Review of “Chinese Espionage Operations and Tactics” (Second Edition)

Chinese Espionage Operations and TacticsMUCH HAS HAPPENED IN the West and in China since Nick Eftimiades first published Chinese Espionage Operations in 1994. It was the first in-depth study of Chinese espionage operations, which for decades had been overshadowed by Soviet intelligence and their espionage operations.

Throughout much of the latter part of the 20th  century, United States and other Western security services viewed Chinese intelligence and security services as being focused on their own internal security matters. They were not nearly as well-known or recognized as other adversarial intelligence and security services.  Nick was one of first experts to shine a light on Chinese intelligence operations. Since that time, he has dedicated his career and untold time and efforts to better understand Chinese intelligence tactics and techniques.

In the second edition of the book, Nick provides a comprehensive analysis and assessment on how the espionage and intelligence threat from China has grown significantly over the past three decades. He explains this in very clear and unambiguous terms to anyone who seeks a better understanding of these threats. This book is a culmination of more 30 years of dedicated research and the analysis of hundreds of cases that involve China. It focuses, not only on traditional espionage cases and operations, but examines motives, techniques and tactics relating to economic espionage, the theft of trade secrets and the theft of academic research and development.

There are a number of detailed case studies and real-life examples in the book, which show it is not only Chinese government organizations that pose a significant threat to United States and Western interests, but also a multitude of actors —e.g., academia, business people and researchers, with access to universities, commercial entities and think tanks. Chinese intelligence operatives conduct activities in all these areas in order to help China fulfill its strategic information and technology requirements and objectives. Nick examines China’s Whole of Society approach to a number of recent traditional and non-traditional collection efforts.

Chinese Espionage Operations and Tactics is an absolute must-read for individuals who handle national security matters; for state and local officials who are engaged in discussions with Chinese officials; for American and other Western businesses who are, or who will be, doing business with Chinese counterparts; for those in academia and research institutes involved with technology research and development, and finally for those who seek a better understanding of the threats posed by China’s growing and expanding worldwide presence and intelligence apparatus.

Author: John N. Wanat* | Date: 19 February 2025 | Permalink

  • John N. Wanat retired as Assistant Director for Investigations, Office of Export Enforcement, Bureau of Industry and Security, Department of Commerce.

Israeli soldiers working for Iranian intelligence spied on the Iron Dome

Iron Dome IsraelLAST MONTH, ISRAEL ARRESTED two reservists following an investigation that lasted several months and centered on uncovering espionage for an Iranian state entity during wartime. The two reservists had completed their regular military service before joining the reserves.

The two soldiers, identified as Yuri Eliasfov and Georgi Andreyev, held sensitive positions, and a least one was serving as a member of staff in Israel’s Iron Dome air defense system. The soldier serving in the Iron Dome is accused by the police, the Israel Security Agency (ISA), and the Israel Defense Forces (IDF), of aiding the enemy during wartime, for which the penalty is life imprisonment or death without the discretion of the court. A prosecutor’s statement has been filed against the two soldiers.

According to the investigation, the espionage affair began when one of the suspects, who served in a classified security system, sought to make contact with Iranian intelligence on social media. During his search, he contacted an Iranian operator, who asked him to complete various tasks in exchange for payments. The investigation revealed that the two soldiers were recruited by Iranian intelligence through the Internet to carry out missions in exchange for payments.

They two men were initially required to spray anti-government graffiti in Tel Aviv and in Israel’s the northern region. Giorgi Andreyev, fearing the consequences of such actions, withdrew from the operation. “We are working for Iran and doing something dangerous,” he told Eliasfov. Despite this, however, Eliasfov, who is reportedly the main suspect in the case, continued his activities.

The undercover investigation revealed that Eliasfov, who serves in the Iron Dome system, filmed a video while participating in a classified information, which he then sent to his Iranian handler. He received $3,500 from the same Iranian official, while his at-times accomplice received $70. During his interrogation, Eliasfov claimed that he committed the acts due to being in a difficult financial situation and because he sought to obtain money easily.

