This website uses cookies

Read our Privacy policy and Terms of use for more information.

In partnership with

Weekly Intelligence for a Digital World

INTELLIGENCE BRIEF // DECLASSIFIED

Briefing No. 106
October 6, 2026

Table of Contents

Note From Eric

Welcome to October and National Cybersecurity Awareness Month!

For the next few weeks, we’ll spend some extra time examining our own cybersecurity, learning how to take the advantage back from cyber spies and criminals, and preparing for what comes next. Because just as we head into the holiday season, cybercriminals enter one of their busiest hunting seasons of the year.

This is the month to tighten the defenses, question what we trust and prepare before the attacks arrive. As I’ve said many times: luck is for lottery winners.

Let’s get to work.

—Eric

Title Story

THE SPY WHO PAID FOR THE RESEARCH

The best spy operation is the one where nobody thinks they’re spying.

There is no dead drop. No clandestine meeting in a dark parking garage. Nobody photographs classified documents or stuffs cash into an envelope. Instead, somebody offers to fund your research.

Last week, Britain’s domestic intelligence service, MI5, issued an extraordinary public warning about the China General Technology Research Institute, or CGTRI. According to MI5, the institute has “very strong ties” to China’s Ministry of State Security (MSS) and its primary purpose is to fund academic research that directly improves the MSS’s technical capabilities for espionage.

The research was targeted to pursue critical development of technologies like artificial intelligence, cybersecurity, covert communications and steganography. MI5 says more than 100 UK-linked academics have contributed to research projects ultimately funded by the MSS through CGTRI.

Like any good spy operation, most researchers likely had no idea Chinese espionage was actually paying the bill.

Steganography is the practice of concealing a secret message, file, or image within another ordinary, non-secret file or physical object to hide the very existence of the communication.

THE RECRUITMENT THAT DOESN’T LOOK LIKE RECRUITMENT

When people hear the word “espionage,” they tend to imagine someone stealing secrets. I spent years hunting spies for the FBI, and the reality is usually far more subtle. An intelligence officer doesn’t begin a recruitment by asking someone to betray their country.

Instead, you build trust. You establish a legitimate reason for the relationship. You learn what the target knows, what the target wants and what the target might eventually provide. Then you move incrementally toward your real objective.

The operation described by MI5 takes that old tradecraft and gives it an institutional disguise. A researcher doesn’t necessarily need to think of himself or herself as an intelligence source at all. The work can be legitimate. The collaboration can be legitimate. The resulting research can be publishable and professionally valuable. The problem is who sits at the end of the money trail and what that organization ultimately intends to do with the work.

MI5’s warning does not accuse more than 100 academics of knowingly participating in espionage. In fact, MI5 specifically warns that researchers may not know CGTRI is funding the Chinese research projects to which they contribute.

Intelligence services have always exploited legitimate relationships and human incentives. Money, ideology, compromise and ego are the classic motivations for recruiting a spy, but a sophisticated intelligence operation doesn’t always require a recruited spy. Sometimes the target can continue doing exactly what he or she was already doing while an intelligence service quietly benefits from the result.

FOLLOW THE MONEY

MI5 is now advising British academic institutions to review ongoing or planned collaborations involving CGTRI and telling researchers to determine the ultimate funding source behind collaborations with Chinese institutions.

I would take that advice several steps further.

This isn’t simply a university problem. Companies should be asking the same questions about investors, vendors, joint ventures, subcontractors, research partnerships and technology-development agreements. In a world where intellectual property, proprietary data and artificial intelligence models can be worth more than physical assets, understanding who sits behind a business relationship has become part of protecting the business itself.

Before accepting the investment, signing the partnership or sharing the research, find out who is actually paying. Determine who controls the organization. Understand who receives the data, code, prototypes and resulting intellectual property. Look beyond the company immediately across the table and identify the entities sitting behind it.

I call it The Ultimate-Funder Test.

Follow the money all the way to the end.

Because in espionage, the name printed on the check may be far less important than the person standing behind the bank account.

Breach of the Week

110 TERABYTES OF EXTORTION

Ransomware used to have a wonderfully simple criminal business model. Break into a company, encrypt its files and demand money for the key.

Then criminals figured out they could make considerably more money by stealing the files first. Double extortion turned medical records, employee information, customer data and corporate secrets into bargaining chips.

Last week, U.S. and European authorities struck KillSec, a ransomware and extortion operation accused of breaking into organizations, stealing sensitive information and threatening to publish or sell it unless victims paid.

Authorities arrested several people, seized infrastructure and took control of KillSec’s leak site, securing at least 110 terabytes of data. Operation KillSwitch is investigating around 1,000 suspected attacks worldwide, roughly 500 of which investigators have so far identified as successful.

