A hacking group believed to be acting on behalf of China has spent months impersonating prominent American AI insiders — including a former senior White House technology official and a senior Anthropic employee — to break into the email accounts of US AI policy experts, according to a report from cybersecurity firm Proofpoint released on October 1, 2026, and reported by Reuters and CNN.
The campaign, which Proofpoint tracks as TA419, targeted fewer than ten individuals at think tanks, universities and law firms — people whose work centers on AI regulation, export controls and national AI strategy. The company linked the group to China through its malware, the servers used in the intrusions, and its selection of targets, which aligns with the kind of intelligence Chinese state actors traditionally seek. China has repeatedly denied US allegations of state-sponsored hacking, CNN noted. For more context on this story, see our ongoing latest AI developments.
Posing as Anthropic — and the White House
The impersonations were specific and credible. In February, the group posed as a senior Anthropic employee and emailed an AI policy analyst at a US think tank, with a subject line requesting feedback on the military use of Claude, Anthropic's AI model, according to CNN's reporting on the findings.
From July, the attackers took on the identities of two real former US officials: Lynne Parker, who served as a senior White House technology official, and Caroline Crebo-Rediker, a former State Department economist.
The bait: panels, Senate reports and malware
The lure emails were tailored to their targets' professional lives. Recipients were asked to join a fictitious AI policy panel or to contribute to a purported Senate report on AI export controls — requests a working policy expert would find routine rather than suspicious.
Later messages escalated: Proofpoint says they carried malware-laced files or attempted to trick recipients into surrendering their passwords, converting a trusted conversation into account access.
Who was targeted, and why it matters
The target profile is what distinguishes this campaign from ordinary phishing. Proofpoint assessed that the operation reflects an interest in how the United States develops AI policy — the deliberations inside think tanks, universities and law firms that shape regulation, export controls and national strategy — rather than an attempt to steal AI technology itself.
The company said the group has been targeting US and Japanese think tanks, defense companies, universities and law firms since at least 2025, and expects the impersonation of genuine experts to continue.
Reuters reported that one of the targets was Alex Engler, a former White House official who now leads the Penn Center for Media, Technology and Democracy, and that Parker was one of the identities used in the fake emails. "The United States and China are in a competition around AI," Parker told Reuters.
Attribution, denial and the gray zone
Attributing intrusion campaigns to a specific state is never simple, and Proofpoint's evidence is circumstantial in the way most such reporting is: infrastructure, tooling and targeting consistent with Chinese espionage priorities, rather than a signed confession. Beijing routinely denies involvement in hacks against the United States and has done so again in coverage of this report.
But the technique itself — impersonating trusted, named individuals to exploit the trust economy of a small professional community — fits a broader pattern security researchers have documented in espionage operations aimed at policy circles. When the community of experts in a field is small enough that its members know each other's names, a forged email from a recognizable figure carries weight no generic lure can match.
Why impersonation works
The technique's effectiveness lies in what security researchers call the trust economy of a specialized field. The community of people who work full-time on AI policy is small: analysts swap panel invitations, comment drafts and Senate testimony requests by email, often with people they have never met in person. A forged message from a recognizable name — a former White House official, a serving executive at a leading AI lab — arrives with borrowed credibility that no generic phishing template can replicate.
That is also why the phishing payload came second, not first. By opening with legitimate-sounding professional requests and following up over weeks, attackers can establish an ongoing exchange before introducing malware-laced attachments or credential-harvesting pages. Proofpoint's expectation that the group will keep impersonating genuine experts suggests the approach is working often enough to continue.
What organizations can do
The defensive lessons are procedural rather than technical. Security teams advise verifying unusual requests through a second, independently confirmed channel — a phone call to a known number, not a reply to the email — especially when messages involve document sharing or login screens. Organizations whose staff work on politically sensitive policy areas are increasingly treated by security professionals as at-risk targets regardless of their size, since their value to intelligence collectors comes from what they know rather than what they sell.
Email authentication standards such as DMARC make direct impersonation of an organization's domain harder, but they do not stop lookalike personal accounts or free-mail addresses crafted to resemble a real person — which is precisely the pattern Proofpoint describes. Names, titles and affiliations used in the fake emails were all real.
Why AI policy circles are now a spying priority
The campaign underscores how AI policymaking itself has become an intelligence target. Export control decisions, safety regulation and national AI strategy are being drafted in real time by a dispersed network of think tank analysts, academics and lawyers — and insight into those deliberations has clear strategic value to any rival power.
For the targeted organizations, the practical lessons are the ones security teams have long preached: verify unusual requests through a second channel, treat attachments from known contacts with suspicion when they arrive out of context, and assume that your name and reputation may be used against colleagues. For everyone else, the episode is a reminder that the geopolitics of AI is not playing out only in trade negotiations and legislation — it is playing out, quietly, in a handful of inboxes.
---
Stay Ahead of AIGet the latest AI news, analysis, and breakthroughs — all in one place.
Read more AI news →