One of the interesting findings that emerged from the investigation of the suspects was that other soldiers and family members were aware of Eliasfov’s initial actions and warned him that he was connecting himself with Iranian elements. Despite that, Eliasfov continued his espionage activities, which included filming a video from inside an Iron Dome facility. The footage reportedly contained classified material that could significantly endanger the security of the State of Israel. Read more of this post

Germany charges three dual German-Russian nationals with espionage

Grafenwoehr Training Area GermanyTHE OFFICE OF THE Federal Prosecutor in Germany has charged three dual German-Russian citizens with acts of espionage on behalf of Russia, with the intent of harming the national security of the German state. In compliance with German privacy laws, the three espionage suspects have been publicly identified only by their first names and last name initials. They are: Dieter S.,  Alex D., and Alexander J.

Dieter S. appears to be the central suspect in this case. Following his arrest by the German Federal Criminal Police Office, he was found to have participated in military operations of the secessionist Donetsk People’s Republic in Ukraine. By that time, German authorities had already charged him with being in contact with an individual known to be a member of Russian intelligence, who operated as his handler.

According to the indictment, throughout his interactions with his Russian handler, Dieter S. repeatedly made it known that he was willing and able to carry out acts of sabotage against security-related installations in Germany, on behalf of the Russian Federation. He also offered to carry out arson attacks and use explosives against transportation facilities and infrastructure, such as railway lines, which were used by the German state to transport military supplies to Ukraine.

Subsequently, Dieter S. was instructed by his Russian handler to collect intelligence about potential targets in southeastern Germany. He thus engaged in systematic surveillance activities targeting the Grafenwoehr Training Area, a United States Army military training base located near Grafenwöhr, in eastern Bavaria. Grafenwöhr is the largest training facility maintained by the United States in Europe. Since 2022, it has been used to instruct Ukrainian troops on how to operate American-built tanks.

Dieter S. is also believed to have conducted surveillance at several loading stations used by the German and American militaries, as well as the facilities of private-sector contractors to the German military. In his surveillance operations, Dieter S. was assisted by Alex D. and Alexander J. All three men took photographs and videos of the targeted facilities. The collected material was eventually passed on to Dieter S.’s Russian handler.

Official charges against the three suspects were filed before the State Security Senate of the Munich Higher Regional Court on December 9. They were publicized by the office of the Federal Public Prosecutor General on December 30. A trial date is now pending.

Author: Joseph Fitsanakis | Date: 06 January 2025 | Permalink

Russia using nontraditional means to gather intelligence, Finland warns

SUPO FinlandRUSSIA’S NEED TO GATHER intelligence from Scandinavian targets has increased considerably since Finland and Sweden joined the North Atlantic Treaty Organization (NATO), prompting Moscow to seek nontraditional means of collecting intelligence, according to Finland’s spy agency. A new report by the Finnish Broadcasting Company (Yle) relays a warning by the Finnish Security and Intelligence Service (SUPO) that Russian spies are increasingly operating in Scandinavia without relying on diplomatic protection.

Human intelligence (HUMINT) operations are typically carried out of diplomatic facilities by intelligence officers who enjoy various degrees of diplomatic immunity. Such protections are seen as crucial for the safety of intelligence personnel, who tend to engage in illegal activities while stationed abroad. However, the number of Russian intelligence officers who are based in diplomatic facilities in Finland and elsewhere in Scandinavia has “significantly decreased” in recent years, according to the Yle report.

The reason for the decline in numbers rests with the numerous expulsions of Russian diplomatic personnel —which include intelligence officers— that took place throughout Europe in the months following Russia’s February 2022 invasion of Ukraine. Since then, Finland is one of dozens of European countries that have repeatedly denied Russia’s requests for the issuance of diplomatic visas. As a result, Russian embassies and consulates in Finland remain understaffed and mostly devoid of intelligence personnel.

In response to this new reality, the Kremlin has been experimenting with using nontraditional HUMINT collectors. The latter are not based in diplomatic facilities and are not protected by diplomatic immunity. Such nontraditional intelligence collectors operate as “journalists or researchers”, according to SUPO. At the same time, Russian intelligence agencies increasingly target for recruitment Finns who life in Russia, or try to recruit them while they are traveling elsewhere in Europe.

Lastly, Russian intelligence agencies are systematically hiring criminals to carry out specific tasks on behalf of the Kremlin, in return for money. Such criminals include computer hackers, who are attracted by the Russian state. Indeed, the Russian government is systematically “providing favorable conditions” for computer hackers to operate out of Russian territory. They receive money and protection in return for letting the Russian state use them as a cover for cyber espionage, sabotage, and influence operations.

