Skip to content

Security1 publisher3 min readPublished

APT40's front company hires off public job ads, and that is the scaling problem

A leaked candidate list obtained by the Financial Times shows Hainan Xiandun recruiting translators through ordinary job adverts. Chinese espionage capacity grows on a labour-market curve, not a clearance queue.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • The Financial Times investigation acquired a "leaked list of candidates compiled by security officials in the region" and contacted potential translators who had responded to job adverts at Hainan Xiandun.
  • Hainan Xiandun is a front company that provides translation services for the Chinese cyber espionage group known as APT40.
  • APT40 has carried out operations on behalf of the PRC's Ministry of State Security (MSS) Hainan State Security Department (HSSD).
  • Candidates were not told what work they would be doing, but the application process included translation tests on "sensitive documents obtained from US government agencies" and open source research into potential intelligence targets.
  • One candidate told the Financial Times "it was a very weird process", and another said "it was very clear that this was not a translation company".

Compiled by The WatchSomething wrong?How this is made

Why it matters

The Financial Times obtained a leaked list of job candidates compiled by security officials in the region and used it to contact people who had answered translation adverts placed by Hainan Xiandun, the front company that supplies translation services to the Chinese espionage group APT40 [1][2]. What matters for defenders is not the tradecraft but the hiring channel: a group that has run operations for the Ministry of State Security's Hainan State Security Department was sourcing staff through openly advertised jobs, and was still doing so after US prosecutors named it [3][6][7].

According to the FT reporting as summarised by Seriously Risky Business, applicants were not told what the work would be [4]. The selection process included translation tests on sensitive documents obtained from US government agencies, plus open source research into potential intelligence targets [4]. One candidate described "a very weird process"; another said "it was very clear that this was not a translation company" [5].

In July 2021 the US Department of Justice indicted three HSSD officials and a Hainan Xiandun hacker over a campaign against dozens of companies, universities and government entities in the United States and abroad between 2011 and 2018 [6], eight calendar years of intrusions [18]. Recruitment for the front companies continued after that [7][19].

Set that against the Western staffing model. Western agencies also recruit from universities, but candidates understand what they are applying for, and selection and vetting are rigorous [8]. Seriously Risky Business argues the loose vetting here is fit for purpose: the PRC steals intellectual property at scale, and rigorous vetting slows things down [9]. Alex Joske, an independent researcher on MSS and Chinese Communist Party espionage, told the newsletter this looks strange only from outside, being "typical of the way [Chinese] bureaucracy works in general", and that "the nature of cyber adds to that" [10]. His practical point: "it is not like a Chinese student will look up [the company's] name on Intrusion Truth before taking a job" [11].

The contractor layer is long-standing rather than improvised. Joske said it is very common for every significant PRC ministry to run its own companies [12], and that a late-1990s divestiture push saw the MSS close 112 companies and hand another 144 to other agencies, including government trade and asset-management bodies [13]. That is 256 firms touched in a single reorganisation [14]. He said MSS investment in links to universities and cyber security researchers goes back decades, with evidence of embedding "from the very beginning" [15], and cited Shanghai Jiaotong University's cyber security school, whose founder was a former MSS vice minister and which was subsequently linked to the Operation Aurora hacks of the late 2000s [16]. Antony Blinken said something similar in 2021, describing an MSS-fostered "ecosystem of criminal contract hackers who carry out both state-sponsored activities and cybercrime for their own financial gain" after the mass compromise of Microsoft Exchange servers [17].

The consequence is a different growth curve. If operational support capacity is bought from contractors advertising in the open labour market, headcount is not gated by a vetting pipeline of the kind Western services run [8]; it is gated by how many local applicants a front company can test and onboard [4]. Blinken's statement framed that ecosystem as something to be stopped [17], while recruiting carried on after the indictments [7][19], which reads less like deterrence than like a cost already priced in.

Worth watching: whether the same adverts reappear under new corporate names, whether Western enforcement starts targeting recruiters, universities and intermediaries rather than only named operators, and whether any of the translation test material surfaces as evidence of what was already inside the pipeline.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories