INTELLIGENCEORIGINAL.COM · INTELLIGENCE & TECHNOLOGY · SEPTEMBER 16, 2026
E S P I O N A G E
The New Spies
They do not meet in Vienna. They do not exchange microfilm in train stations. They meet on LinkedIn. They build honeypots. They clone your voice. The tradecraft of the twenty-first century looks nothing like the movies — and is far more dangerous.
By the Intelligence Desk · September 16, 2026 · 18 min read
In February 2017, a retired CIA officer named Kevin Mallory received a message on LinkedIn. The sender identified himself as Richard Yang, a headhunter with connections to a prestigious Shanghai think tank. Mallory, fluent in Mandarin and struggling with significant personal debt, responded. Within weeks he was on a plane to China. Within months he was passing American defence secrets through a specially encrypted cellular device his new handlers had provided. In 2018, a federal jury convicted him of espionage. The sentence was twenty years.
There was no dead drop. There was no brush pass in a Moscow underpass. There was no exchange in a Vienna café. There was a job website, a direct message, and a man who needed money.
The Mallory case became, in intelligence circles, a kind of parable. Not because it was unusual. Because it was representative. The recruitment of foreign assets, the identification of vulnerabilities, the extraction of secrets — the fundamental activities of espionage have not changed. The environments in which they occur have changed entirely. The new generation of intelligence officer does not lurk in the shadows of Cold War Berlin. They operate inside the same digital architecture you use to book flights and order groceries. The tradecraft has migrated to the infrastructure of daily life, and most people have no idea it is happening.
“Chinese intelligence’s campaign on LinkedIn — contacting thousands of members at a time — is super aggressive. Other nations do it too. But China’s efforts are the most prolific and pose the biggest threat.”
— William Evanina, Director, US National Counterintelligence and Security Center
I. The Professional Network
How 900 Million Professional Profiles Became the World’s Largest Spy Database
LinkedIn was designed to help people find jobs. It turned out to also be extraordinarily useful for finding spies — or, more precisely, for finding people who might be persuaded to become them. The platform’s architecture, built to encourage detailed disclosure of professional history, security clearance levels, and institutional affiliations, amounts to a voluntary, continuously updated intelligence database of the Western world’s most sensitive workforce.
The Ministry of State Security — China’s civilian intelligence agency — grasped this early. By the mid-2010s, German, British, and American counterintelligence services were each, independently, identifying the same pattern: fake profiles presenting as academics, headhunters, and think-tank researchers, reaching out systematically to individuals in sensitive positions. The targets were not random. They were identified through the very information LinkedIn’s design encouraged them to share: their employer, their role, their specialisation, their career frustrations. A profile indicating a recently downgraded clearance, a lateral move suggesting professional disappointment, or a comment in a forum thread about budget cuts — any of these could mark someone as worth approaching.
The approach itself was patient and methodical. The fake profile would connect, then engage in weeks or months of legitimate-seeming professional conversation: comments on industry topics, sharing relevant papers, offering introductions. The ask, when it came, was typically framed as modest: a paper on an open-source topic, a consultancy arrangement, a speaking invitation. The financial element was introduced gradually, the escalation incremental. By the time the target was asked for something genuinely sensitive, they were embedded in a relationship, had already accepted payment, and faced the additional deterrent of their own prior cooperation.
Germany’s domestic intelligence service, the BfV, identified more than ten thousand fake LinkedIn profiles linked to Chinese intelligence activity directed at government employees and industrial researchers. The scale was not surgical. It was industrial. About seventy percent of China’s espionage effort, according to FBI assessments, targets the private sector — a recognition that the most valuable secrets of the twenty-first century are held by corporations and universities, not ministries.