Author: Joseph Fitsanakis | Date: 18 November 2024 | Permalink

Israeli couple who spied for Iran made ample use of digital applications

Israel and IranTHE ISRAEL SECURITY AGENCY (ISA) recently announced the arrests of an Israeli couple of Azeri origin on suspicion of spying for Iran. The couple, both 32 years old, were allegedly recruited by an Iranian handler of Azeri origin named Elshan Agheev. As part of their activities, and for about two years, the couple gathered intelligence on critical infrastructure and security sites in Israel, and even conducted surveillance on an academic working for the Institute for National Security Studies, allegedly in order to kill her.

The case demonstrates how software that is easily accessible on the Internet makes it possible to encrypt information communicated between a handler and an agent, as well as how money is transferred to the agent. The official indictment reveals details about the couple’s modus operandi, including the identity of the particular software the spies used to communicate with their Iranian handler.

One of the applications the couple used is Zangi, which facilitates the exchange of encrypted instant messages. According to the company’s website, Zangi offers voice and video calling, text messaging, and file transfer services “without registration and without data collection”. In fact, according to Zangi, the data is saved on the user’s device only. In addition to using the Zangi application, the couple also appear to have used the Zolotaya Korona money-transfer platform. The couple allegedly used the platform in order to receive payments by their Iranian handlers, and to transfer funds to other parties involved in Iranian-led espionage activities inside Israel.

Another application allegedly used by the couple is Ecos Dos, a digital wallet for storing and transferring digital currencies. Ecos Dos is a software wallet that can be installed on a computer or mobile phone. It supports a wide variety of crypto-currencies and is used to store and transfer cryptocurrencies. It is known for its simplicity of use and friendly interface. It is popular among users who wish to maintain anonymity when transacting in digital currencies. It does not require identifying a user’s details when operating, so anyone can create an account and receive funds anonymously.

The suspects are also believed to have used a software called Encryptor in order to encrypt information. This software allows files and folders to be encrypted so that only those who have the encryption key can open them. The couple allegedly used Encryptor to encrypt the information they collected before passing it on to their Iranian handlers, thus making it difficult for Israeli authorities to decipher the information.

The use of these applications attests to the sophistication of the Iranian spy network that was recently busted in Israel, and its efforts to hide its activities inside the Jewish state. The recent indictment against the couple details a collection of serious security offenses, including aiding the enemy in war and providing information to the enemy to harm the security of the state. Iran is clearly stepping up its efforts to recruit Israeli citizens for espionage and terrorist activities.

Author: Avner Barnea | Date: 11 November 2024 | Permalink

Dr. Avner Barnea is research fellow at the National Security Studies Center of the University of Haifa in Israel. He served as a senior officer in the Israel Security Agency (ISA). He is the author of We Never Expected That: A Comparative Study of Failures in National and Business Intelligence (Lexington Books, 2021).

US government wants to ban Chinese-made smart cars over espionage, sabotage fears

Chinese car industryTHE UNITED STATES DEPARTMENT of Commerce is proposing new regulations that seek to ban the sale of Chinese-made cars in the United States, over concerns that they could be used for espionage or sabotage. Several reports on the proposal noted that it was hurriedly introduced last week as a “national security action,” rather than a trade-related dispute between the US and China.

American government officials said that the new proposals come out of lengthy investigations into the software and technical specifications of Chinese cars. The investigations raised concern about “[c]ertain technologies originating from the [People’s Republic of China] or Russia” that are often found in Chinese-made cars. Such technologies include vehicle cameras, microphones, tracking devices, and several software packages that connect the cars to the world wide web.

Washington is concerned that these devices, and the software that runs them, could be used to collect the personal data of users, or to facilitate espionage activities on a large scale. Concerns have also been raised by US officials that Chinese-made smart cars could be remotely manipulated and used for sabotage during wartime. According to the US Department of Commerce, a central source could potentially “take control of all [the Chinese-made] vehicles operating in the US all at the same time, causing crashes, block[ed] roads, etc.”

When asked by reporters to justify the proposed regulations, Jake Sullivan, White House national security adviser, replied that the US had “already seen ample evidence of the [People’s Republic of China] pre-positioning malware on our critical infrastructure for the purpose of disruption and sabotage. And with potentially millions of vehicles on the road, each with 10- to 15-year lifespans, the risk of disruption and sabotage increases dramatically”.

