The images in this article were generated with artificial intelligence. How we publish
On 30 September 2026, the UK domestic intelligence service (MI5) issued an unusual public warning that over 100 UK-related academics have participated in projects funded by the China General Technology Research Institute (CGTRI, also known as the China Academy of General Technology). According to MI5, this institution acts as a facade of the Chinese Ministry of State Security (MSS) and its funding is aimed at improving technical capabilities that the MSS can use in espionage operations. The British agency urged universities to immediately review collaborations with CGTRI and to trace the origin of the funding, while also warning of possible criminal consequences under the National Security Act 2023 if material assistance is provided to a foreign intelligence service.
What is confirmed: MI5 issued a security alert with the above assessment and requested academic institutions to review links with CGTRI; the Chinese embassy in London responded publicly by denying the allegations and calling them unfounded. There is also a previous report of the think tank UK-China Transparency that has pointed to overlaps of staff between CGTRI and the University of International Relations, an institution marked by close links with the MSS. These are the elements of the factual chain that have been officially disseminated or published by public organizations.

Estimates and uncertainties: the number of "more than 100" academics, the exact nature of each researcher's individual contribution and if they were aware of the origin of the funding are data that MI5 presents as an evaluation but has not publicly broken down with specific names or projects. It is also not verified in the public domain which specific CGTRI works have been operationally used by the MSS or to what extent academic results have been transferred to offensive intelligence applications. Therefore, there is a mixture of official facts and assessments that require additional research to establish the complete chain of causation.
From a technical perspective, the fields mentioned - artificial intelligence, cybersecurity, covert communications and steganography - are dual use by nature. Research in IA can improve the ability to process large volumes of signals, recognize patterns in encrypted communications, automate vulnerability detection and generate synthetic content for influence operations. Steganography and covert communications facilitate the concealment of instructions and exfiltration of data without raising alarms; advanced techniques here allow to camouflage channels in apparently benign traffic (e.g. images, video or metadata). Cybersecurity research, although legitimate in academic environments, also produces tools and knowledge that can be adapted for offensive exploitation - from penetration tests to explosion development - if they fall into the hands of intelligence services with strategic objectives.
Who does this affect? Direct to individual academics and research teams working with Chinese institutions or receiving funding whose origin has not been strictly verified. At the institutional level, UK universities themselves are at the centre: they face reputational, legal and financial risks, as well as the possibility of losing access to sensitive projects or international staff. At the national level, the risk identified by MI5 is for the MSS to use this research network to improve capacities that are then used in operations against British interests - industry, infrastructure, public services or strategic research - which could result in intellectual property losses and operational vulnerabilities.
The immediate practical consequences include increased pressure on research and university compliance offices to strengthen the traceability of funds and due diligence, potential suspensions of disputed projects and a cooling of academic cooperation with Chinese institutions. In the medium term, a stronger policy review of international partnerships in sensitive areas can be generated, and demands for transparency by financiers and governments increased.
Specific measures to be taken by researchers and universities:: first, complete mapping of all collaborations and projects with Chinese institutions, clearly identifying the sources of funding and any intermediary. Secondly, to require contracts specifying intellectual property, publication of results and restrictions on use; any income or subsidy with opaque clauses should be subject to legal review. Third, segregate and protect sensitive data: use isolated computer environments (air-gapped or secure enclaves), strict access controls and exfiltration monitoring. Fourth, strengthen security training for Pis and students, including facade financing signals, information collection risks and data protection measures. Fifth, establish or strengthen the figure of the Research Security Officer and protocols to scale up doubts to legal and institutional security teams. Sixth, in the event of reasonable suspicion of the origin of funds or the purpose of the project, consult with the competent authorities and, where appropriate, suspend cooperation until the case is clarified.

For individual researchers: document all funding offers and agreements, request transparency on the origin of the funds, avoid transferring sensitive data without institutional authorization and request advice on export controls and intellectual property before sharing code or non-public data sets. If you are under pressure to hide the source of funding or censor research lines, notify your university and, if necessary, the authorities.
At the legal level, MI5's warning recalls that the National Security Act 2023 creates crimes for materially facilitating the activities of a foreign intelligence service related to the United Kingdom. Criminal consequences are a real factor that requires universities and research staff to strengthen due diligence and the registration of decisions. For practical guidance on research security and cyber threats, institutions can rely on agencies such as MI5 ( https: / / www.mi5.gov.uk) and the National Cyber Security Centre ( https: / / www.ncsc.gov.uk), which provide resources and guidelines on risks and protection.
Finally, it is important to separate policy from scientific practices: international collaboration is essential for academic advancement, but it requires clear rules when there are national security components at stake. Universities that act quickly and with transparent procedures will better protect both their academic freedom and institutional integrity. Researchers must assume that transparency in funding and care in data management are no longer just good academic practices, but security obligations that may have legal and national security implications.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...