- Why are you a target?
- Realise: the evolving threat
- Who is of Interest?
- How do Foreign Intelligence Services hide their identify?
- It will never happen to me - navigating tactics used at scale
- Recognise the Signs
- When reviewing jobs, look out for signs of suspicious adverts
- If applying, look out for signs of suspicious recruiter behaviour
- Report
- Remove and cease engagement
- Further guidance
This guidance is also available as a PDF: Applicant Beware - Who Is Recruiting You?
Spotting the Signs of Online Targeting
Why are you a target?
The UK is a target for Foreign Intelligence Services (FIS) who use a variety of methods to collect information that they believe will give them advantage over the UK. We have previously warned about the use of direct approaches over professional networking sites. A new method deployed at scale by FIS and third parties acting on their behalf is the use of online job platforms to attract applicants who have direct or indirect access to privileged information.
This guidance helps you to recognise suspicious adverts and recruiter behaviours and understand how you can protect yourself and your organisation by reporting concerns and ceasing engagement if something doesn't look right.
Foreign Intelligence Services are targeting a wide range of individuals, including current or former government staff, clearance holders, academics, think tank employees, private defence firm and consultancy employees and people with networks that provide them with access to these groups
The signs of suspicious adverts include:
- Company has limited online presence
- Job titles are generic and descriptions focus on privileged or unique insight and access
- Adverts and websites are of poor quality with spelling and grammatical errors, stock imagery and broken links
The signs of suspicious recruiters include:
- Communications may avoid video and encourage a move to encrypted messaging services or in-person meetings
- Pace of engagement escalates quickly, asking for ‘non-public’ information and details about your network
- Payment through unconventional means such as online payment platforms and cryptocurrency
- Research the advert and the company and do some due diligence
- If something doesn’t look right, report the suspicious advert to the online platform without delay
- If you hold a security clearance or are - or used to be - in a sensitive profession, you should inform the department’s security team
- Remove yourself from the recruiter’s network and cease engagement immediately
We recommend that you use the 4Rs when reviewing jobs adverts and throughout the application process:
- Realise the evolving threat,
- Recognise the signs of suspicious adverts and recruiter behaviours,
- Report your suspicions without delay, and
- Remove them from your online network and cease engagement.
Realise: the evolving threat
Our Think Before You Link campaign highlights direct approaches over professional networking sites by FIS with the goal of accessing information that harms UK national security and economic wellbeing. This type of approach still occurs. Our experts have identified that this tactic has evolved, and FIS are also posting job adverts to online platforms to attract applicants with direct or indirect access to sensitive and protected information. Thousands of suspicious job adverts have been posted to online job platforms, with more appearing daily.
Information sought by FIS may not necessarily be “classified” or an obvious target for espionage. Your insights and network of contacts can form valuable ‘pieces of the jigsaw’ when brought together with other information. Desirable information includes non-public, sensitive, or protected information on a wide range of topics, for example:
- UK HMG policy
- Geopolitical issues
- Western military capabilities and alliances
Applicants bear the consequences
This includes prosecution under the National Security Act (2023) for offences such as disclosing protected information or obtaining a material benefit from or assisting a Foreign Intelligence Service.
Who is of Interest?
Job adverts target a wide range of individuals:
- UK government and parliamentary employees
- Military employees
- Current or former clearance holders
- Academics
- Think tank employees
- Private defence firm and consultancy employees
- Former staff, and individuals who can provide access to the categories identified above
How do Foreign Intelligence Services hide their identify?
A variety of techniques are used to covertly post job adverts online, for example:
- Using headhunters and recruitment consultants to act on their behalf
- Setting up fake companies
- Spoofing legitimate companies
It will never happen to me - navigating tactics used at scale
When an unsolicited email arrives in your inbox, you are more likely to be suspicious as it can bear the hallmarks of a scam: urgency, high reward, too good to be true…
This evolving tactic is effective because you make the initial approach in applying for a job opportunity, and are unaware that you are at risk of engaging with a state actor.
In a legitimate recruitment process, the person you’re talking to assesses your background and quality of work because they are considering if you’re the right candidate. A FIS is assessing whether the access and information you could provide will be useful to them.