II. The Trap
Honeypots, Ancient and Modern: The Art of the Deliberate Vulnerability
The word honeypot carries two entirely separate meanings in the intelligence world, and it is a measure of how the profession has evolved that both are now in active simultaneous use. The classical honeypot — a human being deployed as a lure, using seduction as the mechanism of entrapment — is as old as statecraft itself. The digital honeypot — a deliberately exposed and instrumented computer system designed to attract, observe, and profile attackers — is a product of the networked age. What unites them is the same fundamental principle: the trap that appears to be an opportunity.
The human honeypot — the swallow in Soviet parlance, the raven for male operatives — was a speciality of the KGB during the Cold War that successor services have never entirely abandoned. John Kiriakou, a former CIA case officer, has described it as “routine well into the late seventies and early eighties” — a tool so commonly deployed that counterintelligence services budgeted for it as a standard operational threat. The United States discontinued the practice around the Reagan administration. The Russians and, separately, Israeli intelligence continued to refine it.
In the digital age, the human honeytrap has migrated to social platforms. Pakistani intelligence services have systematically used Indian social media to target military personnel — a technique so consistent and well-documented that Indian counterintelligence has published public advisories. The approach is structurally identical to its analogue predecessor: a synthetic romantic relationship, developed over weeks or months, that creates emotional dependency before graduating to requests for information. The relationship develops over WhatsApp or Instagram rather than in a hotel bar. The fake persona is assembled from photographs sourced across the internet. The emotional leverage is identical.
“The emotional leverage is the same as it has always been. What has changed is the scale. A single handler can now manage forty romantic deception operations simultaneously. In 1975 that would have required forty officers.”
— Former Western counterintelligence officer, speaking on background
The digital honeypot operates on an entirely different logic — and has become, in the assessment of most serious security organisations, one of the most valuable defensive intelligence tools available. The concept is deceptively simple: build a system that looks like a real target — a corporate server, a government database, an industrial control interface — but is instrumented at every layer to record everything an attacker does. The attacker, believing they have found a real vulnerability, reveals their tools, their methods, their objectives, and in many cases the infrastructure they operate from.
The US Naval Postgraduate School in Monterey constructed a honeypot populated with documents chosen to appear attractive to foreign intelligence collection — papers on supercomputing, stealth technology, military budgets, and nuclear energy, carefully selected from open-source material. The site was seeded with links placed only where someone systematically scraping official library and faculty pages would find them — the behaviour of automated collection operations run by state intelligence services. The traffic patterns that followed were revealing: not just the volume and frequency of access, but the specific documents prioritised, the collection sequences, and the fingerprints left by the automated tools doing the scraping.
By 2026, the honeypot has evolved from a specialist research tool into a standard layer of enterprise defence. The 0ktapus threat group’s campaign against 130 firms demonstrated why this matters: defenders who captured early 0ktapus activity in honeypots had visibility into the phishing kit structure, the relay infrastructure, and the credential formats being tested — weeks before those same techniques reached production systems elsewhere. A firewall that blocks an intrusion tells you an intrusion was attempted. A honeypot that admits it tells you everything about the attacker.
III. The Synthetic Operative
The Face That Never Existed, the Voice That Was Never Spoken
Every espionage operation built on a fake identity faces the same foundational problem: the legend must hold. Building a convincing cover story has historically been expensive, time-consuming, and limited by the supply of real biographical material that could be quietly appropriated or fabricated. Artificial intelligence has demolished this constraint entirely.
In 2025, deepfake-as-a-service platforms became commercially available — tools offering voice cloning, video generation, and real-time face substitution to anyone willing to pay a subscription fee. According to analysis by Cyble, AI-powered deepfakes were involved in more than thirty percent of high-impact corporate impersonation attacks in 2025 alone. The technology does not require technical sophistication. It requires a credit card and a photograph.
In Hong Kong, a finance employee at a multinational firm was deceived into transferring twenty-five million dollars after participating in a video conference call in which every other participant — including individuals presenting as senior company executives — was a deepfake. The employee had been suspicious of an initial email and had requested the video call precisely to verify the instruction. The call satisfied his doubts entirely. None of the faces he was looking at belonged to real people.
