A China-aligned hacking group impersonated former US officials and a senior Anthropic employee to target AI policy experts at American think tanks, universities and law firms, according to research disclosed by Proofpoint on October 1.
The campaigns used invitations to discuss AI regulation, export controls and military applications to start conversations before sending links to fraudulent sign-in flows. Proofpoint tracks the group as TA419 and assesses that the targeting supports Chinese intelligence collection about US policymaking.
The July campaign borrowed the identities of Lynne Parker, a former senior White House technology official, and economist Heidi Crebo-Rediker. Messages invited recipients to join a fictitious AI policy advisory committee or contribute to a Senate Foreign Relations Committee report about AI export controls and supply chains.
Alex Engler, a former White House official who now heads the Penn Center on Media, Technology, and Democracy, told Reuters he received an apparent invitation from Parker. He said something about the email felt wrong, and checking with others in the field established that the sender was an impostor. Proofpoint said the targeting it observed involved fewer than 10 people at a handful of organizations.
In February, the group impersonated an Anthropic employee in an approach to an AI policy analyst at a US think tank. The message asked for feedback on military integration of Claude. Both that campaign and the July outreach directed targets toward attempts to steal cloud-account credentials.
The phishing system relayed genuine Microsoft sign-in pages through attacker-controlled infrastructure. It was designed to let a password and multifactor authentication check succeed while capturing the resulting session cookies. A fake browser window and OneDrive presentation concealed the intermediary, according to Proofpoint’s technical analysis.
Proofpoint told CNN it found no evidence that the targeted organizations were successfully breached. Researcher Mark Kelly attributed the group to Chinese government-aligned activity based on its targets, infrastructure, technical artifacts and corroboration from industry partners. The assessment does not establish that every person approached lost account access.
Parker told CNN that colleagues contacted her after receiving suspicious messages in her name. She said warning potential recipients was difficult because she did not know who was being targeted. Proofpoint has observed TA419 targeting organizations in the United States and Japan since at least April 2025.
The disclosure follows a separate US advisory accusing Chinese AI laboratories of model distillation. That advisory concerns extraction of model capabilities; the TA419 report concerns access to policy experts’ accounts.
Proofpoint recommends phishing-resistant authentication such as passkeys and checking unexpected professional invitations through another, independent channel.
Sources: Proofpoint, Reuters, CNN
–
By the Control Plane Editorial Team