Fake Press, Real Spies: How China Tried to Infiltrate Taiwan’s Civil Society
Source:CommonWealth Magazine
As Taiwan's mass recall movement dominated headlines, a fraudulent interview request impersonating CommonWealth Magazine's editor-in-chief — sent under the ICIJ's name — contacted media outlets, think tanks, and legislators' offices, sustaining conversations for nearly a year and even offering a free Samsung phone. An investigation by CommonWealth, ICIJ, and the University of Toronto's Citizen Lab exposed the scheme as a transnational Chinese espionage operation, with IP addresses linked to hackers who targeted semiconductor companies last year.
Views
Fake Press, Real Spies: How China Tried to Infiltrate Taiwan’s Civil Society
By Silva Shihweb only
The message looked entirely routine. At least at first.
In May 2025, as Taiwan's mass recall movement (Read: Taiwan’s “Mass Recall” Movement Explained ) was consuming headlines, an interview request landed in the inbox of Hung Kuochun, chief operating officer of Watchout, a Taiwanese online civic media outlet. The sender identified herself as “Yi-Shan Chen”, a journalist with the International Consortium of Investigative Journalists (ICIJ), citing the political turmoil surrounding the recall and impeachment campaign against President Lai Ching-te as the reason for reaching out.
Yi-Shan Chen is, in fact, the name of the editor-in-chief of CommonWealth Magazine. In 2016, CommonWealth was invited to participate in ICIJ's Panama Papers investigation (Read: Panama Papers Open New Era of Megaleaks | Can Tax Havens be Rooted Out?). Chen joined ICIJ as a full member the following year and has continued working on cross-border investigations since. An interview request from her, bearing the ICIJ name, would hardly seem unusual.
But something felt off to Hung. "I'd never met or been in contact with Yi-Shan before," he recalled. What struck him most was the sender's email address — not an official ICIJ domain, but a Gmail account with an oddly disposable name: [email protected].
His instincts were right. A six-month investigation by CommonWealth, conducted in partnership with ICIJ and the Citizen Lab at the University of Toronto, has uncovered that "Yi-Shan Chen" was not the editor-in-chief of CommonWealth at all, but a front for a Chinese state-linked intelligence operation — one with digital fingerprints connecting it to the same hacker infrastructure used to target Taiwan's semiconductor industry.
A Network of False Identities
Hung was not the only target. Over the past year, at least five individuals in Taiwan were contacted by the same impersonator: media workers, think-tank analysts, a Democratic Progressive Party city councilor, a legislative aide, and one person with prior experience at Taiwan's National Security Council. Targets were also reached in the United States, including a worker at an American nonprofit organization.
Beyond Taiwan, ICIJ confirmed that two of its other journalists were separately impersonated in operations targeting Uyghur, Tibetan, Taiwanese, and Hong Kong human rights communities. Even Taiwan's overseas representatives received overtures from individuals posing as ICIJ members based in Europe and North America.
ICIJ journalist Scilla Alecci, who leads the organization's "China Targets" investigation series (https://www.icij.org/investigations/china-targets/) on Beijing's transnational repression of dissidents, believes the timing may be related. "It could be connected to our April investigation into how China suppresses dissidents abroad," she said. CommonWealth had no involvement in that series, yet its editor-in-chief's identity was still borrowed as cover.
The real Chen Yi-shan filed reports with Taiwan's police and Bureau of Investigation on April 11 of last year after learning of a second impersonation incident. The fake "Yi-Shan Chen," however, continued making contact with new targets using virtually identical methods.
The Hook: An Interview That Was Never an Interview
The initial approach followed a consistent playbook. Consider the case of Hsiao Wei (a pseudonym), a legislative aide who had been in his post for just one month when, last March, he received an unprompted message on Line from someone claiming to be CommonWealth's editor-in-chief.
The account displayed a profile photo of the real Chen Yi-shan, listed her titles and credentials — albeit with small inaccuracies in her Chinese name and job description — and opened with a question about whether the relationship between Ukrainian President Zelensky and U.S. President Trump might affect Taiwan. When Hsiao Wei asked why he had been chosen, the impersonator explained she was gathering broad perspectives from regular Taiwanese citizens, and the conversation continued.
