Chinese Hackers Posed as a Former White House Official to Spy on US AI Experts
A China-aligned hacking group impersonated well-known American AI figures to trick policy experts into giving up their email passwords, according to the cybersecurity firm Proofpoint. The campaign was small, with fewer than ten known targets. Proofpoint says it points to an interest in how the US shapes its AI policy, not just in stealing technology.
.
A Fake Invitation From a Familiar Name
Hackers linked to China have been posing as respected US artificial intelligence experts to break into the email accounts of people working on AI policy. The cybersecurity company Proofpoint described the campaign in a report published on October 1, 2026.
Proofpoint calls the group "TA419" (the firm's internal label for a hacking group it tracks). It says the group has repeatedly gone after US and Japanese think tanks, defense contractors, universities and law firms since 2025.
The method is a classic one called phishing: fake emails that lure people to look-alike websites where they enter their login details.
Who Was Impersonated, and Who Was Targeted
In the latest wave, which began in July, the emails appeared to come from Lynne Parker. She is a former principal deputy director of the White House Office of Science and Technology Policy. According to Proofpoint, the group also posed as Heidi Crebo-Rediker, a former chief economist at the US State Department.
The messages invited recipients to join an AI policy project or panel, or to contribute to a report on AI export controls and supply chains. Those who clicked were steered to password-stealing pages.
Proofpoint did not name the victims. It said only that they were experts working on AI regulation, export controls and national AI strategy. Reuters independently identified one of them: Alex Engler, a former White House official who now leads the Penn Center on Media, Technology, and Democracy.
Engler received an email that seemed to come from Parker. Something about it felt slightly off to him. After checking with colleagues in his field, he realized it was a fake.
Parker told Reuters that Engler was one of two people she knew of who had received such messages in her name in early July.
A Second Campaign in February
Proofpoint also traced an earlier operation from February 2026. In it, the same group posed as a senior employee of the AI company Anthropic. The email went to an AI policy analyst at a US think tank and asked for feedback on the military use of AI, according to reports on the findings.
How the Trick Worked
Proofpoint described a chain of web redirects that ended on a fake Microsoft OneDrive page. The attackers used a modified version of an open-source tool known as "Frameless BitB." It fakes a login window inside the victim's own browser (a "browser-in-the-browser" trick), so the page looks genuine.
This kind of attack aims to capture passwords and active login sessions. Reporting on the findings notes that Proofpoint has not confirmed any successful break-ins in this campaign.
Why Beijing Is Suspected
Proofpoint tied the activity to China based on three things:
- the type of malicious software used,
- the internet infrastructure behind the attacks,
- the choice of targets, which match known Chinese intelligence priorities.
The small number of targets is telling. Proofpoint said it suggests an intelligence interest in US policymaking and not only in technology theft.
The Chinese Embassy in Washington did not immediately respond to Reuters' request for comment. Beijing has long denied carrying out cyberespionage.
Background: The Race for AI Leadership
Parker said the allegation of Chinese involvement did not surprise her. In her view, the US and China are in a competition over AI. Getting experts to reveal their policy plans would fit that rivalry.
The case shows that the target list is widening. Hackers no longer go only after companies and their technology. They also go after the people who advise governments on rules and export controls.
Outlook
Proofpoint says the group's interest in AI policy extends its earlier focus on defense, national security, energy and foreign policy. Experts in these fields should expect more of the same.
The advice is simple. Verify unexpected invitations through a second channel, such as a phone call or a known address. Be careful with login pages reached through email links. Where possible, use hardware security keys or other phishing-resistant sign-in methods.
.
Sources
- Reuters – "Chinese hackers impersonated ex-US official to steal emails from AI experts" (Raphael Satter, A.J. Vicens), Oct 1, 2026: https://www.reuters.com/legal/government/chinese-hackers-impersonated-ex-us-official-steal-emails-ai-experts-2026-10-01/
- Proofpoint Threat Insight – "Hallucinating Credibility: China-aligned TA419 impersonates its way into US AI policy": https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy
- CyberScoop – "AI policy circles targeted in China-linked phishing operation": https://cyberscoop.com/china-cyber-espionage-ta419-phishing-us-ai-policy-experts/
.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0



Comments (0)