Security1 distinct publisher3 min readUpdated
A leaked candidate list obtained by the Financial Times shows Hainan Xiandun recruiting translators through ordinary job adverts. Chinese espionage capacity grows on a labour-market curve, not a clearance queue.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
A leaked candidate list obtained by the Financial Times shows Hainan Xiandun recruiting translators through ordinary job adverts. Chinese espionage capacity grows on a labour-market curve, not a clearance queue.
The Financial Times obtained a leaked list of job candidates compiled by security officials in the region and used it to contact people who had answered translation adverts placed by Hainan Xiandun, the front company that supplies translation services to the Chinese espionage group APT40 [1][2]. What matters for defenders is not the tradecraft but the hiring channel: a group that has run operations for the Ministry of State Security's Hainan State Security Department was sourcing staff through openly advertised jobs, and was still doing so after US prosecutors named it [3][6][7].
According to the FT reporting as summarised by Seriously Risky Business, applicants were not told what the work would be [4]. The selection process included translation tests on sensitive documents obtained from US government agencies, plus open source research into potential intelligence targets [4]. One candidate described "a very weird process"; another said "it was very clear that this was not a translation company" [5].
In July 2021 the US Department of Justice indicted three HSSD officials and a Hainan Xiandun hacker over a campaign against dozens of companies, universities and government entities in the United States and abroad between 2011 and 2018 [6], eight calendar years of intrusions [18]. Recruitment for the front companies continued after that [7][19].
Set that against the Western staffing model. Western agencies also recruit from universities, but candidates understand what they are applying for, and selection and vetting are rigorous [8]. Seriously Risky Business argues the loose vetting here is fit for purpose: the PRC steals intellectual property at scale, and rigorous vetting slows things down [9]. Alex Joske, an independent researcher on MSS and Chinese Communist Party espionage, told the newsletter this looks strange only from outside, being "typical of the way [Chinese] bureaucracy works in general", and that "the nature of cyber adds to that" [10]. His practical point: "it is not like a Chinese student will look up [the company's] name on Intrusion Truth before taking a job" [11].
The contractor layer is long-standing rather than improvised. Joske said it is very common for every significant PRC ministry to run its own companies [12], and that a late-1990s divestiture push saw the MSS close 112 companies and hand another 144 to other agencies, including government trade and asset-management bodies [13]. That is 256 firms touched in a single reorganisation [14]. He said MSS investment in links to universities and cyber security researchers goes back decades, with evidence of embedding "from the very beginning" [15], and cited Shanghai Jiaotong University's cyber security school, whose founder was a former MSS vice minister and which was subsequently linked to the Operation Aurora hacks of the late 2000s [16]. Antony Blinken said something similar in 2021, describing an MSS-fostered "ecosystem of criminal contract hackers who carry out both state-sponsored activities and cybercrime for their own financial gain" after the mass compromise of Microsoft Exchange servers [17].
The consequence is a different growth curve. If operational support capacity is bought from contractors advertising in the open labour market, headcount is not gated by a vetting pipeline of the kind Western services run [8]; it is gated by how many local applicants a front company can test and onboard [4]. Blinken's statement framed that ecosystem as something to be stopped [17], while recruiting carried on after the indictments [7][19], which reads less like deterrence than like a cost already priced in.
Worth watching: whether the same adverts reappear under new corporate names, whether Western enforcement starts targeting recruiters, universities and intermediaries rather than only named operators, and whether any of the translation test material surfaces as evidence of what was already inside the pipeline.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Recruitment for these front companies is still ongoing, suggesting that despite official attribution efforts from the US and other governments, the MSS does not care that people know.
The Financial Times investigation acquired a "leaked list of candidates compiled by security officials in the region" and contacted potential translators who had responded to job adverts at Hainan Xiandun.
Hainan Xiandun is a front company that provides translation services for the Chinese cyber espionage group known as APT40.
APT40 has carried out operations on behalf of the PRC's Ministry of State Security (MSS) Hainan State Security Department (HSSD).
Candidates were not told what work they would be doing, but the application process included translation tests on "sensitive documents obtained from US government agencies" and open source research into potential intelligence targets.
One candidate told the Financial Times "it was a very weird process", and another said "it was very clear that this was not a translation company".
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One secondary account of a single primary investigation, plus a named expert
All claims trace to one newsletter that summarises a Financial Times investigation it did not conduct, supplemented by direct quotes from independent researcher Alex Joske and a citable public record (the July 2021 DOJ indictment, Blinken's Exchange statement). The anchor artefact - a leaked candidate list compiled by regional security officials - is not inspectable in the cluster, and no second publisher corroborates it.
Practice documented and continuing, but only at one named front company
There is concrete evidence the recruitment model is in live use - candidates responded to real adverts, sat tests on US government documents, and the publisher states recruitment for these front companies is still ongoing after formal US attribution. Scale beyond Hainan Xiandun is asserted by analogy (ministry-run companies generally, 256 MSS firms in the late-1990s divestiture, decades of university links) rather than counted, so measured adoption stays in the middle of the range.
Framing extrapolates a scaling thesis from one company's hiring
The reporting itself is hedged ('one lesson may be', 'may simply be appropriate'), but the cluster's headline framing - that Chinese espionage capacity grows on a labour-market curve - generalises from a single front company's advert-based recruiting with no counts of candidates, adverts or comparable firms. The 'no way we can credibly impose costs' conclusion is one researcher's judgement presented as the takeaway. Modestly overstated relative to the supplied evidence rather than sensationalised.
Disclosed sponsorship plus a source promoting a forthcoming book
The newsletter discloses at the top that it is supported by the Hewlett Foundation's Cyber Initiative and AustCyber and by corporate sponsors CyberCX and Proofpoint - security vendors whose commercial interest aligns with a heightened-threat narrative. Its principal expert is described as the author of an upcoming book on the MSS, giving him a promotional interest in MSS-centric framing. Disclosure is explicit, which limits the concern, but the incentive structure is visible and one-directional.
Moderate: verifiable anchors, single-publisher chain, unmeasured scale
Confidence is held up by a checkable indictment, a named on-the-record expert and internally consistent reporting, and held down by full reliance on one publisher relaying another outlet's investigation, an unexaminable leaked list, no Chinese-side response, and no quantification behind the scaling thesis.
invest
China's crude imports fell to a 2016 low, and the self-sufficiency bill looks cheaper1 distinct publisher
invest
556 wallets, 78,496 bets: Polymarket's insider problem now has a denominator1 distinct publisher
invest
Jane Street's $990M in Bitcoin ETFs looks like inventory, not conviction1 distinct publisher
invest
Washington licenses private hacking, and hands the contractor the liability1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026