China-Aligned Hackers Impersonated Anthropic and Former White House Officials to Target America’s AI Policy Experts


Oct. 2, 2026, 5:31 a.m.

Views: 0


Chinese hackers impersonated an Anthropic exec to get information about AI

China-Aligned Hackers Impersonated Anthropic and Former White House Officials to Target America’s AI Policy Experts

A China-aligned cyber-espionage group has been caught impersonating an Anthropic employee, former White House technology officials and prominent policy figures in an effort to steal credentials from Americans working at the center of U.S. artificial-intelligence policy. The campaign, uncovered by cybersecurity firm Proofpoint, targeted experts at American think tanks, universities and law firms whose work included AI export controls, military applications of artificial intelligence, supply chains and technology regulation. The activity shows that competition over AI is no longer confined to chips, models and corporate research. The people who shape American AI policy have themselves become intelligence targets.

Proofpoint tracks the group as TA419 and describes it as a China-aligned, espionage-motivated threat actor. The company says it has observed TA419 conducting targeted credential-phishing operations against people at U.S. and Japanese think tanks, defense contractors, universities and law firms since at least April 2025. In July 2026, the group expanded its activity against U.S. AI-policy specialists, impersonating former White House technology official Lynne Edwards Parker and economist and foreign-policy expert Heidi Crebo-Rediker.

The campaign was built around credibility rather than obvious spam. According to Proofpoint, TA419 first sent benign-looking emails intended to start a conversation. One lure invited recipients to participate in a supposed “AI Policy Advisory Committee.” Another asked targets to contribute to what was presented as a Senate Foreign Relations Committee report concerning AI export controls and supply chains. Only after a target replied did the attackers move to the credential-theft stage.

That sequencing is important. The attackers were not relying primarily on poorly written mass-phishing messages or obviously suspicious attachments. They used the identities of real, respected figures in technology and policy to exploit professional trust. An AI analyst who receives an unexpected message from someone known in Washington policy circles may reasonably believe the outreach is connected to legitimate advisory work, government consultation or academic collaboration.

Once a target engaged, TA419 reportedly sent a shortened link that redirected through attacker-controlled infrastructure to a fake OneDrive login environment. Proofpoint said the operation used an Adversary-in-the-Middle credential-phishing system combined with a customized version of the open-source Frameless BitB, or Browser-in-the-Browser, phishing toolkit. The objective was to capture access to Microsoft 365 and Entra ID cloud accounts.

This kind of attack can be especially dangerous in policy organizations because an email account can contain far more than ordinary correspondence. Think-tank researchers, university experts, lawyers and policy advisers may exchange drafts, meeting invitations, unpublished analysis, private conversations with officials, assessments of export-control options and information about who is advising whom. Even when documents are not classified, that material can reveal how American institutions are thinking before policy becomes public.

The targeting therefore has obvious intelligence value. Proofpoint assesses that TA419’s activity likely supports broader Chinese intelligence objectives aimed at understanding developments inside the U.S. AI-policy and regulatory environment. That assessment is based on the group’s targeting patterns, infrastructure, technical artifacts and corroboration from industry partners.

The February portion of the campaign was even more closely tailored to the American AI debate. Proofpoint says TA419 impersonated a senior Anthropic employee and emailed an AI policy analyst at a U.S. think tank with the subject line “Request for Feedback on Military Integration of Claude.” The message referred to the politically sensitive debate over how Anthropic’s Claude models should be used in military contexts, giving the phishing attempt a subject that would be highly relevant to someone working on national-security AI policy.

That is what makes the campaign especially instructive. The attackers were not simply asking victims to click generic invoices or fake security warnings. They were following current American policy debates closely enough to construct highly specific pretexts around military AI, export controls and government advisory work.

For the United States, that means cyber defense around AI cannot stop at major laboratories such as Anthropic, OpenAI or Google. The policy ecosystem surrounding those companies is also valuable. Lawyers interpret regulations. Think tanks produce policy recommendations. University researchers advise government officials. Former White House personnel maintain broad professional networks. Stealing access to those communities can reveal relationships and policy direction long before a final rule or public announcement appears.

The campaign also illustrates the growing value of impersonation as an espionage technique. In traditional cyber operations, attackers often try to exploit a software vulnerability. Social-engineering campaigns exploit a human vulnerability instead: familiarity, professional curiosity and trust in known colleagues.

