Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » China-Linked Hackers Target US AI Policy Experts in Credential Phishing Campaign

China-Linked Hackers Target US AI Policy Experts in Credential Phishing Campaign

Last updated:October 4, 2026
Human Written
  • A China-aligned group called TA419 posed as a former White House official and other experts to steal logins from AI policy specialists.

  • Fewer than 10 people were targeted. Proofpoint says the goal looks like spying on US policy, not stealing technology.

  • The fake emails started with harmless chat. Experts should confirm odd invitations through a second channel.

Chinese Hackers Target US AI Policy Experts With Fake Invitations

Hackers linked to China have been posing as well-known American AI experts to break into the email accounts of people who help shape US AI policy. The cybersecurity firm Proofpoint described the campaign in a report released Thursday.

Proofpoint calls the group TA419. It says the hackers sent fake invitations to experts at think tanks, universities and law firms. The goal was to steal passwords and reach their cloud accounts.

The Hackers Impersonated a Former White House Bureaucrat

Starting July 8, the hackers wrote as Lynne Parker, a former principal deputy director of the White House Office of Science and Technology Policy. They later posed as Heidi Crebo-Rediker, an economist and foreign policy expert.

The same group used a similar trick in February. Proofpoint says it pretended to be a senior Anthropic employee. That email asked a think tank analyst for feedback on military use of the company’s Claude AI models. The report does not name the employee.

Proofpoint did not name the people it believes were targeted. It said they work on AI regulation, export controls and national AI strategy. Reuters identified one of them: Alex Engler, a former White House official who now heads the Penn Center on Media, Technology, and Democracy.

Engler told Reuters he received an email that appeared to come from Parker. It invited him to join a new AI policy project. Something felt slightly off, so he asked others in the field. They helped him realize the sender was an impostor.

Parker said Engler was one of two people she knew of who got suspicious messages in her name in early July.

How the Scheme Worked

The first emails had no links and asked for no passwords. They pitched projects, such as joining an “AI Policy Advisory Committee” or helping with a Senate Foreign Relations Committee report on AI export controls.

The goal was to build trust. If a target replied, the hackers sent a shortened web link. It passed through several sites and ended at a fake Microsoft OneDrive page.

A fake sign-in window then popped up over that page. Behind the scenes, the sign-in ran through real Microsoft systems. The victim’s password and security code worked normally. But the hackers copied the login session, which gave them access to the account.

Proofpoint said the group’s tool also tracked each victim’s progress in real time. It even accepted the “Keep me signed in” prompt to make the stolen session last longer.

Additionally, Proofpoint said the group also set up lookalike websites that copied real organizations, including the Heritage Foundation and the Japan-Taiwan Exchange Association.

Why Fingers Point to China as the Suspect

Proofpoint tied the activity to China based on the malware the group used, the internet servers behind the attacks, and the people it targeted. Those targets match Chinese intelligence priorities, the company said.

Furthermore, Proofpoint said it has watched TA419 target US and Japanese think tanks, defense contractors, universities and law firms since at least April 2025. Other China-linked data activity has also surfaced in separate cases, including a dark net seller’s claim to have 280 million China Housing Provident Fund records for sale. This activity had not been reported publicly before. The company said the focus on AI policy extends the group’s long-standing interest in defense, national security, energy and foreign policy, rather than a new direction.

The report does not directly link the hackers to the Chinese government. It also does not say whether any accounts were broken into. The Chinese Embassy in Washington did not immediately respond to Reuters. Beijing has long denied carrying out cyberespionage.

A Search for Policy Insight

Proofpoint said the narrow targeting points to an interest in US policymaking, not technology theft alone. It targeted fewer than 10 people across a few organizations.

This comes as the competition between the US and China over AI, export controls and chip supply intensifies. On Sept. 8, the NSA, CISA and the FBI accused Chinese AI companies of systematically extracting abilities from US AI models by sending them millions of requests.

Parker told Reuters the claim of Chinese involvement made sense. She said the two countries are in an AI competition, so trying to learn US policy plans would not surprise her. Proofpoint expects TA419 to keep going after think tanks and policy experts, and to keep copying real people’s identities.

The company told vulnerable groups to switch to passkeys since they’re tougher to fake than regular passwords. Also, it urged individuals to treat any unsolicited communication by experts as a potential trap. Before trusting anything, verify it through an alternative means, like a phone call.

To aid security teams in identifying and blocking attack attempts, Proofpoint has released technical details, including web domain names and email addresses that attackers use.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.