Case study
A UK-based consultant, Adam, applied for the following freelance analyst role advertised online by a consultancy company via a job seeker website:
- Part-time, remote working role with flexible hours
- Report writing and insights into international politics and geopolitical issues
- Desirable experience: freelance analyst, with experience of government, security or military sectors
- Payment: US$500 per project
- Company details referenced a consulting firm in Singapore
Adam provided a CV and cover letter detailing his professional experience and previous UK government employment. The email response from a company representative requested further information about his UK government experience. The company expressed the need for ‘exclusive information and high-quality analysis’ and interest in his government-related professional connections. Adam recognised the recruitment process as suspicious and reported it to the online platform and his department’s security team without delay.
Subsequent research indicated the ‘consultancy company’ was a Chinese Intelligence Service’s cover company who hid this using Western names and false information on a company website.
Recognise the Signs
They may (initially at least) look legitimate, but it is possible to spot the signs that job adverts and recruiter behaviours are suspicious, as illustrated by the graphics below.
When reviewing jobs, look out for signs of suspicious adverts

An accessible version can be found in the downloadable PDF
| Who is of interest? |
|
|---|---|
| Company Background |
|
| Account Posting Job |
|
| What is of interest? |
|
| Look and feel |
|
If applying, look out for signs of suspicious recruiter behaviour
- You spot and apply for an opportunity you find on an online job platform
- They quickly move communications onto an encrypted platform
- They may not use video capability and may claim connectivity issues in interview
- They ask questions about your suitability, probing about your access to sensitive information, including through your contacts
- They provide little information about the company or its clients
- They set a test report. Further report topics may focus on geopolitical and international matters. These may not relate to the services the company claims to offer
- The pace develops quickly, with increasing requests for non-public, exclusive and sensitive information in reports
- They ask you to gather information from your networks and connections
- They pay through unconventional means e.g. online payment platforms and cryptocurrency
- Payments from accounts which do not share the company name or clear links to the company
- Tiered salary, with ‘insider’ information garnering higher pay
- They may request in-person meeting in a non-Western country
Report
If you recognise signs associated with suspicious adverts and recruiter behaviours, report concerns to the online platform without delay. If you currently hold, or used to hold, a security clearance or have access to sensitive information (which can include academic research or bulk customer data) inform your department’s security team. Include the following details:
- URL of the profile
- Screenshot of the job advert and messages exchanged
- Brief explanation of why you think the approach is suspicious
- Any other relevant details
Remove and cease engagement
If you start an application process and notice suspicious recruiter behaviours, remove them from your network, and cease engagement immediately. Keeping malicious profiles in your network gives them legitimacy and puts colleagues and other contacts at risk.
General Tips
- Don’t advertise your security clearance publicly online – publicising this will mean you are of interest to malicious actors
- Don’t reveal details of sensitive job roles and/or projects, either publicly or to unknown contacts
- Don’t make your CV and /or social media profile information publicly available
- If absolutely necessary, only include details of your security clearance in direct correspondence with genuine contacts
- If it’s necessary to share sensitive details, such as a complete CV, or details of specific projects, do so one-to-one over trusted networks or in person with verified contacts
- Check your organisation's guidance and policy on the management of your digital footprint
- Use account settings to maintain your privacy and control who can view your profile (seek out the guidance on the relevant platforms you use). The more personalised these settings are, the more control users have over their information. NCSC has guidance on how to use social media safely
Further guidance
Keep up to date with National Protective Security Authority (NPSA) and National Cyber Security Centre (NCSC) guidance. It’s especially important to seek advice from your security department about declaring second jobs or consultancy work you may wish to undertake.
For further guidance on how you can help protect yourself and your organisation from this type of threat, download the Think Before You Link app.
Disclaimer
This document has been prepared by the National Protective Security Authority (NPSA). This document is provided on an information basis only, and whilst NPSA has used all reasonable care in producing it, NPSA provides no warranty as to its accuracy or completeness. To the fullest extent permitted by law, NPSA accepts no liability whatsoever for any expense, liability, loss, damage, claim, or proceedings incurred or arising as a result of any error or omission in the document or arising from any person acting, refraining from acting, relying upon or otherwise using the document. You should make your own judgment with regard to the use of this document and seek independent professional advice on your particular circumstances.
© Crown Copyright 2025