The DOJ seized 13 fake recruitment sites in June, including a clone of a small Australian consultancy, after a joint advisory from the Five Eyes intelligence alliance on AI enhanced espionage.
For a year, strangers had been sending CVs to a Brisbane consultancy that wasn't hiring. The applicants thought they were applying to a defence, trade and policy firm called Horizzen, which the cloned site described as an "architect of influence". Some phoned the cloned number. Some visited the cloned Melbourne address. The real Horizzen, a small outfit with a handful of domestic clients, just fielded the confusion, a spokesperson said.
Then, in June, the US Department of Justice seized the clone.
The fake site, thehorizzen.com, was one of 13 domains the FBI took down in a single wave as part of a multi-agency investigation into alleged Chinese espionage. A senior FBI officer's affidavit alleged that all 13 sites had been created to "recruit individuals in the United States to obtain sensitive and possibly classified information in exchange for monetary payments" on China's behalf, using "aliases, stolen identities and AI-generated photographs" to deceive applicants. The Horizzen-impersonating site was registered in India, per the FBI court filing.
The Brisbane firm first noticed suspicious emails and calls from mid-2025, about a year before the June 2026 seizure. Eager jobseekers (defence analysts, trade specialists, Indo-Pacific policy researchers) sent their real CVs and cover letters to Horizzen's actual Australian email address, believing the clone was the same organisation. Some were invited to "more privileged information" through encrypted channels, though no applicant is documented as having crossed that line.
Within 24 hours of an early-June public advisory from the Five Eyes intelligence alliance (Australia, the UK, the US, Canada and New Zealand), the FBI obtained a warrant for the Horizzen-impersonating site. The advisory named the same HR-recruiter tradecraft: clone a legitimate consultancy, harvest CVs from defence and policy specialists, push vetted candidates toward encrypted channels, AI-enhanced at scale. The five governments issued the warning together. That joint step signals how seriously the impersonation tactic is now being treated.
One of the other seized sites, Catalyst Global Solutions, claimed to be "among DC's top firms" while listing a Lahore, Pakistan address and recruiting analysts in "international relations" and "geo-politics" through an Australian job website. A third firm pretended to be based in Western Australia, but its job adverts were posted by someone in Thailand; its LinkedIn profile still claimed a Melbourne office. The pattern: small, plausible-looking cover companies placed where defence and policy talent would actually look.
The AI claim is what makes this wave new. FBI assistant director for counter-intelligence Roman Rozhavsky said the sites "illustrate the lengths the Chinese government's intelligence services will go to as they try to use AI-generated content to trick, recruit, or coerce". The Guardian's reporting does not present forensic proof that AI generated the specific Horizzen clone's content. The AI role here is the alleged pattern in the affidavit and Rozhavsky's statement, not a demonstrated fact for this case.
China's embassy in Canberra rejected the allegations, calling them "purely smears and denigration" with "no factual basis". The denial is on the record. The FBI's evidence so far consists of a sworn affidavit and 13 domain seizures.
The tactic is not new in Australia. ASIO's 2024 annual threat assessment named a spy ring it called "the A team", which targeted Australians on LinkedIn with similar approaches. The June operation used cloned websites, registered domains, and a multi-country public warning, a step up in both tradecraft and institutional response.
The Guardian states it explicitly: it is unknown whether the network succeeded in extracting sensitive information. No one has been indicted. No classified documents are confirmed stolen. The FBI's action so far is website seizures, not prosecutions. The operational value of 13 fake sites can be measured in the applicants they managed to talk to, defence specialists who thought they were emailing a real consultancy and who now sit in a database somewhere, whether or not they ever crossed into encrypted chat.
For Horizzen, the after-effect is the strange one. A small firm that was never hiring now has its name attached to an FBI case file and a year of confused applicants' CVs in its inbox.