Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
China

How a Chinese Agent Used LinkedIn to 'Lure' American Targets (bbc.com) 61

Today the BBC told the story of Jun Wei Yeo, "an ambitious and freshly enrolled Singaporean PhD student" who was gradually recruited by Chinese intelligence.

Yeo "would end up using the professional networking website LinkedIn, a fake consulting company and cover as a curious academic to lure in American targets." Some of the targets that Yeo found by trawling through LinkedIn were commissioned to write reports for his "consultancy", which had the same name as an already prominent firm. These were then sent to his Chinese contacts. One of the individuals he contacted worked on the U.S. Air Force's F-35 fighter jet programme and admitted he had money problems. Another was a U.S. army officer assigned to the Pentagon, who was paid at least $2,000 (£1,500) to write a report on how the withdrawal of US forces from Afghanistan would impact China... According to the court documents, his handlers advised him to ask targets if they "were dissatisfied with work" or "were having financial troubles"...

In 2018, Yeo also posted fake online job ads for his consulting company. He told investigators he received more than 400 CVs with 90% of them coming from "US military and government personnel with security clearances". Some were passed to his Chinese handlers... Dickson Yeo does not appear to have got as far with his contacts as his handlers would have liked. But in November 2019, he travelled to the U.S. with instructions to turn the army officer into a "permanent conduit of information", his signed statement says.

He was arrested before he could ask.

The 39-year-old now faces up to 10 years in prison for being an "illegal agent of a foreign power" — but the article notes he was "aided by an invisible ally — the LinkedIn algorithm.

"Each time Yeo looked at someone's profile it would suggest a new slate of contacts with similar experience that he might be interested in..."
This discussion has been archived. No new comments can be posted.

How a Chinese Agent Used LinkedIn to 'Lure' American Targets

Comments Filter:
  • ....is that you don't TELL PEOPLE ABOUT BEING IN FIGHT CLUB ! (paraphrased).

    What's going on over there ? Your Opsec is awful.

    They make you do stupid nonsense like polygraph for a TS, yet you're fine with posting all your shit up on LinkedIn ?

    Security theater.

  • by pieisgood ( 841871 ) on Sunday July 26, 2020 @11:06PM (#60334761) Journal

    Generally for these kinds of secrets the individuals involved are consistently monitored for things like "financial trouble", an agency is slipping somewhere if these kinds of things are happening in the first place.

    • One target had been in the army, with some desk job at the Pentagon. People who have been in the army, need jobs and gigs too, and LinkedIn is where the recruiters are.

      The other target mentioned had done something related to the F-35. Recruiters for Lockheed Martin jobs use LinkedIn too, including for some pretty sensitive jobs. Unfortunately Lockheed is on the other side of Dallas from me, so rush hour traffic would be a bitch. :)
      I'm not at all surprised that someone who used to work for Lockheed is on LinkedIn. Heck, most of the white-collar workers currently at Lockheed are probably on LinkedIn.

      Actually, when I need to contact a counterpart at another company, LinkedIn is a good place to find their name if I don't already know someone at that company through a professional organization. The specific details of our work we keep quiet, our resume we flaunt just like you would if you had impressive experience.

      Heck, come to think of it, several of the people I know from the professional organizations don't state what company they work for because we want to be able to share techniques, ideas, and experiences without obviously associating those with particular companies. (Though I can normally guess - for example the team that red-team hacks cars - there is only ine major car company in town). Because we do tend to be hush-hush, it wouldn't be that unusual for someone in a hush-hush field to be somebody you haven't heard about. A spy could very easily come to our meetings and get useful information. We try to be aware of that, balancing that with sharing information with fellow good guys.

      • But you can be sure the intelligence agencies are also looking out for suspicious activity related to LinkedIn, which is where this kid got unstuck. He probably fine-tuned his fake job adverts based on the data he was getting as feedback, but data analysis could also be used by the opposing intelligence agencies to detect suspicious listings like his.

        • by rtb61 ( 674572 )

          It's like the amateur hour way of doing things. What you do is recruit criminals in the target country and use them to target the desired sources of actual information. You use the criminals to corrupt the targeted sources of information, generally making their acquaintance by attending venues of entertainment and intoxication. It creates a layer a, buffer between international contact sources and the most likely targets of information. In establishing a relationship, they can gauge the corruptibility of th

          • > What you do is recruit criminals in the target country

            Putting your trust in criminals often turns out to be a bad idea.
            Better to convince a reliable person that your team is the good guys, or simply buy someone who is trusted.

            • > It's like the amateur hour way of doing things.

              Yes, that is why this one got caught. You do not read about the others.

              You do not use criminals. Just people that are a bit pissed off with the world. Would not be any of those at Slashdot.

    • But they caught him, before he could get anywhere.

      One of the flaws in the logic here and something that should make this less scary is that this kid was merely using LinkedIn to automatically suggest contacts to him. The good news is that the counter-intelligence people can run analysis on the same data and look for suspicious contacts. In this case I'm guessing the fake job advert was a dead giveaway. This amateur thought he struck it rich with the number of people who applied to it, but that's all data th

  • by backslashdot ( 95548 ) on Monday July 27, 2020 @12:09AM (#60334861)

    Havent heard the details of the case, but it sounds like they should have known better in these instances. Somebody asks you to write a detailed report on your experiences in the military, that doesn't seem weird?