This is corporate fraud, not state espionage — but the line between the two is increasingly theoretical. The same technology that enables a criminal to impersonate a CFO on a video call enables a state intelligence service to conduct a recruitment approach using a persona that not only has a detailed LinkedIn history and a plausible professional biography, but can sustain a live video conversation without any of the visual tells that previously allowed counterintelligence officers to identify synthetic identities. The operation that ensnared Kevin Mallory worked because a human pretended to be someone slightly different from who they were. The next Kevin Mallory may be approached by a person who does not exist at all.
IV. The New Tradecraft
Clifford Stoll’s Lesson, and What Came After
In 1986, Clifford Stoll — working as a system administrator at Lawrence Berkeley National Laboratory in California — noticed a seventy-five-cent accounting discrepancy in the lab’s computer usage records. A methodical man, he investigated. What he found, over the following months, was a hacker using Lawrence Berkeley’s network as a staging point to probe US military systems. The intruder, eventually identified as Markus Hess, was working for the KGB. Stoll’s account, published as The Cuckoo’s Egg, is the founding text of cyber counterintelligence — and his instinct to watch rather than immediately block, to document rather than simply expel, established the template for everything that followed.
Forty years later, the Stoll principle remains the foundation of the most sophisticated cyber defence operations. The modern intelligence officer working in this domain operates in a world of persistent threat actors — the designation APT, for Advanced Persistent Threat, is now the standard shorthand for state-sponsored intrusion groups. APT40 is a Chinese group focused on naval technology. APT28, known as Fancy Bear, is the GRU unit responsible for the Democratic National Committee breach in 2016 and multiple subsequent European operations. APT41 is unusual in that it appears to operate both as a state intelligence tool and as a criminal enterprise — compromising targets for espionage and then using the same access for financial gain.
What has changed in the last two years is the integration of artificial intelligence into offensive cyber operations. Credential spray attacks — in which attackers test stolen username and password combinations across large numbers of accounts — are now automated at a scale that makes manual defence essentially impossible. The student loan breach of early 2026, which exposed 2.5 million records, followed a pre-attack pattern visible in honeypot telemetry weeks earlier: automated enumeration of exposed API surfaces, fingerprinting of the environment, credential testing. The warning was there. The instrumentation to read it was not universally in place.
V. What Has Not Changed
The Enduring Human Variable
The image of the intelligence officer that persists in popular culture — the elegant figure in a Savile Row suit, ordering a martini in a Monaco casino — was never entirely accurate and is now essentially useless as a model. The skills the contemporary intelligence profession prizes most are, in rough order: facility with data analysis, proficiency in multiple languages, knowledge of network architecture and cloud infrastructure, an understanding of financial flows and corporate structures, and — still — the ability to build genuine human rapport. The last item on the list has not diminished in importance. It has simply moved further down the pipeline.
The most valuable intelligence of the twenty-first century is not where the missiles are pointed. It is how TSMC makes a three-nanometre chip, what Moderna’s mRNA platform can do that its competitors cannot, and what the next generation of battery chemistry looks like before the patent applications are filed. This intelligence does not live in government vaults. It lives in corporate networks, university servers, and the laptops of individual researchers who checked their LinkedIn messages this morning.
“The most valuable intelligence does not live in government vaults. It lives in corporate networks, university servers, and the laptops of researchers who checked their LinkedIn messages this morning.”
— Intelligence Original editorial assessment
The new spy operates in the cloud. They build systems that watch systems that watch other systems. They deploy synthetic personas capable of sustaining a relationship across months without ever physically existing. They use tools that automate at scale what previously required human judgment at every step. But somewhere at the end of every operation, there is still a person who made a choice they wish, in the end, they had not made. The technology has changed everything around that moment. It has not changed the moment itself.
