Kevin Mallory maintained a clandestine relationship with People's Republic of China intelligence operatives from 2014-2017 Credit: Thinkstock During a routine secondary inspection by the U.S. Customs and Border Protection (CBP) personnel at Chicago’s O’Hare Airport, Kevin Mallory was found to be carrying $16,500 after having declared he was not carrying over $10,000 on his customs forms. The Customs Officer allowed Mallory to amend his form, and Mallory went on his way.This incident on April 21, 2017, was the beginning of the unraveling of Mallory’s espionage relationship with the People’s Republic of China’s intelligence services (PRCIS). You see, when Mallory arrived in Chicago, he was arriving from Shanghai, China, where he had just completed a series of meetings with his PRCIS handlers. The U.S. Department of Justice announced Mallory’s arrest on June 22, 2017, and made publicly available the criminal complaint against Mallory. Who is Kevin Mallory? According to the criminal complaint, Mallory is a 60-year-old, self-employed consultant working out of his home in Leesburg, Virginina. He is educated, a graduate of Bringham Young University, is fluent in Mandrin Chinese, and was active duty military from 1981-86. From 1987-90, Mallory worked within the U.S. Department of State, within the Diplomatic Security Service. He left the State Department in 1990 and went to work for a variety of U.S. defense contractors and on U.S. Army active duty deployments from 1990-2013. His foreign assignments included the PRC and Taiwan. His security clearance was terminated in 2012 when he left government service.On May 24, 2017, the FBI conducted a follow-up to the CBP interview with Mallory. During this voluntary interview, Mallory shared a tale in which he said he had been contacted by a Chinese recruiter via a social media site and that he had traveled to the PRC in March and April of 2017 for interviews. During this same interview, Mallory shared how he had reached out to former colleagues within the U.S. government and requested their assistance making contact with a specific department within an unidentified government entity. The FBI shares in the criminal complaint that this contact continued after the CBP interview in April 2017.On May 12, 2017, Mallory said one of his contacts had arranged a meeting with an individual from the desired department within the unidentified government entity, and during this meeting, Mallory claimed he told his interlocutor that he believed the individuals with whom he met in March might be associated with the PRCIS. Mallory continued to dissemble, and his tale was not holding water. Mallory’s clandestine relationship with the PRCISAs the interview with Mallory continued, it was revealed that over several years, Mallory maintained a clandestine relationship with the PRCIS. The PRCIS used the Shanghai Academy of Social Science (SASS) as their operational cover mechanism for their engagement with Mallory. The SAAS cover arrangement served as appropriate rationale for Mallory’s continued contact with PRC nationals and his periodic travel to China. Reading the criminal complaint and Mallory’s description of his actions, there is no doubt Mallory was acting on behalf of the PRCIS as a fully witting and collaborative manner.During his travels to China in March and April of 2017, Mallory was trained in the use of a clandestine piece of covert communications equipment. He was paid by the PRCIS $10,000 in March and $15,000 in April. The device was designed to capture messages and images and securely transmit the information from Mallory to his PRCIS contacts. During the short investigation, the FBI conducted multiple voluntary interviews with Mallory during which he described his clandestine relationship and how the covert communications device operated. When Mallory demonstrated the PRCIS device for the FBI, previously shared messages between Mallory and the PRCIS were exposed and viewed by the FBI special agents. These messages on the device contained U.S. government classified materials at the Secret and Top Secret level. Furthermore, it was clear Mallory was actively using the device during the month of May 2017 to communicate with the PRCIS. Those documents found on the device were later confirmed to have come from the government entity to which Mallory had been cajoling his former colleagues to make an introduction. The documents were fresh, not old documents, that he had secreted during his time within government. The governmental entity confirmed the classification of the documents at the Secret and Top Secret levels were still appropriate when the documents were transmitted to the Chinese in May 2017.How much classified material did Mallory share?What is not yet known is what or how much classified material Mallory provided to the PRCIS over the course of his three-year clandestine relationship. The obvious question: How did Mallory come to possess these documents? The answer, no doubt, is being investigated. There may be a trusted insider who has broken trust by providing to Mallory the classified documents, which Mallory shared onward with the PRCIS. This is yet another instance of an individual with clandestine ties to the PRCIS being arrested in 2017. In April, Candace Claiborne, a U.S. State Department employee was arrested and charged with espionage. She, too, had lived and worked within the PRC, had accepted and responded to direct tasking from her PRCIS contacts, and had been remunerated for her efforts. There is no doubt. The PRC intelligence activities in the U.S. and beyond have shown no signs of letting up. Related content news analysis China’s MSS using LinkedIn against the U.S. The head of the U.S. National Counterintelligence and Security Center says China's MSS is using social networks, specifically LinkedIn, to target, access, and recruit U.S. sources. By Christopher Burgess Aug 31, 2018 4 mins Social Engineering Cybercrime Security news analysis Tesla insider with expired NDA spills the tech beans A former Tesla engineer with an expired non-disclosure agreement (NDA) shared inside technical information on an obscure forum, which was quickly shared across multiple social media platforms. By Christopher Burgess Aug 30, 2018 3 mins Risk Management Security news analysis Horizon Air tragedy highlights airline insider threat vulnerability The ease at which a Horizon Air employee was able to steal and crash a Bombardier Q400 turboprop will likely prompt airlines to develop an insider threat mitigation strategy to close this vulnerability. By Christopher Burgess Aug 13, 2018 4 mins Security news analysis How did the TimeHop data breach happen? Compromise of an employee's credentials, lack of multi-factor authentication, and weak insider threat analysis all played a factor in the recent TimeHop data breach in which 21 million user accounts were compromised. By Christopher Burgess Aug 10, 2018 4 mins DLP Software Analytics Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe