Singapore-Registered Infoassa: How a Fake Think-Tank Mirrored Foreign Intelligence Recruitment Tactics

A Singapore-registered entity called Infoassa presents a textbook illustration of how foreign intelligence recruitment operations exploit institutional legitimacy, digital anonymity, and the professional ambitions of policy specialists — and why such operations persist even after exposure.

The thesis is straightforward: Infoassa was not merely a clumsy imitation of a think-tank. It was a deliberately constructed recruitment infrastructure, calibrated to attract individuals with access to privileged government information, and its architecture — fake employees, plagiarised event listings, shared technical fingerprints with a US-seized website — reflects a methodology that intelligence analysts and law enforcement have documented repeatedly, yet struggle to suppress.

Maria, a former United States government employee with experience on Indo-Pacific affairs, encountered Infoassa through what appeared to be a routine job advertisement for a remote policy analyst role. The posting was credible enough on its surface. Her background aligned precisely with the stated requirements. But the recruitment process unravelled quickly: responses came from a personal Gmail account rather than an organisational one, a writing test asked her to analyse Washington’s “pressure tactics” ahead of a Trump-Xi summit while explicitly discouraging the use of open-source information, and a US$500 “reward” was dangled for compliance. The instruction to “indicate the source of the information” provided carried an implication that unsettled her immediately. “I thought, at best, they’re trying to steal my work,” she told CNA. At worst, she recognised the contours of a foreign intelligence recruitment attempt.

Her instinct was well-grounded. A CNA investigation found that Infoassa’s online presence, active since its domain registration in September 2025, contained multiple fabricated elements. At least one employee persona — a “James Scoot” — claimed affiliations with Vriens & Partners and the Institute of Southeast Asian Studies, both of which confirmed no such individual had ever worked there. Profile photographs attached to Infoassa personas tested as likely AI-generated. Facebook event listings advertising geopolitical seminars at a Beach Road address had their descriptions lifted verbatim from publications by organisations such as the US-based Council on Foreign Relations. The most recently advertised event, scheduled for August 7, never took place.

The apparent crudeness of these fabrications is, paradoxically, beside the point.

Associate Professor Dylan Loh of Nanyang Technological University’s Public Policy and Global Affairs programme told CNA that such operations function on volume and low cost rather than precision. “It’s a low-cost, set-and-forget kind of system that is easily discardable,” he said, noting that advances in AI have made it substantially cheaper to generate convincing front organisations at scale. The operators, he added, need not achieve a high recruitment rate — one or two sources with access to sensitive information can prove consequential enough to justify the entire exercise. Some of these operations are further insulated from scrutiny because they are executed by for-profit intermediaries acting on behalf of state actors, contractors who, as Assoc Prof Loh observed, “sometimes do not put as much care and attention into the endeavour as one might expect.”

What distinguishes Infoassa from some of its predecessors is that it established actual corporate infrastructure in Singapore. Filings from the Accounting and Corporate Regulatory Authority show the entity was originally incorporated in August 2024 under the name Xinhaiyi Pte Ltd, adopting the Infoassa name in October 2025. Its registered address at Gateway East in Beach Road maps to a corporate secretarial services provider — a common arrangement, but one that lends a veneer of institutional legitimacy. Ownership transferred to a foreign national in late May. When CNA visited the registered address, no signage, logo or observable artefact connected to Infoassa was present. Unlike the Institute of East Asia Strategic Studies, another Singapore-claimed fake think-tank flagged by Chatham House associate fellow Dr Bill Hayton in late June, Infoassa had gone to the additional step of embedding itself within Singapore’s regulatory framework rather than relying solely on a website.

The technical layer of CNA’s investigation adds a further dimension. Analysis of Infoassa’s website infrastructure identified shared features with TheTruthInfo, a domain seized by US authorities in June as part of what Washington characterised as a Chinese military intelligence operation targeting Americans with access to classified or sensitive government information. Both sites used the same distinctive administrator email address from the Proton service provider and shared backend content-loading systems, several of which were already embedded in Infoassa’s infrastructure before TheTruthInfo’s seizure. Infoassa’s underlying website code also contained a configuration for simplified Chinese, despite the site being entirely in English. An independent analysis by Max Lesser, a senior analyst at the Foundation for Defense of Democracies who studies malign foreign influence, corroborated these findings. CNA was careful to note that shared technical features do not definitively establish common ownership or control.

The recruitment profile Infoassa targeted was not accidental. Job advertisements posted since at least January appeared on platforms including the US-based Workable and the Taiwanese platform Cake.me, as well as in online communities such as Effective Altruism and Jobs That Are Left — communities that attract candidates oriented toward politically progressive or internationally engaged work. Roles were framed as remote and part-time, paying between US$1,500 and US$4,000 per month, with a clear preference for applicants carrying former government, military, parliamentary or think-tank experience. This targeting mirrors the methodology outlined in a June bulletin by the Five Eyes intelligence-sharing partnership, which warned of Chinese military intelligence services using front companies to approach individuals with access to privileged information, before progressively escalating requests toward classified material.

The Dickson Yeo case from 2020 remains the most prominent Singaporean precedent: Yeo was sentenced by US authorities for acting as a foreign agent on behalf of China, having used LinkedIn to identify and recruit former US government and military employees, paying them to produce reports that progressively probed their access to sensitive information. The Infoassa operation follows the same structural logic, updated for a post-pandemic remote-work environment where the absence of physical offices raises fewer immediate red flags.

Infoassa’s website went dark shortly after Dr Hayton flagged it on X on August 4. But Lesser’s assessment of why such operations persist regardless of exposure is instructive: “This activity continues even after it is exposed because, quite frankly, there is no reason for the actors to stop. The methods still work and the costs remain low.” If a domain is exposed but not seized by authorities, its operators face no compulsion to abandon it. And as Assoc Prof Loh noted, each exposure cycle can itself function as operational feedback — a means of refining the next iteration of the same playbook.

The implication is uncomfortable. Singapore’s status as a credible institutional address — a jurisdiction with functional corporate registration, an internationally recognised research community, and deep integration into regional policy networks — makes it an attractive staging ground for exactly this kind of operation. The regulatory architecture that confers legitimacy on genuine entities here can be appropriated, at modest cost, to lend cover to fabricated ones. Until the friction of establishing such fronts increases substantially, whether through faster cross-agency detection, stricter beneficial ownership verification, or coordinated domain enforcement, the calculus for operators remains favourable. Infoassa may be gone. The playbook is not.

Leave a Reply

Your email address will not be published. Required fields are marked *