Author: Ian Allen | Date: 23 September 2024 | Permalink

Ex-CIA analyst accused of spying for South Korea had prior warnings from FBI, CIA

NIS South KoreaA FORMER INTELLIGENCE ANALYST for the Central Intelligence Agency (CIA), who is married to a high-profile columnist for The Washington Post, remains under arrest for allegedly spying for South Korea. According to an indictment unsealed last Tuesday in the Southern District of New York, the former CIA analyst is Sue Mi Terry, 54, of New York. Terry is a naturalized American citizen born in Seoul, South Korea, who grew up in Virginia and received a PhD from Tufts University in Massachusetts.

Terry joined the CIA in 2001 but resigned in 2008, allegedly “in lieu of termination” because her employer “had ‘problems’ with her contact with” officers from South Korea’s National Intelligence Service (NIS). After leaving the CIA, Terry worked briefly for the National Security Council and the National Intelligence Council, before transitioning to academia. Her most recent post was that of a senior fellow at the Council on Foreign Relations, where she became known as an exert on East Asian affairs with a focus on the Korean Peninsula. For over a decade, Terry has made frequent appearances on television and radio, as well as on several podcasts. She is married to the Washington Post columnist Max Boot.

The Department of Justice accuses Terry of failing to register under the Foreign Agents Registration Act and deliberately conspiring to violate that law, thus effectively operating as an unregistered agent of a foreign power. The indictment claims that Terry was gradually recruited by the NIS, beginning in 2013, two years after she stopped working for the United States government. Terry allegedly continued to work for the NIS for a decade, during which she was handled by NIS intelligence officers posing as diplomats in South Korea’s Washington embassy and permanent mission to the United Nations in New York.

It is alleged that throughout that time Terry provided her NIS handlers with access to senior US officials, disclosed “nonpublic US government information” to the NIS, and promoted pro-South Korean policy positions in her writings and media appearances. In return, Terry is alleged to have received luxury goods, free dinners at expensive restaurants, and nearly $40,000 in “covert” funding, nominally to operate a public policy program on Korean affairs. It is worth noting that, according to the unsealed indictment, the Federal Bureau of Investigation warned Terry that she should be wary of being approached by NIS officers seeking to offer her funding. Read more of this post

Tradecraft observations on the Reichenbach/Fischer espionage case

Germany ReichstagSEVERAL CASES OF CHINESE espionage have been announced recently in Europe. Thomas Reichenbach and Herwig and Ina Fischer —a married couple— were arrested on April 22, 2024, for illegal exports of dual use technology with military (naval) applications.

Reichenbach lists himself as a contract marketing manager for the Hong Kong Trade Development Council. He studied at Peking University in the mid-1980s. He worked in China, speaks Mandarin, and has a Chinese wife.

Herwig and Ina Fischer own a small engineering consulting company named Innovative Dragon in Duesseldorf. Both have travelled extensively in China. Innovative Dragon contracts for technical research with universities. Herwig studied mechanical engineering and aircraft and spacecraft construction at the Rhine-Westphalia Higher Technical School, focusing on guidance technology and composite fiber materials. The company headquarters are in London and there are offices in Duesseldorf and Shanghai (Donghua University Science and Technology Park). The London office does not appear to have a functioning telephone number.

Reichenbach is suspected of having been recruited by the Ministry of State Security (MSS) in China. The German government has accused the trio of having illegally exported dual use technology since at least 2022. At the time of the arrests, the suspects were in negotiations on additional research projects useful for expanding the combat strength of the Chinese People’s Liberation Army Navy.

Status: Alleged

Tradecraft observations:

  1. Use of a potential front company in London to facilitate allegedly illegal exports.
  2. Use of third countries to facilitate allegedly illegal exports.
  3. Reichenbach allegedly recruited Herwig and Ina Fischer and handled them as in-country assets.
  4. It is alleged that the MSS probably recruited Reichenbach in China.
  5. An MSS officer allegedly handled Reichenbach from China (linear control).
  6. The MSS allegedly funded the operation through front companies.

