The Defense Counterintelligence and Security Agency (DCSA) released its annual "Targeting U.S. Technologies" report on September 17, 2026, revealing persistent and sophisticated efforts by foreign intelligence entities (FIEs) to compromise the U.S. cleared defense industrial base. The report, analyzing data from fiscal year 2025, highlights that FIEs most commonly attempt to co-opt subject matter experts (28% of incidents) and use email as their primary method for initial contact (30% of attempts). Geographically, entities from the East Asia and Pacific region remain the most significant threat, accounting for nearly half of all collection attempts. The DCSA urges cleared personnel to be vigilant against unsolicited professional and commercial outreach.
Foreign adversaries are employing a blended approach that combines traditional human intelligence (HUMINT) with cyber-enabled tactics to target cleared U.S. personnel and contractors. Instead of relying solely on technical exploits, FIEs are using social engineering at scale, leveraging professional networking and business opportunities as a pretense to access sensitive and classified information. The DCSA analyzed over 22,000 suspicious contact reports in FY 2025, identifying 2,900 as legitimate attempts by FIEs to gather intelligence.
The success of these foreign intelligence operations poses a direct threat to U.S. national security and economic competitiveness. The theft of sensitive or classified defense technology can erode the U.S. military's technological advantage, accelerate foreign military modernization, and compromise the integrity of the defense supply chain. For cleared contractors and personnel, falling victim to these schemes can result in loss of security clearance, legal repercussions, and significant reputational damage.
T1593 - Search Open Websites/Domains).The most effective mitigation is educating cleared personnel to recognize, vet, and report suspicious outreach attempts.
Using email security gateways to filter and block phishing and spear-phishing emails is a critical technical control.
The primary defense against the social engineering tactics described by the DCSA is a well-informed workforce. Organizations with cleared personnel must implement a continuous counterintelligence and security awareness training program. This training should go beyond generic phishing examples and focus specifically on the lures used by FIEs: fake job offers, paid consultations, and academic collaborations. Use real-world (anonymized) examples from DCSA reports to make the threat tangible. Training should empower employees to 'trust their gut' and provide them with a clear, frictionless process for reporting any suspicious contact to their FSO without fear of reprisal. This human firewall is the most critical asset in detecting these targeted campaigns.
Establish a formal, mandatory process for vetting all unsolicited professional opportunities presented to cleared personnel. This process should be managed by the security department or FSO. Before an employee is permitted to engage with a request for consultation or a job offer, the security team must independently verify the legitimacy of the entity making the offer. This includes checking corporate registration records, verifying contact information through official websites (not from the email itself), and researching the individuals involved. This formalized 'pause-and-verify' step inserts a critical control point between the FIE's approach and the potential victim, disrupting the social engineering lifecycle.
Augment user training with robust technical controls at the email gateway. Since email is the top vector, advanced email security solutions are essential. These tools should use machine learning to analyze email content, sender reputation, and communication patterns to identify sophisticated spear-phishing attempts. Configure policies to apply extra scrutiny or warning banners to emails originating from outside the organization, especially those from high-risk geographic regions identified by DCSA. Integrate the email security system with threat intelligence feeds that track domains and infrastructure associated with FIEs. This provides an automated first line of defense, filtering out many malicious emails before they ever reach an employee's inbox.
Start of fiscal year 2025, the period analyzed in the DCSA report.
End of fiscal year 2025.
DCSA releases the 'Targeting U.S. Technologies' report for FY 2025.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.