the white house

China-aligned Hackers Impersonate US AI Insiders

China-aligned hackers pose as White House, Anthropic insiders to phish AI policy experts.

A China-aligned hacking group has been impersonating a former White House official, a prominent economist, and an Anthropic employee in an effort to break into the email accounts of people who shape US policy on artificial intelligence.

Researchers at Proofpoint say the targets were AI policy experts at US think tanks, universities, and law firms. The apparent target was the policy process itself. That is, the people working on AI regulation, export controls and national strategy rather than proprietary model technology. Proofpoint says the activity likely supports broader Chinese intelligence efforts to understand how US AI policy and regulation are developing.

Beyond the Break weekly cybersecurity newsletter — Subscribe

Known as TA419, the group is espionage-motivated and aligned with the aims of the Chinese government. Proofpoint says it has watched TA419 phish people at US- and Japan-based think tanks, defense contractors, universities, and law firms since at least April 2025. Until now the group had not been publicly reported.

Proofpoint says TA419 has also shown sustained interest in defense, national security, energy, international relations and foreign policy, making the move into AI policy an extension of its existing intelligence targets rather than a wholly new mission.

Due to the often murky nature of the connections between threat actors and state intelligence agencies, it can be hard to say definitively whether a group is directly employed by or simply acting on behalf of a government. Proofpoint researcher Mark Kelly told CNN the firm is confident in the China alignment. He cited targeting consistent with Chinese government interests, infrastructure and technical artifacts, and corroboration from industry partners.

The campaign starts with spear-phishing emails that impersonate trusted names in the AI policy world. Beginning July 8, TA419 posed as Lynne Parker, former Principal Deputy Director of the White House Office of Science and Technology Policy, and then as economist and foreign policy expert Heidi Crebo-Rediker.

The targeting also lands amid a fresh shift in White House AI policy language. On Sept. 29, the White House directed executive agencies to use “Super Intelligence” and “SI” in place of “Artificial Intelligence” and “AI” in official correspondence, public communications and other non-statutory documents. This is a change affecting the same federal policy apparatus TA419 was probing.

The opening emails were harmless. Targets were invited to join a fictitious “AI Policy Advisory Committee” or to contribute to a Senate Committee on Foreign Relations report on AI export controls and supply chains. The point was to get a reply. In other words, the first message was not designed to steal anything. It was designed to establish enough conversational legitimacy that the victim would trust what came next.

Those who replied got a shortened link that promised more information. It ran through a Cloudflare Turnstile check behind a fake OneDrive loading screen, then landed on an adversary-in-the-middle (AitM) phishing page built on a customized version of the open-source Browser-in-the-Browser kit Frameless BitB.

Proofpoint says the July campaigns used driftshare[.]co as the first attacker-controlled domain before sending victims to globalfileshareplatform[.]com, which hosted the second-stage AitM phishing site. That site used a customized version of the open-source Frameless BitB phishing kit to proxy the victim’s sign-in to genuine Microsoft infrastructure. The login therefore appears legitimate and the password, MFA code and conditional-access checks can all succeed. Meanwhile the kit captures the resulting authenticated session for the attacker.

Meanwhile the attacker walks off with the session cookies. Proofpoint says the chain specifically targets Microsoft 365 and Entra ID through Microsoft’s first-party OfficeHome application. TA419 added its own module that tracks each victim’s progress live, auto-submits one-time codes, and clicks “Keep me signed in” to stretch the stolen session.

The proxy lets the sign-in “all succeed while the attacker captures the resulting session cookies,” Proofpoint said.

AI policy is not new territory for the group. In February, TA419 impersonated a senior Anthropic employee in an email to an AI policy analyst at a US think tank. The subject line was “Request for Feedback on Military Integration of Claude.” It led to the same kind of credential phish.

The lure was closely tailored to a real policy debate around Anthropic. Claude’s use in national security and military settings has become an increasingly prominent issue, making a request for feedback on “Military Integration of Claude” considerably more plausible than a generic AI-themed lure.

There is a wider China-Anthropic connection as well, although it involves separate activity. Anthropic’s September threat-intelligence report described PRC-aligned actors using Claude for tasks ranging from identifying politically sensitive targets to supporting surveillance operations. Anthropic said one Chinese state security bureau had even used Claude to produce an internal manual for using AI in surveillance. There is no indication that activity was connected to TA419, but it underscores the broader intelligence interest surrounding frontier AI systems and the people shaping policy around them.

The operation was narrow. Proofpoint told Reuters that fewer than 10 people were targeted, which the firm said reflects an interest in how the US develops policy rather than in stealing technology. Proofpoint declined to name the targets. Reuters identified one as Alex Engler, a former White House official who now heads the Penn Center on Media, Technology, and Democracy.

Parker told Reuters that Engler was one of two people she knew of who received suspicious messages in her name in early July, and that the China attribution made sense.

Parker told CNN that relationships she’d “built over my career were being exploited by bad actors.”

Proofpoint’s report does not say whether any targets’ accounts were actually compromised.

Proofpoint says the activity likely serves wider Chinese intelligence goals of tracking US AI policy and regulation. It comes amid intense strategic competition, accusations of model distillation, and export controls involving the US and China.

That puts the people writing and analyzing AI rules alongside the technology itself as intelligence targets. Understanding what Washington may restrict, subsidize or regulate can be valuable before those decisions become policy.

The firm expects TA419 to keep going after think tanks and policy experts and to keep borrowing the identities of real experts to do it. Proofpoint says the group has previously registered domains impersonating organizations and public figures including the Heritage Foundation, the Japan-Taiwan Exchange Association and Japanese Defense Minister Shinjirō Koizumi’s website.

TA419 also fits into a broader pattern Proofpoint has observed around Chinese intelligence collection and AI. The company has separately tracked another China-aligned actor, UNK_SweetSpecter, conducting AI-related phishing, while Chinese-aligned groups have repeatedly targeted semiconductor and rare-earth organizations critical to the AI supply chain. In that context, policy experts represent another layer of the same strategic ecosystem.

Beijing routinely denies US hacking allegations, CNN noted.

The defensive advice is blunt. Proofpoint recommends phishing-resistant, origin-bound authentication such as passkeys. Anyone in TA419’s scope should treat unsolicited subject-matter outreach as a possible pretext and verify it through a separate channel.

Total
0
Shares
Previous Article
Illustration of an MCP server diverting OAuth login credentials to a malicious server

Official MCP Code Flaw Exposes AI's Trust Gap

Next Article
A glass cube containing a glowing neural-network brain, with secrets and documents streaming out through a crack in its side

LLMLeak Turns AI Chatbots Into Unwitting Data Smugglers

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading