Skip to main content
World Today News
  • Home
  • News
  • World
  • Sport
  • Entertainment
  • Business
  • Health
  • Technology
Menu
  • Home
  • News
  • World
  • Sport
  • Entertainment
  • Business
  • Health
  • Technology

Why Fake Identities Are Cheaper and More Dangerous Than Cyber Exploits

August 27, 2026 Lucas Fernandez – World Editor World

In July, prosecutors in Taipei’s Shilin district concluded their case against two local residents, Li Hualun and Chen Mengsen, after they spent a lengthy period setting up LINE accounts—the widely used messaging app in Taiwan—with each profile linked to an authentic Taiwanese phone number. Xiamen Empress Information Technology, a mainland organization that Taiwanese investigators state operates under the command of the Chinese Communist Party’s cyber units, rented the accounts from them. The going rate was about 1,100 RMB per account, call it $160 each, and the accounts were used to build trusted personas and deploy malware against lawmakers, defense think tanks, and semiconductor firms, bypassing traditional technical network defenses entirely.

The incident in Taipei underscores a fundamental shift in state-sponsored espionage. Attackers are bypassing hardened firewalls and multi-factor authentication protocols by purchasing aged, locally registered chat accounts for the price of a modest dinner. Rather than spending millions of dollars on gray-market zero-day software exploits, foreign intelligence services are weaponizing the digital credibility of everyday communications platforms.

The Mechanics of Persona Leasing and the $160 Entry Point

According to Taiwanese investigators, the operation relied on volume and patience. Li Hualun and Chen Mengsen spent months registering accounts on LINE, the dominant messaging app in Taiwan. They leased these accounts to mainland handlers who used them to infiltrate high-value networks.

The economic logic driving this trend is stark. While a working exploit for a major software platform commands millions of dollars on secretive gray markets, a trusted local identity costs about $160. This expenditure yields a return that pure code cannot match: social engineering capability.

Researchers at Citizen Lab and the International Consortium of Investigative Journalists tracked more than a hundred malicious domains tied to this broader campaign. Their findings reveal that attackers utilized artificial intelligence tools to draft phishing messages and select targets. The recipients included legislative staffers, defense analysts, and human rights dissidents.

Nothing technical failed within the target organizations. The networks held firm, and system patches remained current. Instead, the attackers subverted the human element by renting the digital reputation of a free press.

One of the leased accounts was dressed in the name and photo of Chen Yishan, editor-in-chief of CommonWealth Magazine. The operator used this fabricated editorial presence to court an aide in a Taiwanese legislator’s office over months of ordinary political journalism traffic.

There were no malicious links in the initial messages. The cultivation followed a traditional counterintelligence rhythm. Eventually, under the guise of protecting sensitive journalistic sources, the operator asked the target to install a secure communication app. That application contained malware.

When the legal proceedings concluded in July, the two account suppliers received deferred prosecutions and financial penalties totaling just under $6,000. Counterintelligence analysts note that such minimal legal consequences fail to provide a deterrent, functioning instead as a negligible business expense for state-backed operations.

Global Repercussions and the Downing Street Precedent

This methodology is not confined to East Asia. High-ranking Western officials have faced similar credential-spoofing campaigns.

British Prime Minister Burnham experienced a comparable infiltration attempt weeks into his tenure. According to reports published by Politico, Burnham exchanged brief messages with an individual falsely claiming to be Susie Wiles, the White House chief of staff. Burnham grew suspicious, ceased communication, and reported the incident. The British embassy subsequently informed the White House, which verified that Wiles’s personal devices remained uncompromised.

Similar impersonation attempts have targeted senior American leadership. The Federal Bureau of Investigation warned last year about impostors using artificial intelligence to mimic senior officials after an individual posing as Wiles contacted prominent Republicans and business executives. Additionally, the State Department tracked a separate incident where a fictitious Marco Rubio reached out to three foreign ministers.

These episodes expose a critical vulnerability in modern communications: when contact cards and display names serve as primary authentication, simple social engineering easily penetrates high-level offices.

Anthropic, OpenAI's models create fake identities to fool humans in new cyber incident

Organizations managing sensitive operations must adapt their defense strategies. Mitigating these risks requires integrating comprehensive verification protocols across all communication channels. Ensuring robust internal security frameworks often involves partnering with specialized cybersecurity advisory firms to audit human-layer vulnerabilities and credential handling.

Furthermore, defending against sophisticated cultivation campaigns demands rigorous legal and structural responses. Industry leaders frequently consult with corporate intelligence investigators to trace illicit account-rental networks and identify compromised access points before exploitation occurs.

Legislative bodies must also reevaluate statutory penalties for individuals collaborating with foreign intelligence services. Treating account leasing as a minor terms-of-service violation or a light regulatory infraction leaves critical digital infrastructure exposed.

The adversary has made a rational economic choice. When technical barriers become too difficult to breach, foreign intelligence agencies simply invest in the human vulnerabilities that software cannot patch. Protecting modern institutions requires defending trusted digital identities with the same rigor traditionally reserved for network firewalls.

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

Keep reading

  • Man Arrested for Forging Chief Justice John Roberts’ Signature to Dismiss Criminal Case
  • Touching Note Left for New Car Owner Named Bublinka

Related

AI, Artificial intelligence, China, chinese communist party, cyber, uk

Search:

World Today News

World Today News is your trusted source for global journalism — breaking headlines, in-depth analysis, and reporting from around the world.

Quick Links

  • Privacy Policy
  • About Us
  • Accessibility statement
  • California Privacy Notice (CCPA/CPRA)
  • Contact
  • Cookie Policy
  • Disclaimer
  • DMCA Policy
  • Do not sell my info
  • EDITORIAL TEAM
  • Terms & Conditions

Browse by Location

  • GB
  • NZ
  • US

Connect With Us

© 2026 World Today News. All rights reserved. Your trusted global news source directory.
For contact, advertising, copyright, issues email: [email protected]

Privacy Policy Terms of Service