Commentary
The arrest of a Canadian intern accused of spying inside NATO’s senior military headquarters in Belgium reaches beyond one person or one failed security check. It shows how hostile states can combine espionage, criminal networks, technology, and trusted access to weaken an alliance without firing a shot.
Belgian prosecutors allege that the intern, who is of Chinese origin, conducted espionage for an unidentified third country while interning at Supreme Headquarters Allied Powers Europe, known as SHAPE, in Mons, Belgium. They also accuse her of belonging to a criminal organization.
The suspect has not been convicted, and the allegations have not been tested in court. Belgian authorities have not identified the foreign state or the alleged criminal group.
The organized-crime allegation deserves close attention. Espionage is often pictured as a direct relationship between a foreign intelligence officer and a recruited source. Modern operations can be less visible. Criminal networks may provide money laundering, false documents, encrypted communications, surveillance, transportation, cyber services or access to compromised insiders. A state gains distance and deniability, while the network gains money, protection, or influence.
That overlap is a feature of hybrid warfare. NATO describes hybrid threats as a mixture of military and non-military, covert and overt tools, including cyberattacks, economic pressure, disinformation and proxies. These activities blur the line between peace and conflict while exploiting weaknesses inside open societies.
SHAPE is NATO’s main operational military headquarters. Even an intern with limited formal access may learn a great deal by watching personnel, routines, internal relationships, security procedures, and the movement of information. Small details become valuable when combined with cyber collection, public records, and information gathered elsewhere.
An insider does not need to leave carrying secret files to cause damage. Information about who makes decisions, how quickly the alliance responds, which systems are vulnerable, or where disagreements exist among members can help an adversary prepare for a crisis. An insider may also identify recruitment targets or expose weaknesses in contractors and supply chains.
Media reports state that the suspect was vetted by the Canadian Security Intelligence Service and the RCMP before Global Affairs Canada authorized the clearance required for her NATO placement. A federal court ruling had already upheld a Public Service Commission finding of fraud involving a Canada Border Services Agency staffing process, reports say.
That finding was administrative, not a criminal conviction. Even so, honesty, reliability, and judgment are basic elements of security screening. Canadians deserve to know whether the finding appeared during the review, how it was assessed, and whether all agencies involved had access to the same information.
The suspect had reportedly worked or held placements at Statistics Canada, the National Research Council, the Canadian Space Agency, the European Space Agency, and the World Trade Organization. That career placed her near government information, emerging technology, and international policy before she arrived at NATO.
No screening system can prevent every betrayal. A person may be recruited after receiving a clearance, and circumstances can change. Continuing evaluation is therefore as important as the original background check. Access should be reconsidered as an individual changes positions, develops new foreign relationships, faces pressure, or seeks entry into increasingly sensitive institutions.
NATO security personnel reportedly detected the suspicious activity and referred the matter to Belgian military intelligence. Belgian authorities then searched the suspect’s residence and workplace before making the arrest. No comparable Belgian case involving an alleged insider at SHAPE appears in the public record, making this an unusually serious event for the alliance.
Canada has faced similar concerns before. The FBI alerted Canadian authorities about naval intelligence officer Jeffrey Delisle, who later admitted to selling highly classified Five Eyes information to Russia. A former senior FBI counter-intelligence official later criticized delays and weaknesses in the Canadian response.
The investigation that led to the conviction of senior RCMP intelligence official Cameron Ortis also grew from the multinational investigation into Phantom Secure, an encrypted communications company used by international criminal organizations. Evidence recovered during that operation helped investigators trace unauthorized disclosures back to Ortis.
The cases are different, and the NATO suspect remains accused rather than convicted. Together, they show how allied or multinational investigations have repeatedly played an important role in exposing Canadian security breaches.
For NATO, the danger extends beyond headquarters and intelligence databases. Allied forces depend on ports, airports, railways, telecommunications systems, defence contractors, laboratories, and civilian supply chains. Transnational criminal organizations already know how to move money, corrupt insiders, conceal ownership, and operate across borders. Those capabilities can be rented, directed, or quietly exploited by hostile states.
Canada’s intelligence service has warned that foreign governments increasingly use proxies and criminal organizations for hostile activity, including espionage, coercion and transnational repression. In a crisis, similar networks could interfere with shipping, compromise a contractor, move restricted technology, collect information around bases, or disrupt the movement of troops and equipment.
Canada and its allies need closer cooperation among counter-intelligence, criminal intelligence, cyber defence, and security screening. Information held by one department must be available to those protecting sensitive positions. Clearances should be treated as continuing assessments rather than permanent certificates of trust.
Hybrid warfare succeeds by exploiting the gaps between institutions. Police investigate organized crime, intelligence agencies monitor foreign states, and defence departments prepare for military threats. An adversary can combine all three.
The arrest in Belgium is more than an individual criminal case. It is a warning that the next threat to allied forces may already be inside a trusted institution, supported by networks operating quietly below the threshold of open conflict.
Scott McGregor is a former Canadian Armed Forces intelligence operator and intelligence adviser to the RCMP. He is the co-author of “The Mosaic Effect: How the Chinese Communist Party Started a Hybrid War in America’s Backyard.”