Within minutes, the tone shifted: "Your perspective is quite unique. I'd love to conduct a more in-depth interview with you over email."
A week later, Hsiao Wei received a message from a Proton Mail address — the encrypted email service — with what appeared to be an interview outline, protected by a password and prompting him to download and open the file.
That download, investigators later determined, contained malware.
In Hung Kuochun's case, the operation was more visually sophisticated. The "interview outline" he received was a meticulously crafted fake Google Document, built using Google's drawing tools. It was designed to look identical to a genuine Google file, but it prompted Hung to enter his real Google account credentials to access it — a classic credential-harvesting phishing page.
Targeting People, Not Systems
"This is a classic social engineering attack," said Chang Che-cheng, a threat intelligence analyst at Taiwanese cybersecurity firm TeamT5, who has long tracked Chinese hacking groups. "The attacker first disguises themselves as someone you know or trust, to get you to open a file or link carrying malicious code."
Unlike conventional cyberattacks — which target system vulnerabilities, plant malware on servers, or exploit software flaws — social engineering exploits human trust. The attack surface is not a firewall. It is a relationship.
Fortunately, CommonWealth found no evidence that any of the contacted individuals had fallen for the trap. Nearly all of them reached out to the magazine's editorial team to verify the communications before taking further action. Taiwan's Bureau of Investigation is continuing to look into the impersonated Line accounts.
But the breadcrumbs left behind by the operation proved valuable in another direction: they gave investigators a thread to pull.
The Trail Leads to Semiconductors
Working with the Citizen Lab at the University of Toronto and TeamT5, CommonWealth traced the malicious domains linked to this campaign and found that all of them were hosted on cloud and network infrastructure commonly used by Chinese threat actors.
More significantly, while these domains appeared to be ordinary websites on the surface, they all resolved to a single master domain: entruhub.com. Beneath it, a cluster of seemingly random subdomains all pointed to the same IP address — many doors, one building.

That IP address had appeared before. In July of last year, U.S. cybersecurity firm Proofpoint published a report identifying a cluster of Chinese hacking groups, including one tracked as "UNK_SparkyCarp," that had targeted between 15 and 20 Taiwanese semiconductor companies. The attackers posed as job seekers and investors to send inquiries — laced with malicious links and attachments — to semiconductor firms and industry analysts.
The parallels with the ICIJ impersonation campaign are striking: nearly identical phishing techniques, and the same IP infrastructure.
Citizen Lab's investigation revealed even broader scope. Over the past year, more than 100 similar domain structures have been identified, targeting over a dozen human rights workers across Uyghur, Tibetan, Hong Kong, and Taiwanese communities, using a range of false identities such as journalists, film directors, and members of the European Parliament.
| Community Targeted | Primary Method |
| Taiwan human rights and political groups | Impersonation of ICIJ journalists |
| Uyghur human rights groups | Impersonation of journalists, film directors, European Parliament members; fake security alert emails leading to phishing pages |
| Tibetan human rights groups | Fake security alert emails leading to phishing pages |
| Hong Kong human rights groups | Fake security alert emails leading to phishing pages |
Source: Citizen Lab, University of Toronto
It has not been possible to definitively confirm whether "UNK_SparkyCarp" operates under the direction of China's Ministry of State Security, Ministry of Public Security, the United Front Work Department, or the People's Liberation Army. What is clear is that the intelligence community has already categorized this operation as part of China's broader transnational espionage apparatus.
In response to ICIJ's inquiries, a spokesperson for the Chinese Embassy in Washington stated: "Tracing the source of cyberattacks is technically complex. We hope relevant parties will act with professionalism and responsibility, and base their characterizations of cyber incidents on solid evidence rather than speculation and accusation. China consistently opposes and cracks down on all forms of cyberattacks."
The Long Game
What distinguishes this operation from ordinary cybercrime is its patience.
Mark Kelly, a Proofpoint analyst who contributed to last year's semiconductor report, explained the logic: sending malware from the outset is easily flagged by security software. Building rapport first — sometimes over months — before introducing malicious content is both harder to detect and more likely to succeed. "Financially motivated attackers rarely sustain this kind of prolonged back-and-forth with targets," Kelly said. "This is not just social engineering. It is textbook espionage."
