Chinese Hackers Impersonated Ex-White House Official to Trick AI Experts Into Handing Over Passwords

Proofpoint says the campaign used fake collaboration offers and malicious links to target experts working on AI regulation, export controls and national strategy

Hacker
China-aligned hackers targeted AI policy experts by impersonating trusted US officials in credential-phishing attacks Wikimedia Commons

AI experts who spend their working lives thinking about the risks of artificial intelligence were themselves targeted by a surprisingly old-fashioned tactic: hackers pretending to be someone they knew and trusted.

A China-aligned hacking group impersonated former US government officials and an employee of AI company Anthropic in a campaign designed to trick AI policy experts into handing over their login credentials, according to cybersecurity firm Proofpoint.

The campaign targeted people at US think tanks, universities and law firms, with fake emails offering opportunities to collaborate on AI policy projects before directing recipients towards websites designed to steal their passwords. And the targets were not random.

Proofpoint said they included people working on AI regulation, export controls and national AI strategy, areas that could provide valuable insight into US policymaking.

Hackers Pretended To Be a Former White House AI Official

One of the people impersonated was Lynne Parker, who previously served as principal deputy director of the White House Office of Science and Technology Policy. The attackers reportedly began by sending apparently legitimate professional messages.

Rather than immediately demanding a password, they used the kind of invitation that would not necessarily look suspicious to someone working in AI policy: an offer to participate in an AI-related initiative or advisory project. Once a recipient engaged, the attackers could move the conversation towards a malicious link designed to capture their credentials.

Proofpoint said the campaign began on 8 July and involved the impersonation of Parker and foreign policy expert Heidi Crebo-Rediker. In another campaign in February, the same threat actor impersonated a senior Anthropic employee while targeting an AI policy analyst.

One Target Realised Something Was Wrong

Reuters independently identified Alex Engler, a former White House official who now heads the Penn Center on Media, Technology, and Democracy, as one of the people targeted. Engler told Reuters that he received an email appearing to come from Parker inviting him to join a new AI policy project. But something about the message did not feel right.

After checking with other people in the field, he realised that the sender was an impostor. Parker later said that two people she knew of had received suspicious messages pretending to be from her in early July.

The incident illustrates why highly targeted phishing can be difficult to spot. The attacker does not necessarily need to invent a completely convincing stranger. They can instead borrow the identity of someone whose name, job title and professional connections already carry credibility.

The Hackers Were Not Just Pretending To Be Anyone

Proofpoint tracks the group behind the campaign as TA419 and describes it as a China-aligned, espionage-motivated threat actor. The cybersecurity company said it had observed the group targeting people connected to US and Japanese think tanks, defence contractors, universities and law firms since at least April 2025.

The group's targets and infrastructure led Proofpoint to assess that the activity was consistent with Chinese intelligence interests. Reuters reported that the latest campaign involved fewer than 10 people at a handful of organisations.

Proofpoint said the targeting appeared to indicate an interest in US policymaking rather than simply stealing technology.

No Evidence That the Hackers Successfully Breached the Targets

Despite the elaborate impersonation campaign, there is an important caveat. Proofpoint's findings document attempts to steal credentials. They do not establish that the hackers successfully compromised the targeted organisations or obtained the information they were seeking.

CNN reported that Proofpoint had not found evidence of successful breaches of the targeted organisations, although the cybersecurity company warned that its visibility might not capture every part of the activity.

Why AI Policy Experts Were Targeted

The choice of targets appears closely connected to the geopolitical competition surrounding AI. The people targeted worked on subjects including AI regulation, export controls and national AI strategy. Those areas have become increasingly important as the US and China compete over advanced AI technology and governments debate how the technology should be regulated.

Parker told Reuters that the targeting made sense in the context of the US-China competition over AI. 'If that indeed was what the objective was,' she said, attempts to obtain information about AI policy plans would not be surprising.

The Irony of Targeting AI Experts With a Human Weakness

There is an obvious irony in the campaign. The targets were people whose professional lives revolve around one of the world's most advanced technologies. Yet the attackers did not necessarily need an exotic AI exploit to get their attention. They used something much older: social engineering.

The formula was simple. Pretend to be a credible person. Offer an interesting professional opportunity. Establish enough trust to make the conversation feel legitimate. Then introduce a link that can steal credentials.

Proofpoint said the attackers used a multi-stage process that eventually led targets towards credential-phishing pages. It is a reminder that sophisticated organisations can still have a very ordinary weak point: a person deciding whether an email looks trustworthy.

And in this case, the people being targeted were some of the very experts trying to understand how AI could reshape security, government and society.