Author: Nicholas Eftimiades* | Date: 03 May 2024 | Permalink

* Nicholas Eftimiades is a Senior Fellow at the Atlantic Council. He retired from a 34-year government career that included employment in the United States Central Intelligence Agency, the Department of State, and the Defense Intelligence Agency. He held appointments on the Department of Defense’s Defense Science Board and the Economic Security Subcommittee of the Department of Homeland Security’s Homeland Security Advisory Council. He is an advisor to the United States Intelligence Community. Eftimiades authored numerous works on China’s espionage methods. His books, Chinese Intelligence Operations (1994) and Chinese Espionage: Operations and Tactics (2020) are examinations of the structure, operations, and methodology of China’s intelligence services. They are widely regarded as seminal works in the field.

Germany arrests sixth alleged spy in less than a month

MSS ChinaAUTHORITIES IN GERMANY HAVE arrested a sixth person in less than a month, in connection with three separate cases of espionage orchestrated by Russian or Chinese intelligence. Last Tuesday, police in the east German city of Dresden arrested an assistant to a leading politician of the far-right Alternative für Deutschland party (AfD). The assistant, who is a dual German-Chinese citizen, is accused of spying for Chinese intelligence, while the far-right politician who employed him is also being investigated, according to reports.

German news reports have identified the alleged spy as Jian Guo, 43, who lives in Dresden with his wife and children. Guo reportedly entered Germany as a student and stayed there after completing his studies, eventually becoming a naturalized German citizen. In 2019 he joined the staff of the office of Maximilian Krah, a senior AfD politician, who had recently been elected to the European Parliament.

According to the German prosecutor’s office, Guo had begun working for Chinese intelligence prior to joining Krah’s office as an assistant. At least some of his alleged espionage activities involved posing as a critic of the Chinese government and joining dissident groups of Chinese expatriates in Germany. He would then provide information about the activities of these groups to Chinese intelligence, according to his indictment. The latter described Guo’s intelligence activity as “an especially severe case” of espionage.

Meanwhile, German authorities are also reportedly investigating Krah himself over payments he allegedly received from pro-Chinese and pro-Russian individuals or groups. In a statement issued late last week, the AfD politician said he had been informed about Guo’s arrest from media reports and that he had no information about this case. Shortly after Krah’s statement, the AfD described Guo’s arrest as “highly disturbing” and added that party authorities would do “everything possible to aid the investigation”.

During the month of April alone, Germany has arrested no fewer than six individuals in a series of apparently unconnected cases of espionage, connected with Russia or China. Two of these individuals are German citizens of Russian origin, who were allegedly assisting Russian intelligence plan acts of sabotage against military installations located on German soil. Three other German citizens were allegedly planning to provide designs of advanced aircraft engines to Chinese intelligence officials.

Author: Joseph Fitsanakis | Date: 29 April 2024 | Permalink

Austria: Arrest raises broader questions about counterintelligence capabilities

BVT AustriaON GOOD FRIDAY, MARCH 29, Egisto Ott, a former member of Austria’s now-dissolved domestic intelligence agency, the Federal Office for the Protection of the Constitution and Counterterrorism (BVT), was arrested in his house in Carinthia, Austria’s southernmost state. Ott had frequently been at the center of media attention in the past year, in connection with the network surrounding the fugitive financier and alleged spy Jan Maršálek, as well as alleged misconduct relating to carrying out illegal investigations of persons. Ott also seems to have been involved in an alleged attempt to create an intelligence unit, or even an entire shadow intelligence service, embedded inside Austria’s foreign ministry. Now the veteran police and intelligence officer stands accused by the state attorney of abusing his authority and of being part of an “intelligence activity to the disadvantage of Austria” —the only form of spying that is illegal under § 256 of the Austrian criminal code.

Ott’s arrest came several years after intelligence was first shared with Austria by Western partner services —allegedly the Central Intelligence Agency— that reportedly date from as early as November 2017. Back then, Ott allegedly received classified material from his service’s email address to his personal Gmail account. However, Peter Gridling, director of the BVT from 2008 until its dissolution in 2021, stated in a recent interview that the ensuing investigations did not yield actionable results that could be used in criminal proceedings. This statement is highly interesting, as Gridling filed accusations about Ott with the State Prosecutor’s Office himself, and would hardly have done unless he had access to hard evidence. Ott was consequently removed from the BVT and placed in Police Academy Austria (SIAK), which is responsible for training police officers and conducts research related to police and domestic security.

