9 Sources
[1]
Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing
A suspected Chinese espionage group impersonated AI policy figures, including a senior Anthropic employee and a former White House official, in phishing campaigns targeting AI policy experts at US universities, think tanks, and law firms, security researchers say. The bulk of these campaigns
[2]
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and
[3]
Chinese hackers impersonated ex-US official to steal emails from AI experts
WASHINGTON, Oct 1 (Reuters) - Chinese hackers have been impersonating US AI experts, including a former government official, to try to steal emails from experts in AI at think tanks, universities, and other organizations, the cybersecurity company Proofpoint said on Thursday. In a report,
[4]
Suspected Chinese hackers posed as US AI insiders, Proofpoint says
The group impersonated a former White House official and an Anthropic employee to steal AI policy experts' email logins A group of hackers believed to have been acting on behalf of China pretended to be well-known American AI experts to obtain the email accounts of people who specialize in AI
[5]
Chinese Hackers Impersonated Ex-US Official to Steal Emails From AI Experts
By Raphael Satter and AJ Vicens WASHINGTON, Oct 1 (Reuters) - Chinese hackers have been impersonating US AI experts, including a former government official, to try to steal emails from experts in AI at think tanks, universities, and other organizations, the cybersecurity company Proofpoint said
[6]
Chinese hackers: Chinese hackers impersonated ex-US official to steal emails from AI experts
In a report, Proofpoint said that it had watched the hackers - which it dubs "TA419" - regularly try to steal passwords from people working for US or Japanese think tanks, defense contractors, universities, and law firms since as far back as 2025. Chinese hackers have been impersonating US AI
[7]
China linked hackers pose as former US officials to steal emails from researchers, Proofpoint says
Chinese hackers have been impersonating US AI experts, including a former government official, to steal emails from AI experts at think tanks, universities, and other organizations, the cybersecurity company Proofpoint said on Thursday. In a report, Proofpoint said that it had watched the hackers,
[8]
Chinese Hackers Impersonate US AI Experts in Phishing Campaign | PYMNTS.com
That report, issued Thursday (Oct. 1) by cybersecurity firm Proofpoint, said that a hacking group known as "TA419" has since last year routinely attempted to steal passwords from think tanks, defense contractors, universities and law firms in Japan and the U.S. "Proofpoint assesses that TA419 will
[9]
Chinese hackers impersonated ex-US official to steal emails from AI experts
WASHINGTON, Oct 1 (Reuters) - Chinese hackers have been impersonating US AI experts, including a former government official, to try to steal emails from experts in AI at think tanks, universities, and other organizations, the cybersecurity company Proofpoint said on Thursday. In a report,
Share
Copy Link
Chinese hackers posed as a former White House official and an Anthropic executive to launch credential theft schemes against fewer than 10 US AI policy experts. The China-aligned TA419 group targeted specialists working on AI regulation, export controls, and national AI strategy at think tanks, universities, and law firms.

A China-aligned cyber espionage group known as TA419 has been conducting sophisticated phishing campaigns targeting AI policy experts across US think tanks, universities, and law firms, according to cybersecurity firm Proofpoint
1
2
. The Chinese hackers impersonated high-profile AI policy figures, including Lynne Parker, a former principal deputy director of the White House Office of Science and Technology Policy, and a senior Anthropic employee, to steal emails from AI experts working on critical policy issues3
. These credential theft schemes represent intelligence-gathering related to US AI policymaking during a period of intense geopolitical competition between the United States and China.Proofpoint identified that TA419 has been orchestrating credential phishing campaigns against individuals working for US and Japan-based organizations since at least April 2025
2
. The bulk of these attacks occurred in July 2026, when the group impersonated multiple individuals to target U.S. AI policy experts1
. Beginning July 8, TA419 sent phishing emails spoofing Parker and economist Heidi Crebo-Rediker, inviting targets to join a fake AI policy advisory committee or contribute to a Senate foreign relations committee report on AI export controls and supply chains1
. The Chinese hackers employed adversary-in-the-middle phishing using a multi-stage attack chain that began with harmless invitations to establish trust before deploying malicious links2
.The phishing chain targets Microsoft 365/Entra ID through the first-party OfficeHome application, utilizing an open-source tool called Frameless BitB
1
. This Browser-in-the-Browser attack creates a fake browser window within a legitimate session using HTML, CSS, and JavaScript, spoofing trusted login pages without using iframe elements2
. TA419 extended this open-source tool with custom telemetry and automation modules that track the victim's Microsoft sign-in flow and capture credentials using an AitM proxy powered by Evilginx2
. The July 2026 campaigns used driftshare[.]co as the first-stage domain and globalfileshareplatform[.]com as the second-stage domain, typically hiding backend hosting IP addresses through Cloudflare's content delivery network1
.Proofpoint attributed the hacking efforts to China based on the types of malware used, internet infrastructure deployed, and targets selected, which align with Chinese intelligence collection priorities
3
5
. The targeting involved fewer than 10 individuals working for a handful of think tanks, universities, and law firms, suggesting an intelligence interest in US policymaking rather than technology theft alone3
5
. Targets included experts working on AI regulation, export controls, and national AI strategy3
. Alex Engler, a former White House official who now heads the Penn Center on Media, Technology, and Democracy, confirmed receiving a suspicious email appearing to come from Parker inviting him to join a new AI policy project3
.Related Stories
In February 2026, the Chinese hackers spoofed a senior Anthropic employee to phish an AI policy analyst at a US think tank, using the subject line "Request for Feedback on Military Integration of Claude"
1
4
. This occurred as US military officials pressured Anthropic to remove Claude's safeguards1
. Proofpoint's alert came one day after OpenAI accused China's Moonshot AI of stealing American models' reasoning and other data in distillation attacks that began on July 11
. Parker noted that the allegation of Chinese involvement made sense given the geopolitical competition: "The United States and China are in a competition around AI. Trying to get people in the AI policy space to reveal information about their AI policy plans—if that indeed was what the objective was—it's not surprising"5
.TA419 has consistently shown interest in defense, national security, energy, international relations, and foreign policy targets, predominantly with a nexus to the US and Japan
2
. The targeting of AI policy experts represents an extension of that focus rather than a departure from it2
. Proofpoint expects TA419 and other Beijing-aligned groups to continue targeting AI and other policy experts working on technologies of interest to the Chinese government1
4
. Organizations in the scope of TA419 activity should consider implementing phishing-resistant, origin-bound authentication such as passkeys1
. Individual targets should treat unsolicited subject-matter outreach with caution and verify authenticity before proceeding2
. The Chinese Embassy in Washington did not immediately respond to requests for comment, while Beijing has long denied carrying out cyberespionage operations3
.Summarized by
Navi
[1]