TA419 reportedly strengthened that approach by impersonating real people with credible backgrounds. Lynne Parker had served in senior roles at the White House Office of Science and Technology Policy under both Republican and Democratic administrations. Someone receiving a policy-oriented message in her name would therefore have a plausible reason to take it seriously.

Proofpoint reported that the real Parker learned of the impersonation after colleagues began contacting her about suspicious messages. The use of her identity demonstrates a secondary harm from this style of operation: the professional reputation and relationships of real Americans become tools for targeting other Americans.

The technical infrastructure was also designed to make the operation harder to detect. Proofpoint found that TA419 used URL-shortening services, Cloudflare infrastructure, actor-controlled domains made to resemble file-sharing services, residential proxies and virtual private servers. The final credential pages were designed to imitate normal Microsoft authentication behavior closely enough to persuade victims that they were interacting with legitimate cloud services.

That matters because cloud credentials can provide durable access. If attackers successfully obtain a Microsoft 365 account, they may gain access to email, documents, contacts, calendars and shared files. They can also observe future conversations, identify other valuable people in the victim’s network and potentially use a compromised legitimate account to launch more convincing attacks.

Proofpoint did not report evidence that the targeted U.S. organizations were successfully breached in these specific campaigns. That limitation is important. The documented threat is a sophisticated espionage attempt, not proof that TA419 successfully stole the targeted information. At the same time, the group’s persistence and narrow targeting show that the underlying intelligence objective is serious enough to sustain repeated operations over time.

The campaign fits a broader pattern identified by Western security agencies. In June, the Five Eyes intelligence partnership warned that Chinese military intelligence services were using fake recruiters, consultants and cover companies on professional networking platforms to cultivate people with access to privileged military, political and economic information. Academics, journalists, think-tank employees and security professionals were among the groups identified as potential targets.

Britain’s MI5 issued another espionage warning on September 30 concerning the China General Technology Research Institute, or CGTRI. MI5 said the institute’s primary purpose is to fund research that directly improves the technical espionage capabilities of China’s Ministry of State Security, including research involving artificial intelligence and cybersecurity. MI5 said more than 100 U.K.-linked academics had contributed to projects ultimately funded through the organization.

Taken together, these disclosures show why AI expertise itself is becoming a strategic intelligence target. Governments do not need to steal an entire frontier model to benefit from information about AI. They can seek regulatory thinking, export-control strategy, military integration plans, security assessments, supply-chain vulnerabilities and the identities of influential experts.

For American institutions, the defensive lesson is practical. High-value personnel should treat unexpected professional outreach about AI policy, defense technology or government advisory work with the same caution traditionally reserved for suspicious login alerts. Identity verification should happen through a second channel before sensitive conversations begin or documents are opened.

Proofpoint specifically recommends phishing-resistant, origin-bound authentication such as passkeys. That matters because sophisticated Adversary-in-the-Middle phishing can defeat some conventional authentication methods by intercepting credentials and active sessions. Stronger authentication systems reduce the value of a stolen password and make impersonation campaigns harder to convert into account access.

Organizations should also understand that former officials and respected academics can be weaponized as identities without their knowledge. A familiar name in an inbox should no longer be treated as sufficient proof that the sender is genuine, especially when the conversation involves sensitive AI, defense, semiconductor or export-control topics.

The broader U.S.-China AI competition is increasingly an intelligence competition as well. American labs are protecting model capabilities, semiconductor companies are protecting advanced hardware, and policy institutions now have to protect the internal deliberations that determine how those technologies will be governed.

TA419’s campaign demonstrates how closely sophisticated threat actors can follow American policy debates and convert them into tailored espionage lures. An invitation to discuss AI military integration, an advisory committee or an export-control report can look like ordinary professional networking while functioning as the first stage of credential theft.

For the United States, protecting AI leadership therefore requires defending the entire ecosystem surrounding the technology. The researchers who build models matter. So do the lawyers who interpret export restrictions, the analysts who study military applications, the professors who advise policymakers and the former officials whose networks connect those communities.

When China-aligned cyber actors begin impersonating those very people to reach American AI experts, the target is no longer merely a computer system. It is the human network through which U.S. technology policy is formed.


Return to blog