Nevertheless, according to media reporting, Ott seems to have kept and illegally used certain forms of identification that presented him as a police officer. He is also alleged to have maintained access to several police databases and to have retained his network of trusted informants that provided him with intelligence. These included contacts in friendly foreign police services, whom Ott knew from his time as a liaison officer in Italy and Turkey. According to Gridling, these contacts were unaware that Ott had been removed from the BVT under suspicion of being unreliable and potentially even working for Russia. They therefore continued to help him when asked. Ott allegedly deceived his contacts by claiming that he needed information on cases relating to different kinds of extremism. As it turned out, according to the leaked arrest warrant, several of the individuals referred to by Ott as “suspects” in terrorism investigations were in fact Russian dissidents or intelligence defectors who were living as protected persons in Austria and elsewhere outside Russia.

It appears highly probable that Ott also had people inside the Austrian bureaucracy, including former colleagues in the BVT, who continued to provide him with information and assistance, even after the first allegations against him arose in 2017. As of now, at least one other officer from LVT Vienna (the state unit of the BVT) has been found to have illegally provided Ott with Information. It is likely, given the publicly available descriptions of Ott’s activities, that other individuals may be implicated. It also remains to be seen whether individuals involved in this case were able to join the BVT’s successor agency, the new Directorate of State Protection and Intelligence (DSN). Read more of this post

India arrests Moscow embassy security employee for spying for Pakistan

Embassy of India in RussiaAUTHORITIES IN INDIA HAVE arrested a security employee at the Indian High Commission in Russia, accusing him of spying for Pakistani intelligence. The embassy of India in Moscow is one of its largest in the world and is viewed as critical to New Delhi’s strategic relations with Russia. Employees that staff the Moscow embassy are highly vetted and typically represent the cream of the crop of India’s Ministry of External Affairs. It follows that news of the arrest of a Moscow embassy security employee on espionage charges must have raised eyebrows in India.

The employee in question has been identified in news reports as Satendra Siwal, a resident of the village of Shahmahiuddinpur, located in the Hapur district of Uttar Pradesh. He is believed to have been employed as an India-Based Security Assistant (IBSA) at the Indian embassy in Moscow since 2021. Siwal reportedly belongs to the embassy’s Multi-Tasking Staff (MTS), a broad job title that encompasses a variety technical support specialists working at India’s diplomatic facilities worldwide.

According to reports, Siwal was arrested by members of the Anti-Terrorist Squad (ATS) in the northern Indian city of Meerut, 250 miles northeast of New Delhi. He was charged with participating in “anti-India activities”, which included providing government secrets to Pakistan’s Inter-Services Intelligence (ISI) Directorate. According to the ATS, the secrets given to the ISI by Siwal included information about strategic planning by the Indian Ministry of Defense, the Ministry of External Affairs (Siwal’s direct employer), and the Indian military. Siwal allegedly spied for the ISI in exchange for financial compensation.

Indian authorities said the case against Siwal was built with the help of “electronic surveillance” and other “evidence collection”, but did not provide details. In a statement issued on Monday, the ATS said Siwal had allegedly “confessed to his crime” during questioning. The espionage suspect is now facing charges under India’s Official Secrets Act.

Author: Joseph Fitsanakis | Date: 5 February 2024 | Permalink

Canadian judge bars Chinese PhD student from entering, citing espionage concerns

University of WaterlooIN AN UNPRECEDENTED AND potentially highly consequential decision, a judge has barred a Chinese PhD student from entering Canada over concerns he might be pressured to spy by the government of China. The case could have “ripple effects” on universities across Canada and possibly even all of North America, according to legal experts.

The central figure in the case is Yuekang Li, a citizen of China, who was accepted into the Mechanical and Mechatronics Engineering PhD program of the University of Waterloo. Li stated in his application that his goal was to return to his home country after receiving his PhD and work to “improve its public health system”. However, when Li applied for a graduate student visa, his application was denied by an officer of Immigration, Refugees and Citizenship Canada (IRCC), the government department that oversees applications for entry visas into the country.

In deeming Li inadmissible to Canada, the IRCC officer in charge of his case reportedly cited the student’s strong interest in microfluidics, a niche branch of nanotechnology with a wide range of applications in the biopharmaceutical industry. The IRCC officer also noted growing concerns in the West about the use of students and researchers as “non-traditional collectors of information” by the government in Beijing. In a number of such cases, Chinese students and researchers have been given permission by the Chinese state to work abroad with the understanding that they will deliberately collect information that will benefit China’s military-industrial complex.

