Modern Spies No Longer Steal Documents: This is the New Modus Operandi
The image of a spy sneaking into a laboratory to steal secret documents is becoming increasingly inadequate to explain modern technological espionage. The latest warning from MI5 indicates that strategic knowledge can now move through channels that appear commonplace: research funding, university collaborations, professional recruitment, and cross-border academic projects.
This shift became clearer after the British security agency issued a Security Service Espolarmente Alert on 30 September 2026. MI5 stated that the China General Technology Research Institute (CGTRI) has very strong links to China’s Ministry of State Security (MSS) and assessed that the primary goal of the institution is to fund research that directly enhances the technical capabilities of the MSS for espionage activities.
According to MI5, more than 100 academics linked to the UK have contributed to research projects funded by the MSS through the CGTRI. The fields affected are not peripheral technologies, but rather artificial intelligence, cybersecurity, covert communications systems, and steganography—fields that possess both civilian benefits and security and intelligence utility.
What distinguishes this case from classic espionage imagery is the possibility that some academics may not even know who is behind the ultimate source of funding. MI5 explicitly stated that in several cases, researchers might be unaware that the CGTRI is funding Chinese projects to which they are contributing.
Therefore, the alert is not an accusation that more than 100 British academics are consciously working as Chinese spies. Rather, the issue highlighted by MI5 is the possibility that academic activities, which appear formally normal, can provide strategic benefits to foreign intelligence agencies without all parties involved understanding the final funding structure.
Reuters reported the alert as an unprecedented public move by MI5 in this format. The Guardian also noted that the warning places pressure on British universities to immediately review their cooperation with the CGTRI, while also opening a broader debate on how universities scrutinise funding sources and foreign research partners.
Security questions are no longer limited to which foreign agent is attempting to steal a secret, but are shifting towards who is financing the research, who is gaining access to scientists and their networks, and how the research results may ultimately be utilised.
MI5 has openly stated that foreign state threats are not only directed at governments or intelligence agencies. Academic partnerships, supply chains, technology companies, commercial information, and STEM research—particularly dual-use and emerging technologies—can also be targets, as they can help other nations accelerate their technological or military capabilities.
The National Protective Security Authority (NPSA), part of MI_5, described this vulnerability very clearly. According to the ‘Trusted Research’ guidelines, international cooperation can grant state actors access to individuals, IT networks, and participation in sensitive research without the need for traditional espionage or cyberattacks.
The openness that serves as the strength of the academic world can, therefore, simultaneously become its point of vulnerability. Researchers are accustomed to sharing findings, attending conferences, conducting joint research, hosting visiting researchers, and building international networks; meanwhile, security agencies must consider whether this legitimate access can be used to obtain technology, intellectual property, or strategically valuable knowledge.
The NPSA specifically mentioned that traditional academic engagement can serve as a pathway for foreign intelligence agencies to approach individuals, including through conferences or research placements. The agency also warned that state actors can exploit the collaborative nature of the academic sector to obtain research data, intellectual property, ideas, and techniques.
Consequently, in contemporary technological espionage, a conference does not need to be a place for exchanging envelopes containing secret documents to hold intelligence value. It can be a venue to identify experts, build professional relationships, understand who masters certain technologies, or pave the way for joint projects that subsequently provide broader access.
This change in modus operandi is not only visible in the world of research. Four months before the CGTRI alert, on 3 June 2026, the ‘Five Eyes’ intelligence alliance—comprising the UK’s MI5, the US FBI, Australia’s ASIO, Canada’s CSIS, and New Zealand’s NZSIS—issued a joint bulletin titled ‘Safeguarding Our Secrets’ regarding online recruitment operations linked to Chinese military intelligence.
The bulletin described a pattern far removed from scenes of secret agents meeting in dark places. Intelligence officers are said to disguise themselves as recruiters or consultants for seemingly legitimate shell companies, posting jobs through professional platforms and gig-work sites such as LinkedIn, Indeed, and Upwork.
Applicants’ CVs can then be screened based on their potential access to sensitive information. Following initial contact, candidates are recruited to produce reports that appear to be ordinary consultancy work, before requests evolve towards more exclusive information that is not available to the public.