Chinese hackers have impersonated US artificial intelligence experts, including a former White House official, in attempts to steal credentials from specialists working on AI policy, according to cybersecurity company Proofpoint.
Proofpoint identified the group as TA419. The company said it has tracked the group targeting people at US and Japanese think tanks, universities, defence contractors and law firms since at least April 2025.
Proofpoint attributed the activity to a China-aligned threat actor based on the malware, internet infrastructure and targets associated with the campaigns. The company said the targeting is consistent with Chinese intelligence priorities.
Hackers Posed as AI Experts
The latest campaign began in July and involved emails impersonating prominent figures in AI policy and economics.
US Creates New Autonomous Warfare Command to Expand AI, Drone Capabilities
One of the impersonated figures was Lynne Parker, a former principal deputy director of the White House Office of Science and Technology Policy.
The attackers initially sent seemingly legitimate messages. They invited recipients to join an alleged AI policy advisory committee or contribute to work on AI export controls and supply chains.
After recipients responded, the attackers sent links that eventually led to fake Microsoft OneDrive pages. Proofpoint said the pages were designed to steal Microsoft 365 credentials.
The group also previously impersonated a senior employee of AI company Anthropic in a February campaign targeting an AI policy analyst.
Former White House Official Among Targets
Reuters independently identified Alex Engler as one of the people targeted.
Engler, a former White House official, now heads the Penn Center on Media, Technology, and Democracy.
He told Reuters that he received an email appearing to come from Parker. The message invited him to join a new AI policy project.
Engler said the email initially appeared plausible but felt unusual. After consulting others in the field, he determined that the sender was an impostor.
Proofpoint said fewer than 10 people at a small number of organisations were targeted in the campaign.
The company said the targeting suggested an intelligence interest in US policymaking rather than an effort focused solely on stealing technology.
Focus on AI Policy
Proofpoint said the targets included experts working on AI regulation, export controls and national AI strategy.
Parker told Reuters that she knew of two people who had received suspicious messages using her identity in early July.
She said the alleged Chinese involvement was plausible given the strategic competition between Washington and Beijing over AI policy.
The Chinese Embassy in Washington did not immediately respond to Reuters’ request for comment. Beijing has previously denied conducting cyberespionage operations.
AI Competition Drives Security Concerns
The campaign comes as the United States and China compete over advanced AI technologies and their applications.
The competition includes AI development, export controls, regulation and access to advanced computing technologies.
Proofpoint said TA419 has also shown interest in defence, national security, energy, international relations and foreign policy targets. The company expects the group to continue targeting policy experts and technology specialists.
The latest campaign demonstrates how cyber attackers can use trusted identities and professional relationships to approach highly specialised targets.






