Li promptly challenged the IRCC’s decision, which ended up being heard in Federal Court. Li’s legal representatives argued that the rejection of his application for a student visa relied on “an overly broad definition of espionage” and engaged in “speculation”, rather than factual evidence. But on December 22, Federal Court Chief Justice Paul Crampton sided with the IRCC.

In his decision, which was made available late last week, the judge agrees with the IRCC’s view that the graduate research Li proposed to carry out at the University of Waterloo would fall under the definition of “non-traditional espionage”. He referred to China as a “hostile actor” and cautioned that such actors “increasingly make use of non-traditional methods to obtain sensitive information in Canada or abroad, contrary to Canada’s interests”. Given that new reality, Canada’s legal understanding of what constitutes “espionage” must evolve”, Judge Crampton argues in his decision.

Author: Joseph Fitsanakis | Date: 08 January 2024 | Permalink

Veteran Belgian politician was a spy for Chinese intelligence, report alleges

MSS ChinaA LONGTIME BELGIAN POLITICIAN worked as a spy for Chinese intelligence for at least three years, according to a joint investigation by a consortium of European news media. Until last week, the politician, Frank Creyelman, 62, was a leading member of Vlaams Belang, a far-right separatist party that draws nearly the entirety of its support from northern Belgium’s Dutch-speaking Flemish regions. In addition to seeking to separate Flanders from Belgium, Vlaams Belang opposes immigration and multiculturalism, with much of its criticism directed at Islam.

From 1995 until 2014, Creyelman served as a member of the Flemish Parliament or the Belgian Senate, representing the Antwerp Province. During that time, he became known for his pro-Russian views, which he continued to propagate in retirement. In 2021, he voiced strong skepticism against the Belgian government’s efforts to provide diplomatic, financial, and military support to Ukraine. Following his retirement from frontline politics, Creyelman became an honorary member of the Flemish Parliament. He also remained chairman of Vlaams Belang in his home city of Mechelen, a Dutch-speaking stronghold.

Last week, however, a joint investigation by the British newspaper The Financial Times, French newspaper Le Monde and German newsmagazine Der Spiegel, claimed that Creyelman worked as a spy for China for at least three years. Citing unnamed “intelligence officials from four Western countries”, the investigation claimed that Creyelman had been recruited by Daniel Woo, a case officer for China’s Ministry of State Security. Woo is believed to work out of the MSS branch in China’s far-eastern province of Zhejiang, though he has also served tours in Europe under diplomatic cover, including in Romania and Poland.

It is not known how the MSS recruited Creyelman. It appears that most of his communication with his alleged MSS handler took place via text messages. However, it is claimed that in 2019 Creyelman traveled to Sanya, a popular tourist resort in China’s Hainan Island, where he allegedly met Woo and possibly other MSS operatives. Notably, the journalists behind the investigation into Creyelman claim that they have accessed incriminating messages exchanged between Creyelman and Woo. The text messages span the period between early 2019 and late 2022.

In the text messages, Woo asks Creyelman to try to influence senior-level discussions in Belgium and elsewhere concerning China’s treatment of its ethnic Muslim populations in the Xinjiang Province. The far-right politician was also instructed to find ways to vilify and discredit European researchers and academics who were documenting China’s treatment of ethnic Muslims in Xinjiang. Woo also asked Creyelman to try to quell criticism of China’s crackdown of the pro-democracy movement in Hong Kong. In one message, Woo explained that China’s purpose was “to divide the US-European relationship”.

Last Friday, just hours after the allegations about Creyelman’s alleged espionage emerged, Vlaams Belang announced that it had expelled him from its ranks. In a social media post, the party’s leader, Tom Van Grieken, denounced Creyelman’s espionage as going “against the purpose and essence, even the name, of our party”. He added: “The only loyalty for nationalists can only be to their own nation”.

Author: Joseph Fitsanakis | Date: 18 December 2023 | Permalink

Germany charges two with ‘high treason’ for spying for Russia

FSB RussiaGERMANY HAS CHARGED TWO men, among them a German intelligence officer, with spying for Russia, in a case that has shocked German public opinion and alarmed Germany’s allies. The two men have been identified only as “Carsten L.” and “Arthur E.”, in compliance with Germany’s privacy laws. Carsten L. is accused of having provided the Russian Federal Security Service (FSB) with intelligence about the Russo-Ukrainian war, in return for nearly $500,000. Arthur E. is believed to have been Carsten L.’s accomplice and to have acted as an intermediate between him and his Russian handlers.

