Cybersecurity firm Proofpoint has uncovered a targeted espionage campaign in which China-aligned hacking group TA419 impersonated prominent US AI experts and former government officials to ta
Cybersecurity firm Proofpoint has uncovered a targeted espionage campaign in which China-aligned hacking group TA419 impersonated prominent US AI experts and former government officials to target researchers and organizations involved in AI policy.
The campaign targeted fewer than 10 individuals across think tanks, universities, defence contractors and law firms in the US and Japan, with attackers seeking email credentials and cloud account access.
The hackers reportedly used identities including former White House Office of Science and Technology Policy official Lynne Parker, former State Department Chief Economist Heidi Crebo-Rediker and a senior Anthropic employee. Emails offered targets opportunities to collaborate on AI projects, discuss export controls or provide feedback on the military use of AI models such as Claude before directing them to malicious websites designed to steal Microsoft login credentials. Proofpoint said the highly selective targeting points to an intelligence-gathering interest in US AI policymaking and regulatory plans.
Reuters identified Alex Engler, head of the Penn Centre on Media, Technology, and Democracy and a former White House official, as one of the targets. Engler received an email in July from an address impersonating Parker, inviting him to join an AI policy project. He described the message as
“slightly, nebulously off,”
checked with colleagues and avoided the credential theft attempt.
AI Policy researchers have become high-value cyber targets
AI policy researchers sit at the intersection of technology, national security and regulation, making their work valuable beyond the academic sector. Their research can cover export controls, military applications, AI governance and national strategy areas that directly inform government decisions.
The threat extends beyond stealing researchers’ email conversations. CrowdStrike’s 2026 Technology Threat Landscape Report found that technology was the world’s most targeted industry, with China-nexus adversaries responsible for more than 58% of state-sponsored targeted intrusions against the sector. The firm said these operations increasingly seek AI capabilities and intellectual property that adversaries cannot develop quickly enough themselves.
AI research is also becoming a target across universities and other institutions outside major AI companies. Google Threat Intelligence Group reported that in the second quarter of 2026, it observed growing attempts to obtain proprietary AI research and models, including attacks against government, military, healthcare and academic organizations. Separately, a June 2026 CNAS report identified industrial espionage and remote access to foreign computing resources among methods being used to strengthen China’s AI capabilities.
Why AI Policy may be as valuable as AI technology
AI policy can reveal how governments intend to regulate advanced models, restrict sensitive technology and manage access to critical AI infrastructure. The US AI Diffusion Rule, for example, established licensing requirements covering advanced computing chips and the model weights of the most advanced AI systems. That makes policy discussions potentially useful for anyone trying to understand where future restrictions or market-access rules could emerge.
The strategic value extends beyond already announced regulations. In July 2025, the White House established the American AI Exports Program to promote US full-stack AI technology internationally, covering chips, servers, cloud services, networking, data pipelines and AI models. Information about how policymakers plan to implement such programmes can therefore provide insight into technology supply chains, export markets and national-security priorities.
The implications also extend to crypto companies, where access to a trusted employee account can expose internal communications, cloud systems, developer tools and other connected services. CoinGecko’s 2026 security report found that crypto platforms lost more than $3.63 billion across 245 documented incidents between January 2025 and July 2026, with stolen private keys, supply-chain attacks and infrastructure weaknesses among the major causes.
Enjoyed this? BookmarkDeFi Planet, explore related topics, and follow us onTwitter,LinkedIn,Facebook,Instagram,Threads, and CoinMarketCap Community for seamless access to high-quality industry insights
Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.
The post China-Linked Hackers Impersonate US AI Experts in Phishing Campaign appeared first on DeFi Planet.