In recent times, a small consulting company named Horizzen in Brisbane, Australia, has found itself in the midst of a bizarre situation, starting from mid-2025. The company began receiving resumes and calls from unknown job seekers applying for US positions that it had never advertised.
According to a report by The Guardian on Sunday, despite initially dismissing it as “cheap counterfeit”, Horizzen eventually realized the severity of the situation when a fake website, impersonating their identity, was shut down by US authorities in June of this year due to its suspected involvement in espionage activities linked to the Chinese Communist Party (CCP).
Unbeknownst to Horizzen, someone impersonated their company name, business address, and contact number, replicated their website content extensively, and created fake recruitment sites to lure job seekers.
The FBI investigation revealed that this website was one of the 13 fake consulting company sites shut down by the US Department of Justice in June. These sites were allegedly affiliated with CCP intelligence agencies, using bogus recruitment activities to gather sensitive information from the US government.
Some job seekers fell for the scam, sending detailed resumes and applications to Horizzen’s genuine Australian email address, believing both entities were the same company.
“It was shocking and unbelievable,” a Horizzen spokesperson told The Guardian. “What damage could it do to the company’s reputation? And what impact could it have on those who may have been misled?”
Further investigation by The Guardian found indications of transnational operations within related networks. According to the FBI, the fake Horizzen website was registered in India; another phony consulting company claimed to be based in Western Australia but had recruitment ads posted by someone in Thailand.
Another shut-down site, Catalyst Global Solutions (CGS), falsely portrayed itself as one of the leading companies in Washington, D.C., while its registered address was in Lahore, Pakistan. The FBI noted that CGS had recruited analysts and consultants specializing in “international relations” and “geopolitics” through Australian job portals, with one advert specifically seeking experts in the Indo-Pacific region.
Horizzen believes that the impostors intentionally copied a large amount of corporate information to make the fake companies appear legitimate, credible, and well-established.
“We cannot determine who created it or their intentions, but the extensive replication of information makes it hard to believe this was mere coincidence,” the company spokesperson stated.
The company also warned about the threat posed by artificial intelligence (AI) in lowering the barriers to creating fake websites and corporate identities.
“Regardless of whether AI was used in this incident, it enables fraudsters to rapidly and inexpensively, and on a frightening scale, produce convincing websites, communication content, images, and corporate identities,” Horizzen cautioned.
On June 10, the US Department of Justice announced the seizure of 13 domains. According to the sworn statement of the department, individuals had established at least 13 fake consulting company websites since November 2023, targeting current or former US government and military personnel with security clearances or access to sensitive government information.
The department stated that recruiters contacted applicants through social media and job platforms like Upwork and Wellfound, offering positions related to issues of interest to Beijing, primarily titled as “senior analysts” or “international affairs consultants.”
These websites used fake names, fabricated personas, stolen real identities, and AI-generated photos to create credibility. Recruiters enticed applicants with relatively high payments in exchange for research reports.
Subsequently, recruiters might request candidates to provide “exclusive”, “internal”, or sensitive information and shift communication to encrypted messaging platforms like Telegram.
Some payments were carried out through online payment accounts or cryptocurrencies. The department mentioned these methods were also utilized to obscure the true sources of payment and the identities of those involved.
Roman Rozhavsky, Assistant Director of the FBI’s Counterintelligence and Counterterrorism Division, highlighted that the seized fake consulting company domains indicated that “Chinese intelligence agencies are sparing no effort in attempting to deceive, recruit, or coerce current and former US security clearance holders using AI-generated content to elicit sensitive information.”
The Chinese Embassy in Canberra denied the allegations, with a spokesperson telling The Guardian, “The accusations by the US are entirely unfounded, purely slanderous and defamatory. China firmly opposes this.”
A June report by The Associated Press revealed that some leads in the cases stemmed from voluntary reports made by targeted individuals.
Daniel Wierzbicki, head of the FBI’s Counterintelligence and Cyber Division in Washington, D.C., mentioned in an interview, “We have gathered much of this information through interviews.”
“Those citizens who stepped forward had noticed something amiss,” he added. “They reported to us, ‘This is really unusual; we received payments in cryptocurrency or through some very uncommon online financial channels.'”
Wierzbicki stated that the FBI believes there are potentially similar sites with comparable purposes still operational and are seeking public assistance in identifying them.
In June, the Five Eyes Alliance consisting of Australia, Canada, New Zealand, the United Kingdom, and the United States issued a rare joint warning, stating that Chinese intelligence operatives were impersonating online recruiters or consultants, posing through false but seemingly legitimate “shell companies”, contacting targeted individuals via platforms like LinkedIn.