The German prosecutor general has charged both men with “high treason in a particularly serious case”. However, there is no public information about the timeline of Carsten L.’s recruitment by the FSB and his espionage for the Russians. He reportedly met his accomplice, Arthur E., a Russian-born German diamond trader, in Bavaria in 2021. After being recruited by Carsten L., Arthur E. is believed to have traveled frequently between Germany and Russia. During those trips, he is thought to have met with FSB officers in order to provide them with intelligence and receive payments.

When they announced the arrests of the two men back in January of this year, German officials said they had been tipped by a foreign intelligence agency. The foreign intelligence agency had allegedly found a document from the BND’s internal files in the possession of an unnamed Russian spy agency. However, the identity of the intelligence agency that provided the tip to the Germans is among several important details about this case that remain unknown for the time being. Among them are the estimated duration of Carsten L.’s alleged espionage for Moscow, the damage he caused to German intelligence, as well as his motives for spying for the FSB.

Author: Joseph Fitsanakis | Date: 12 September 2023 | Permalink

Alleged Israeli spies with Russian citizenship arrested in Lebanon

Rafic Hariri International Airport Beirut LebanonLAST WEEK, LEBANON’S GENERAL Security Directorate charged two Russian citizens with spying for Israel. The two Russians, who appear to be legally married to each other, were detained by authorities at Beirut’s Rafic Hariri International Airport as they were attempting to leave the country. The detentions were reported by the Lebanese newspaper Al-Akhbar, which is affiliated with the Lebanese militant group Hezbollah.

According to the Al-Akhbar report, one of the suspects admitted that he had been recently recruited into Israeli intelligence. He also reportedly admitted that, as part of his espionage activities, he received maps of sites and instructions about gatherings at facilities in Lebanon belonging to the Hezbollah organization. He added that he had been instructed to access, inspect and, if possible, photograph these facilities. He also reportedly admitted that he had visited southern Lebanon and entered Hamas-controlled areas of southern Beirut, where he had collected data and verified it against the information available to his handlers.

The report added that the suspect’s wife, who was also arrested, admitted under interrogation that she was aware of her husband’s work and that she had assisted him in his tasks. According to the report the General Security Directorate had suspected the Russian citizen, because he had traveled in southern Lebanon several times. Lebanese authorities were able to track his movements and connections, eventually tracing his place of residence. He was arrested along with his wife soon after being notified by his handlers that he should leave the country immediately.

Al-Akhbar added that, prior to the arrest, the General Security Directorate had informed the Russian Embassy in Beirut of its intention to arrest the Russian citizens. The agency’s Director, Elias Elbisri, said following the arrest: “A spy ring for the benefit of the Israeli enemy was foiled at the Beirut airport, consisting of two people who tried to leave Lebanon”. According to Elbisri, “we carried out the necessary investigations; this cell posed a threat to Lebanon”.

Israeli authorities did not respond to news about the incident. It should be noted that, if Russian citizens were indeed recruited and employed by Israeli intelligence, this development could further-damage the relationship between Israel and Russia, which is already fragile due to ongoing developments in Syria and Ukraine. Israel regularly launches attacks on Iranian facilities and equipment in Syria —a Russian ally. Israel is also believed to provide security assistance to Ukraine, which is engaged in a bloody war over territory with Russia.

In recent days, there have been leaks in Israel that an intense debate took place in the Israeli Security Cabinet, following the rise in Palestinian acts of terrorism in Israel, which, according to Israeli security agencies, are guided by Hezbollah and Hamas. As a result, Hamas operatives in the Gaza Strip are taking protective actions, fearing the renewal of targeted killings by Israeli forces. Salah al-Aruri, commander of Hamas’ Izz ad-Din al-Qassam Brigades, who is directing his forces against Israel from abroad, could also be a target for the Israeli intelligence community.

Author: Avner Barnea | Date: 04 September 2023 | Permalink

Dr. Avner Barnea is research fellow at the National Security Studies Center of the University of Haifa in Israel. He served as a senior officer in the Israel Security Agency (ISA). He is the author of We Never Expected That: A Comparative Study of Failures in National and Business Intelligence (Lexington Books, 2021).