In at least two cases, the impersonator even offered to send physical Samsung smartphones to the targets — ostensibly to make communication easier. No phone was ever actually delivered, but the gesture underlines the resources and commitment being invested.
The questions being asked were not, by themselves, sensitive: contact information for human rights organizations, opinions on the recall movement, general political observations — information largely available through public sources. The intelligence value of any single response may have been limited. The goal, analysts believe, was network mapping: constructing detailed profiles of key individuals in Taiwan's civil society, political circles, and media ecosystem before any direct recruitment or higher-stakes approach.
Legislator Puma Shen (沈伯洋), who has long tracked Chinese information operations, noted that similar patterns emerged during the COVID-19 pandemic, when groups posing as think-tank scholars began approaching Taiwanese politicians and retired officials. "Our hypothesis is that during the pandemic, when they couldn't send people physically, their visibility into Taiwan dropped sharply," he said. "They shifted to this model to compensate."
(Photo: Kai-Cheng Chuang)
The approach, he added, follows a well-worn arc: begin with innocuous questions, establish trust, then gradually introduce financial incentives — "writing fees" or "interview honoraria" — as a bridge into transactional intelligence exchange. "They can send out a hundred messages. If even one succeeds, it's enough," he said. The cost of outreach is negligible.
A national security official confirmed that similar protracted contact patterns have appeared in cases prosecuted under Taiwan's National Security Act. But prosecuting this particular campaign faces serious obstacles: while domestic laws on personal data protection, document forgery, and defamation offer potential legal pathways, they are largely ineffective when the perpetrators are beyond Taiwan's jurisdiction.
Outsourcing the Spy Work
Two years ago, TeamT5 stumbled upon leaked contracts and internal communications from i-Soon, a Chinese cybersecurity company. Those documents revealed that i-Soon had contracted with the PLA, the Ministry of State Security, and the Ministry of Public Security to conduct cyber espionage — offering the clearest public evidence yet of how private Chinese firms have been integrated into the state's intelligence operations, functioning as commercial subcontractors in what amounts to a full intelligence-industrial complex.
The ICIJ impersonation campaign bears similar hallmarks of private-sector involvement.
"Compared to nation-state hacking groups, the domain clustering in this case was traced relatively easily," said Rebekah Brown, a senior researcher at the Citizen Lab and former director of operations for the U.S. Marine Corps Cyberspace Command and cybersecurity professional at Apple. The relative sloppiness, she suggested, points away from elite state operators.
A Taiwanese national security official observed that the impersonator appeared to follow a standard working schedule — responses came only during business hours — and noted that the conversational content felt more like that of a commercial online opinion-monitoring company than a trained intelligence officer. "It doesn't feel like it comes directly from China's security services," the official said. "There seems to be an additional layer in between."
That intermediate layer is increasingly the norm.
China's intelligence collection network now operates through a layered public-private architecture, extending far beyond traditional military and government targets to encompass journalists, civil society actors, and anyone connected to networks of political relevance.
The Limits of the Surveillance State
History offers a cautionary counterpoint. East Germany's Stasi built what was, at its peak, arguably the most comprehensive domestic intelligence apparatus in history — a surveillance machine that permeated every corner of society. Yet that vastness did not make the regime more stable. It generated enormous volumes of low-quality intelligence, consumed extraordinary resources, and ultimately accelerated the hollowing out of the system it was meant to protect.
As China expands its intelligence-gathering reach — outsourcing operations, widening target lists, investing in long-horizon social engineering campaigns — it is also accumulating the inefficiencies, distortions, and blind spots that accompany any system built on suspicion and control.
Have you read?
- Taiwan Indicts TEL in TSMC 2nm Leak: Implications for the Semiconductor Sector
- Landmark Taiwan National Security Act Ruling: Former TSMC Engineers Sentenced in 2nm Trade Secret Theft
- When Trust Breaks: TSMC Files Lawsuit Against a Former Top Executive Who Joins Intel
Translated from Mandarin Chinese, Uploaded by Ian Huang





