09/17/2026 | Press release | Distributed by Public on 09/17/2026 09:05
WASHINGTON, D.C. - Foreign intelligence entities continued to target the U.S. cleared defense industrial base through expert outreach, employment-related approaches, commercial activity and cyber operations, according to a new report released by the Defense Counterintelligence and Security Agency (DCSA) on Sept. 17, 2026.
The 2026 annual report - Targeting U.S. Technologies: A Report of Threats to Cleared Industry - examines foreign attempts during fiscal year 2025 to gain unauthorized access to sensitive and classified information and technology held by cleared industry and academia. DCSA received more than 22,000 suspicious contact reports during the period and identified roughly 2,900 incidents involving foreign entities seeking sensitive information or technology.
The report identifies exploitation of experts as the most frequently reported method of operation, accounting for 28 percent of incidents. Foreign entities often sought access to cleared subject matter experts, researchers, and technical personnel to obtain specialized knowledge. Email remained the most common method of contact at 30 percent, followed by academic résumé and web form submissions.
East Asia and the Pacific remained the leading source of reported threats, accounting for 48 percent of DCSA reporting, while the Near East accounted for 19 percent. Together, the two regions represented 67 percent of FY 2025 reporting.
The most frequently targeted technology categories: Services and Other Products, Electronics, and Aeronautic Systems accounted for 41 percent of reporting. Foreign entities also pursued emerging and enabling technologies, including artificial intelligence-enabled software, unmanned aircraft systems, telecommunications, advanced electronics, modeling and simulation, and restricted satellite imagery.
The report describes how foreign entities use seemingly routine professional and commercial channels - including paid expert consultations, talent recruitment, conference invitations, résumé submissions, supplier relationships, partnership proposals, and direct technology requests - to seek access to protected information. It also notes that cyberactors continue to target public-facing websites, contractor networks, and organizational points of trust.
DCSA encourages cleared contractors, facility security officers, and cleared personnel to remain alert to suspicious contacts; validate unsolicited employment, consultation, and business opportunities; and report potential foreign collection activity through established security channels. The report underscores that timely suspicious-contact reporting advances DCSA's ability to identify evolving threats and provide relevant threat information to cleared industry.