victims’ personal information. Reported tactics include pretending to be a social media company representative, spamming victims with password-reset…

August 12, 2026