One alleged attack shows how ugly the model can become. According to the Justice Department, KillSec posted data belonging to a Puerto Rico victim and started a seven-day countdown. When the victim didn’t pay, the group allegedly released approximately 180 gigabytes of stolen patient data onto the dark web.

A company can have excellent backups, restore every encrypted server and still face a catastrophe. Once sensitive information leaves the network, restoring the network doesn’t bring it home.

Ransomware planning must therefore extend beyond recovery. Companies need the ability to isolate systems, preserve evidence, engage counsel and communicate before criminals put a countdown clock next to their name.

Tip of the Week

THE FBI IS CALLING. OR IS IT?

I spent years in the FBI, so allow me to clear up something that apparently needs clearing up.

The FBI is not going to call you and demand money.

FBI Newark recently warned about a particularly convincing evolution of the government-impersonation scam. Criminals are spoofing FBI field-office telephone numbers, using the names of actual FBI employees and even staging video calls with backgrounds designed to resemble FBI offices.

That creates a problem with one of the oldest pieces of scam advice: look up the person and make sure the person is real. A sophisticated scammer already knows you might do that. The name the criminal gives you may belong to an actual federal employee. The “person” you end up talking to online may be an AI deepfake avatar.

The better approach is to verify the contact independently. If someone claiming to represent the FBI contacts you unexpectedly, don’t call the number the person provides, click a link in an email or trust the number appearing on caller ID. Find the field office yourself through FBI.gov and call the official, published number. Tell them someone claiming to be an FBI employee contacted you and ask them to verify the contact or claimed case.

In other words, don’t just verify the agent.

Verify the case.

And if the supposed FBI agent wants gift cards, cryptocurrency, a wire transfer or money to make an arrest warrant disappear, tell them to go pound sand.

AI Watch

WELCOME TO THE AI COMMITTEE. IT DOESN’T EXIST

Imagine receiving an invitation to participate in an important discussion about artificial intelligence policy. It appears to come from someone you recognize, the subject fits your expertise, and there’s nothing obviously malicious.

So you reply.

That reply is what the attacker wanted.

Proofpoint recently detailed a cyberespionage campaign it attributes to China threat actor TA419. The attackers impersonated prominent technology and policy figures while targeting people involved in U.S. AI policy. Rather than immediately sending malicious links, they first established credibility and waited for the target to engage. Only then did the conversation progress toward fake reports, fictitious committees and counterfeit Microsoft 365 authentication pages.

I recognize the technique because it is classic intelligence tradecraft. You don’t begin a recruitment with the ask. You establish credibility, create rapport and give the target a reason to continue the conversation.

Rapport first. The ask second.

AI wasn’t the weapon here. It was the subject that made the approach believable.

From the Field

ACROSS THE POND: SPIES, LIES AND CYBERCRIME

I recently joined Tres Giles-Brown on Talk Radio Europe for a wide-ranging conversation about spies, cybercrime and the stories behind Spies, Lies and Cybercrime.

We talked about how old-school espionage tradecraft has moved online, why cybercriminals are so good at exploiting trust, and what all of us can do to become harder targets.

If you missed the conversation, you can listen here:

Continue the Mission

If you enjoyed this week’s newsletter, you’ll find even more inside my new book, SPIES, LIES, AND CYBERCRIME. Drawing on my years hunting spies for the FBI, it reveals how espionage, cybercrime, and AI-powered deception intersect—and what you can do to stay one step ahead.

Ready for the next mission?

Already read the book? A quick review on Amazon or Goodreads helps more readers discover it. Thank you for your support.

Please support my sponsors. It only takes a click - no purchase necessary!

The daily newsletter for finding AI tools worth trying

New AI tools launch every day. A few will change how you work. The rest will be forgotten by next month.

TLDR AI is the free newsletter that tells you which is which. Every morning, Anthropic and ex-Google engineers pick the new tools, updates, and open source releases worth trying, with a quick note on what each one does and who it's for.

You find the good ones early, without testing all of them.

One email, 5 minutes a day, read by 1.1M+ people. Get tomorrow's picks.

Know Someone Who’d Enjoy This?

If someone forwarded you this newsletter, join more than 4,500 readers every Tuesday for practical lessons from the worlds of espionage, cybercrime, artificial intelligence, and the human stories behind them.

A research grant. A ransomware countdown. A call from the FBI. An invitation to join an AI committee.

None sounds particularly threatening. That’s the point.

Technology changes, but the tradecraft remains remarkably consistent: establish credibility, create trust, then make the ask.

Know who you’re dealing with. Verify independently. And when something valuable is changing hands, ask who is really standing on the other side.

Until next week stay safe and keep thinking like a spy hunter.

Praemonitus Praemunitus!

Forewarned is Forearmed!

~Eric

Reply

Avatar

or to participate

Recommended for you

View all
caret-right