DCSA Report: Foreign Spies Target US Defense Industry

DCSA: Foreign Spies Target US Defense Experts via Email

INFORMATIONAL
September 18, 2026
3m read
Threat IntelligencePolicy and Compliance

Full Report

Executive Summary

The Defense Counterintelligence and Security Agency (DCSA) released its annual "Targeting U.S. Technologies" report on September 17, 2026, revealing persistent and sophisticated efforts by foreign intelligence entities (FIEs) to compromise the U.S. cleared defense industrial base. The report, analyzing data from fiscal year 2025, highlights that FIEs most commonly attempt to co-opt subject matter experts (28% of incidents) and use email as their primary method for initial contact (30% of attempts). Geographically, entities from the East Asia and Pacific region remain the most significant threat, accounting for nearly half of all collection attempts. The DCSA urges cleared personnel to be vigilant against unsolicited professional and commercial outreach.


Threat Overview

Foreign adversaries are employing a blended approach that combines traditional human intelligence (HUMINT) with cyber-enabled tactics to target cleared U.S. personnel and contractors. Instead of relying solely on technical exploits, FIEs are using social engineering at scale, leveraging professional networking and business opportunities as a pretense to access sensitive and classified information. The DCSA analyzed over 22,000 suspicious contact reports in FY 2025, identifying 2,900 as legitimate attempts by FIEs to gather intelligence.

Key Tactics and Trends

  • Primary Tactic: Exploitation of Experts (28% of incidents). FIEs actively seek out and build relationships with cleared experts, researchers, and engineers to gain their specialized knowledge.
  • Primary Vector: Email (30% of initial contacts). This is followed by academic résumé submissions and web forms, indicating a focus on professional and recruitment channels.
  • Common Lures: Adversaries use a variety of seemingly legitimate approaches, including:
    • Paid consultations and expert network requests
    • Fake job recruitment and talent acquisition
    • Conference invitations and calls for papers
    • Supplier relationships and business partnership proposals
  • Geographic Threat Source: The East Asia and Pacific region was the origin of 48% of all incidents, followed by the Near East at 19%.
  • Targeted Technologies: While broad sectors like Services, Electronics, and Aeronautics were heavily targeted, FIEs also showed strong interest in emerging technologies such as AI, unmanned aircraft systems (UAS), and advanced telecommunications.

Impact Assessment

The success of these foreign intelligence operations poses a direct threat to U.S. national security and economic competitiveness. The theft of sensitive or classified defense technology can erode the U.S. military's technological advantage, accelerate foreign military modernization, and compromise the integrity of the defense supply chain. For cleared contractors and personnel, falling victim to these schemes can result in loss of security clearance, legal repercussions, and significant reputational damage.

Detection & Response

  • Vetting Unsolicited Contact: All cleared personnel should treat any unsolicited professional or commercial offer with skepticism, especially those originating from unknown or foreign entities. Verify the legitimacy of the company, recruiter, and opportunity through independent channels before engaging. This is a key aspect of D3-OT: Olfactory Testing (i.e., a 'smell test' for legitimacy).
  • Reporting: It is critical that all suspicious contacts are reported to the organization's Facility Security Officer (FSO) and through the DCSA's established reporting channels. These reports provide the DCSA with the raw intelligence needed to identify and counter FIE campaigns.
  • Counterintelligence Programs: Cleared facilities must have robust counterintelligence programs that include regular awareness briefings for all personnel. These briefings should cover the latest FIE tactics, common lures, and reporting procedures.

Mitigation

  • User Training: The most critical mitigation is continuous and targeted security training (M1017 - User Training). Personnel must be educated on the specific social engineering tactics detailed in the DCSA report so they can recognize and report them.
  • Email Security: Implement advanced email security gateways that can detect and block spear-phishing attempts. Configure filters to flag emails from high-risk geographic regions or those containing suspicious links or attachments.
  • Limit Public Information: Advise cleared personnel to be cautious about the amount of detailed professional information they share on public platforms like LinkedIn. FIEs use this information for targeting (T1593 - Search Open Websites/Domains).
  • Travel Security: Provide pre-travel security briefings for employees traveling to high-risk countries, as FIEs often use conferences and international travel as opportunities for in-person approaches.

Timeline of Events

1
October 1, 2025
Start of fiscal year 2025, the period analyzed in the DCSA report.
2
September 17, 2026
DCSA releases the 'Targeting U.S. Technologies' report for FY 2025.
3
September 18, 2026
This article was published
4
September 30, 2026
End of fiscal year 2025.

MITRE ATT&CK Mitigations

The most effective mitigation is educating cleared personnel to recognize, vet, and report suspicious outreach attempts.

Using email security gateways to filter and block phishing and spear-phishing emails is a critical technical control.

Mapped D3FEND Techniques:

Audit

M1047enterprise

Collecting and analyzing suspicious contact reports is a form of auditing that provides crucial threat intelligence.

Mapped D3FEND Techniques:

D3FEND Defensive Countermeasures

The primary defense against the social engineering tactics described by the DCSA is a well-informed workforce. Organizations with cleared personnel must implement a continuous counterintelligence and security awareness training program. This training should go beyond generic phishing examples and focus specifically on the lures used by FIEs: fake job offers, paid consultations, and academic collaborations. Use real-world (anonymized) examples from DCSA reports to make the threat tangible. Training should empower employees to 'trust their gut' and provide them with a clear, frictionless process for reporting any suspicious contact to their FSO without fear of reprisal. This human firewall is the most critical asset in detecting these targeted campaigns.

Establish a formal, mandatory process for vetting all unsolicited professional opportunities presented to cleared personnel. This process should be managed by the security department or FSO. Before an employee is permitted to engage with a request for consultation or a job offer, the security team must independently verify the legitimacy of the entity making the offer. This includes checking corporate registration records, verifying contact information through official websites (not from the email itself), and researching the individuals involved. This formalized 'pause-and-verify' step inserts a critical control point between the FIE's approach and the potential victim, disrupting the social engineering lifecycle.

Augment user training with robust technical controls at the email gateway. Since email is the top vector, advanced email security solutions are essential. These tools should use machine learning to analyze email content, sender reputation, and communication patterns to identify sophisticated spear-phishing attempts. Configure policies to apply extra scrutiny or warning banners to emails originating from outside the organization, especially those from high-risk geographic regions identified by DCSA. Integrate the email security system with threat intelligence feeds that track domains and infrastructure associated with FIEs. This provides an automated first line of defense, filtering out many malicious emails before they ever reach an employee's inbox.

Timeline of Events

1
October 1, 2025

Start of fiscal year 2025, the period analyzed in the DCSA report.

2
September 30, 2026

End of fiscal year 2025.

3
September 17, 2026

DCSA releases the 'Targeting U.S. Technologies' report for FY 2025.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

espionagesocial-engineeringphishingdefense-industrial-basenational-security

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.