NASA Employees Duped in Chinese Phishing Scheme Targeting U.S. Defense Software

The Office of Inspector General (OIG) of the U.S. National Aeronautics and Space Administration (NASA) has revealed how a Chinese national posed as a U.S. researcher as part of a spear-phishing campaign to obtain sensitive information from the space agency, as well as from government entities, universities, and private companies, in violation of export control laws.

“For years, NASA employees and research collaborators thought they were simply sharing software with colleagues. Instead, they were emailing sensitive defense technology to a Chinese national who was impersonating U.S. engineers.”

— NASA OIG

The Song Wu Indictment

The individual linked to the campaign was identified as Chinese national Song Wu in September 2024, when the U.S. Department of Justice (DoJ) announced charges against him for orchestrating a multi-year phishing scheme that stretched from January 2017 to December 2021 and involved targeting dozens of U.S. professors, researchers, and engineers.

Some of the victims of the campaign were employed at NASA, the Air Force, the Navy, the Army, and the Federal Aviation Administration, while the others worked at major universities and private sector firms.

State-Sponsored Espionage

According to the 2024 indictment, Song was an engineer at the Aviation Industry Corporation of China (AVIC), a Chinese state-owned aerospace and defense conglomerate founded in 2008. In an attempt to obtain modeling software used for aerospace design and weapons development, Song and his co-conspirators are alleged to have conducted extensive research on their targets by masquerading as friends and colleagues to gain access to proprietary software and source code.

The OIG said the scheme was successful in a handful of cases where victims shared the sensitive information with the imposter accounts managed by Song et al without realizing they were violating U.S. export control laws.

Charges and Penalties

Song has been indicted on counts of wire fraud and 14 counts of aggravated identity theft, and faces a maximum sentence of 20 years in prison for each count of wire fraud. He also faces a two-year consecutive sentence if convicted of aggravated identity theft. The 40-year-old remains at large.

FBI Most Wanted

Adding Song to the U.S. Most Wanted List, the U.S. Federal Bureau of Investigation (FBI) said the specialized software could be used for industrial and military applications, including the development of advanced tactical missiles and aerodynamic design and assessment of weapons.

Red Flags to Watch For

“As phishing campaigns continue to become more sophisticated, there are common clues that can betray scammers and expose their export fraud schemes,” the OIG said. “In Song’s case, he made multiple requests for the same software and did not justify why he needed it.”

The OIG highlighted several warning signs that organizations should watch for:

  • Repeated requests: Multiple requests for the same software without clear justification
  • Unusual payment methods: Suggestions of suspicious wire transfers or unconventional payment sources
  • Abrupt changes: Sudden changes to payment terms or source of funding
  • Unconventional transfers: Attempts to mask identity and evade shipping restrictions through unusual transfer methods

The Bottom Line

This case underscores the persistent threat of state-sponsored espionage targeting U.S. defense and aerospace technology. The sophistication of these phishing campaigns continues to evolve, making it critical for researchers, engineers, and government employees to verify the identity of anyone requesting sensitive software or technical data.

Export control compliance isn’t just bureaucratic red tape—it’s a national security imperative. When in doubt, verify. When something feels off, report it. The cost of complacency can be measured in compromised defense capabilities and stolen intellectual property worth billions.


Song Wu is currently on the FBI’s Most Wanted list. Anyone with information about his whereabouts is urged to contact the FBI at tips.fbi.gov.

Tzar C. Umang is a technology leader with over 15 years of experience making new technologies work for different industries. As the Chief Technology Officer at Makerspace Innovhub OPC and the Lead Developer for SUI Philippines, he leads projects that create growth and opportunities for everyone. With a strong background in blockchain development, AI engineering, and cybersecurity, Tzar has worked with organizations like the DOST Smarter Philippines Project Management Office and US startup Auto Genie. He is committed to helping the next generation of tech professionals, serving as a cybersecurity instructor at the University of Luzon and a mentor for the Saleng Mentors Group. In his free time, Tzar focuses on building practical solutions for education, healthcare, and new businesses.

Site Footer