    That said I hope the CIA is doing the same thing. It's probably even easier.

    • Comment removed based on user account deletion
      • by AmiMoJo ( 196126 )

        I sometimes wonder if forced pledges of allegiance actually make people less loyal to that thing.

        In the UK we would find reciting a pledge at school quite weird, and in Germany I think it would actually be illegal due to this history of that kind of thing. So we should be able to compare allegiance levels with relatively similar demographics with a bit of effort.

        • by jbengt ( 874751 )
          The pledge of allegiance recited in US schools has been a controversial thing to some, since it reeks of pledging allegiance to a king or dictator, while the US is supposed to be based on individual rights and freedoms. It was first introduced in the late 1800's and has been modified and extended several times since then. There are brief histories in wikipedia and here. [smithsonianmag.com]

          Bellamy, a former Baptist preacher, had irritated his Boston Brahmin flock with his socialist ideas. But as a writer and publicist at the

  • by Ritz_Just_Ritz ( 883997 ) on Monday July 27, 2020 @12:25AM (#60334893)

    Other than being a lazy way to curate your work history, what use does it have? It's just another take on a social media site that's designed to profit from the personal information that you voluntarily give it. If you look at the ever growing number of political comments, pet videos, lame memes, etc, it's clear that the S/N is continuing to drop. Surely, you can think of better ways to spend your cycles if you're bored. And if people in the secret squirrel business are fool enough to participate, then I suspect they may need to find another line of work.

    • by drinkypoo ( 153816 ) <drink@hyperlogos.org> on Monday July 27, 2020 @09:29AM (#60335751) Homepage Journal

      Other than being a lazy way to curate your work history, what use does it have?

      The value of not having to enter your resume over and over and over and over and over... ahem, excuse me. The value of that is pretty high. When you're applying for twenty jobs in a day, not having to enter your resume data into twenty webforms is fairly important. I stopped even applying to jobs that wouldn't take my data from some other site. Too lazy to read my resume, and too incompetent to support a resume-absorbing API? Too shit a place to work.

  • by PhantomHarlock ( 189617 ) on Monday July 27, 2020 @12:30AM (#60334907)

    Does anyone actually use Linkedin for business networking / job hunting these days? It seems like every time they are in the news it's for something bad. Lots of people exploiting data and nation state actors gleefully vacuuming up information they can use to infiltrate other countries' industrial and government sectors.

    I deleted my account after a string of issues like this a few years ago. It wasn't very useful to me as what I do is fairly esoteric at this point and I'm happily self employed. I've had a round of job interviews only once in my life, the rest has come from word of mouth and actual personal networking from close contacts.

    • Recruiters love LinkedIn, and they frequently ask for yours.
    • by Ecuador ( 740021 )

      Recruiters love it, so if recruiters are useful in your field/area, it can be useful. For software engineering in the UK, last time I was looking for a new position, I tried directly applying to some companies and did not hear anything back - which I found quite odd given my CV. Giving in to a recruiter on LinkedIn, got me two great competing offers in less than a week. So YMMV, I don't like social networks, but if I have to use one for something specific I am not too bothered.

      • by bungo ( 50628 )

        I'll second that.

        I do not have any links other than recruiters, and I'm happy to add new recruiters to my network. I haven't got a job via Linkedin, but I always want to keep my options open. I do get a larger number of inquiries - some of them are even in the correct field!

        I don't have any friends, if a friend wants me to add them, I tell them that I'm protecting their privacy and mine.

  • AI consulting [perfectial.com] is when an AI consulting firm help a company harness AI technologies to improve their operations and increase their value. With the increasing implementation of AI technologies, the importance of AI consulting will continue to rise, and some companies predict that it will be a multi-trillion dollar industry within ten years.
  • Why take them to court? Set up a few honey pots, fake resumes, and keep them engaged. Use them to feed a steady stream of false information ....

    We used to be good at this, code breaking against Germany and Japan, double agents in French Resistance, fake army to mislead German airborne reconnaissance ....

    • Hopefully they did feed fake info to them for a bit. And after a year of misdirection, and maybe poor results, reel them in. But if the CIA/FBI is still good at what they do, we will never know.
    • Taking them to court is what you do when the other side figures out what you're doing.

      So, you get a Chinese agent. You turn them with the threat of jail time and use them to feed disinformation back. When the Chinese figure out that their agent has been turned, then you make an example of them. And you quietly tell all your turned agents that the only reason he's being prosecuted is that he leaked that he had been turned.
      • Hope to God our guys are that good. Still have the chops they had in WW II and cold war. Also make them doubt the ones that we have not caught.
  • Surely anyone who really does work in a sensitive government role should know better than not to give away information like this...

    Of course, as someone who doesn't work for government and doesn't have access to any classified information i would quite happily create a fake profile and make up some fake information if i could convince someone to pay me for it.

    • Surely anyone who really does work in a sensitive government role should know better than not to give away information like this...

      You're overestimating the intelligence of some government workers.

  • by OneHundredAndTen ( 1523865 ) on Monday July 27, 2020 @09:13AM (#60335711)
    And that's not a piece of software.

Remember, UNIX spelled backwards is XINU. -- Mt.

Working...