New Delhi: A China-linked hacking group impersonated prominent American policy figures to lure artificial intelligence experts into attempts to steal their email credentials, according to research published on Thursday. The cybersecurity company Proofpoint said the operation appeared intended to gather intelligence on US AI policymaking amid competition between Washington and Beijing over the technology.
The group, tracked as TA419, approached researchers with apparently credible invitations before directing them towards fraudulent sign-in pages. Its targeting brings attention to the intelligence value of policy discussions – including how governments might regulate AI, restrict technology exports or authorize military applications – alongside the technology itself.
According to Proofpoint’s investigation, the July campaign impersonated the former principal deputy director of the White House Office of Science and Technology Policy, Lynne Edwards Parker, and the economist and foreign policy expert, Heidi Crebo-Rediker. The approaches included invitations to a fictitious AI advisory committee and requests for contributions to a purported Senate foreign relations committee report on export controls and supply chains.
These were carefully chosen professional pretexts: invitations to advise policymakers or contribute specialist knowledge would fit the work of the intended recipients. They also borrowed the credibility of recognizable experts, giving targets a reason to engage before encountering a suspicious link.
Reuters independently identified one recipient as Alex Engler, a former White House official who heads the Penn Center on Media, Technology, and Democracy. He checked an apparent invitation from Parker with colleagues and discovered the impersonation; Proofpoint told Reuters that the targeting involved fewer than 10 people across a handful of organizations.
The Chinese embassy in Washington did not immediately respond to Reuters’s request for comment, while Beijing has repeatedly denied conducting cyberespionage. The published accounts do not establish how many targeted accounts, if any, were successfully compromised.
The July approaches followed a February operation in which TA419 impersonated a senior Anthropic employee and sought feedback on military integration of the company’s Claude models. In the July campaign, recipients who replied were sent shortened links leading to a counterfeit OneDrive access page targeting Microsoft cloud accounts.
The attack combined a simulated browser sign-in window with an “adversary-in-the-middle” mechanism that relayed authentication to genuine Microsoft infrastructure. This allowed the attacker to capture authenticated session cookies as the target completed the sign-in process.
The distinction matters because an account can remain vulnerable even when its owner uses a password and an additional verification code. As Microsoft explained in earlier research, attackers using this method can steal the digital token that tells a service the user has already authenticated, then reuse it to enter the account.
This does not mean multifactor authentication is generally ineffective: Microsoft describes it as an essential defence against many attacks. The weakness exploited here is the theft of an authenticated session, which makes phishing-resistant authentication and controls on subsequent account access particularly relevant.
TA419’s activity extends beyond the July operation against US AI specialists. Infosecurity Magazine notes that Proofpoint has observed the group conducting targeted credential phishing against people at think tanks, defence contractors, universities and law firms in the US and Japan since at least April 2025.
AI specialists have faced similar targeting before, although the campaigns should not be conflated. In research published in May 2024, Proofpoint described a separate operation, tracked as UNK_SweetSpecter, that used AI-themed emails and malicious attachments against people connected to American AI efforts.
That earlier operation sought to install remote-access malware, whereas the newly disclosed TA419 campaign concentrated on cloud-account authentication. Together, the reports illustrate how professional exchanges around AI can provide openings for intelligence collection, whether the immediate target is technical knowledge or policy deliberations. Proofpoint recommended independently verifying unexpected professional approaches and adopting phishing-resistant authentication, such as passkeys. Engler’s decision to check the invitation with colleagues illustrates the practical value of confirming a sender’s identity before following a document-sharing link.
