Interviews with 36+ current and former US officials describe China's strategy of analyzing vast quantities of stolen US personal data to identify CIA operatives
Foreign PolicyZach Dorfman
Context & Ripple Effects
This reporting connects two threads the coverage has tracked for years: the compromise of the CIA's source-communications system, which officials say led to roughly 30 executed US spies in 2010-2012, and the more recent finding that US intelligence has stayed one step behind China's hacking campaigns. What changed by late 2020 is the stated method — not a mole hunt but bulk analysis of stolen personal data at national scale.
The follow-on coverage shows where that method leads: Chinese tech firms including Alibaba and Baidu were reportedly enlisted to process stolen US data for spy agencies, and by late 2023 officials described an MSS system using AI to track US spies. A separate WSJ-reported finding that US agencies have lagged on open-source intelligence frames the asymmetry.
First-order effects
CIA officers and sources face direct identification risk: any American whose personal data — travel, financial, biometric records — sits in breached databases can be cross-referenced against patterns of covert activity.
Second-order effects
Enlisting Alibaba and Baidu as data processors gives Chinese agencies commercial-scale compute for counterintelligence while collapsing the line between private Chinese platforms and state spying, complicating how US agencies assess risk from Chinese-operated services.
Third-order effects
Espionage is shifting from recruiting assets to mining datasets: if bulk-data analytics reliably unmasks operatives, US counterintelligence must treat every breached federal or personnel database as a potential kill chain against its own network, and the documented US lag on open-source intelligence widens rather than closes the gap.
The trend: Great-power espionage is migrating from human tradecraft toward state-directed analytics over commercially processed stolen data, with AI systems like the MSS tracker described in later reporting as the endpoint.
Excellent piece on how online data hacks by China against the US led to Beijing being able to identify CIA spies working in Africa and Europe. Important highlighting the movement between cyber data hacks and real world implications on intelligence. https://foreignpolicy.com/...
For many years, the CIA had penetrated China's bureaucracy and even military and intelligence by generous bribing. Then in 2012, China hacked huge data - OPM - and learned how the US spy operation works. Fascinating story... https://foreignpolicy.com/...
In the early 2010s, CIA covers throughout the world were mysteriously being revealed. It appeared that the Chinese were able to do so using personal data stolen from the U.S. government and private firms, Zach Dorfman writes. [2/5] https://foreignpolicy.com/... https://twitter.co…
Investigation: The battle over data—who controls it, who secures it, who can steal it, and how it can be used for economic and security objectives—is defining the global conflict between Washington and Beijing. [Thread] https://foreignpolicy.com/...
China's Secret War for U.S. Data Blew American Spies' Cover — some incredible details in this @zachsdorfman piece. One (non-OPM hack) point jumps out: China learning that CIA was paying the promotion fees of its CCP recruits https://foreignpolicy.com/...
.@zachsdorfman has a blockbuster story today about Chinese intelligence stole US data and then used it to uncover and surveil CIA networks across Europe and Africa: https://foreignpolicy.com/...
NEW: How China's discovery of CIA networks at home fueled Beijing's big data-focused counterintelligence efforts—leading, among other things, to their identification of CIA officers in Europe and Africa. https://foreignpolicy.com/...
- The CIA was paying the ‘promotion fees’ - the bribes necessary to advance in the system - of its assets in China, sometimes up to a million dollars at a time. Discovering that - and the extent of penetration - was a major spur for the anti-corruption campaign.
This @zachsdorfman story - the first in a three-part series going *deep* into the spy data wars between China and the United States - has been long in the making. Some big takeaways from the first part - https://foreignpolicy.com/...
Starting around 2013, one year after the US govt became aware of the OPM hack, the CIA became aware that undercover CIA personnel, flying into countries in Africa and Europe for sensitive work, were being rapidly and successfully identified by Chinese intelligence.
U.S. officials believed Chinese intelligence operatives had likely combed through and synthesized information from these massive, stolen caches to identify the undercover U.S. intelligence officials, @zachsdorfman reports.
HUGE scoop from @zachsdorfman: Remember how people speculated that China's hack of the Office of Personnel Management might allow China to identify and track CIA operatives abroad? Well, that's EXACTLY what China did. Read more at @ForeignPolicy: https://foreignpolicy.com/...
- China used data from the OPM hack and others to identify CIA operatives almost as soon as they landed in third countries, especially within the Belt and Road Initiative