Kevin Mallory was recruited because he was in debt and had skills that someone wanted to purchase. The Pakistani intelligence operative cultivating an Indian soldier online was exploiting loneliness, the desire for connection, the vulnerability of someone far from home who found unexpected warmth in their phone. The deepfake video call in Hong Kong worked because a finance professional trusted what he could see with his own eyes. The vulnerabilities that intelligence operations have always exploited — financial pressure, ideological dissatisfaction, loneliness, ego, and the simple human tendency to trust what appears trustworthy — are not susceptible to a software patch.
Primary sources: US National Counterintelligence and Security Center; FBI counterintelligence assessments; IPThreat.net honeypot telemetry report Q1 2026; Cyble Executive Threat Monitoring Report 2025; Hong Kong Police Force statement on the February 2024 deepfake fraud; US Naval Postgraduate School Department of Computer Science honeypot research; John Kiriakou, interview 2026; Stoll, Clifford, The Cuckoo’s Egg (1989); German Federal Office for the Protection of the Constitution (BfV) public advisories.
INTELLIGENCEORIGINAL.COM · INTELLIGENCE & TECHNOLOGY · SEPTEMBER 16, 2026
T H E A R C H I V E S
What You Have Just Read Is the Surface
Behind every article on this site is a man who has spent thirty years digging where others stopped. The full files are not here. They are on Patreon.
Bernd Pulch has been a forensic expert, publisher, and investigator since 1994. His archives contain the Stasi’s Fipro-Liste — the internal pension documentation of approximately 100,000 full-time MfS employees used in the early 1990s to identify Officers in Special Deployment. They contain KGB and FSB list material covering approximately 200,000 persons — alleged agents, informants, and contacts embedded across Western Europe and the United States. They contain decades of offshore registry cross-references, corporate filing trails, flight and property records, and sealed documents that mainstream publishers declined to touch.
He is the creator of the Epstein Financial Network Hub — a cross-referenced open-source entity database now mapping more than 50,000 named individuals and more than 12,000 firms, institutions, shell entities, and financial intermediaries across multiple jurisdictions. Every entry connects to the next: 9/11 contracting networks to Wirecard, Wirecard to Signa, Signa to the offshore structures that funded them. The Hub is the connective tissue between scandals that the public has been told are unrelated.
His work has been referenced by Reuters, ARD, ZDF, Süddeutsche Zeitung, CBS, and Fox Lorber. He served as an advisor for Reuters Insight and as a member of the Board of Experts for IRETO. His investigations exposed failures at HypoVereinsbank and the Falk bankruptcy — at the time the largest German real estate collapse, involving €3.2 billion and 30,000 investors. His forensic archives trace Nazi escape networks through Switzerland and South America to their integration into post-war intelligence and corporate structures, including the Gehlen Organization and the BND.
He founded Aristotle AI. He publishes on BerndPulch.org. He broadcasts on Telegram at ABOVETOPSECRETXXL. His mission has not changed in three decades: “No gatekeepers. No censorship. No fairy tales. Just evidence, patterns, and the uncomfortable truths that emerge when you follow the money and the documents.”
W H A T P A T R E O N S U B S C R I B E R S R E C E I V E
- The complete intelligence annexes and source documents behind every published article
- Access to the Epstein Financial Network Hub — 50,000+ persons, 12,000+ entities, fully cross-referenced
- KGB, FSB, and Stasi list material not published anywhere else
- Offshore registry and shell company trail reconstructions across every major jurisdiction
- Ongoing forensic updates on Wirecard, Signa, Benko, and the financial networks behind them
- Nazi ratline and Gehlen Organization research — personnel, capital flows, and post-war continuity
- Direct access to Bernd Pulch’s archive of thirty years of investigation
The files exist. The question is whether you want to read them.
BERNDPULCH.ORG · NO GATEKEEPERS · NO FAIRY TALES · NO RELOTIUS


