The modern defence industrial base (DIB) is no longer insulated behind perimeter firewalls and controlled networks. According to a new analysis by the Google Threat Intelligence Group (GTIG), cyber operations by state-linked and criminal actors increasingly strike at the heart of defence manufacturers, contractors and their personnel — effectively making the industry itself a frontline.
Traditionally, espionage against defence targets focused on penetrating secure networks and sophisticated systems. Today, the attack surface has expanded dramatically: adversaries are targeting individuals, personal devices and third-party suppliers in ways that evade conventional security tools. These tactics exploit edge-of-network systems, poorly monitored endpoints and social engineering vectors that are often outside enterprise detection frameworks.
One of the most noticeable trends highlighted in the GTIG report is the strategic focus on personnel. Groups linked to China, Russia, Iran and North Korea have tailored campaigns that exploit recruitment processes, spoof job portals and mimic legitimate hiring communications to trick defence sector employees into compromising credentials or downloading malware. These employment-themed campaigns exploit the inherent trust in job searches and professional networking — turning routine activities into dangerous entry points.
China-nexus groups, in particular, now represent the most active threat actors by volume against defence and aerospace firms, leveraging tactics that target edge devices and operational technology in addition to traditional systems.
The implication for security teams is clear: protecting the defence industrial base today requires visibility that goes well beyond corporate networks — encompassing personal systems, supply chains and individual behaviour.








