Proofpoint’s logo (illustrative). Image: SeekVectorLogo.Com / Wikimedia Commons, Public domain, cropped

A China-aligned hacking group posed as a senior Anthropic employee and a former White House AI official to try to break into the email accounts of American AI policy experts, cybersecurity company Proofpoint said on Thursday, according to CNN and Reuters.

Proofpoint tracks the group as TA419 and says it supports Beijing’s intelligence interests. Its targets were people at US universities, think tanks and law firms who work on AI export controls, national AI strategy and the military use of AI.

A fake Anthropic email about Claude and the military

The earliest lure came on February 26. The hackers wrote to an AI policy analyst at a US think tank in the name of a senior Anthropic employee, under the subject line “Request for Feedback on Military Integration of Claude”. Through the exchange that followed, they tried to steal the analyst’s email password, Proofpoint said. The research doesn’t name the employee whose identity was used.

The timing was pointed. The next day, the Trump administration ordered federal agencies and military contractors to stop doing business with Anthropic after it refused to let the Pentagon use its AI without restrictions, the dispute that later reached an appeals court.

Posing as a former White House AI official

From July 8, the group switched to impersonating Lynne Parker, a former principal deputy director of the White House Office of Science and Technology Policy who served under both Trump and Joe Biden, and then Heidi Crebo-Rediker, the State Department’s first chief economist. The emails invited experts to join a made-up “AI Policy Advisory Committee” or to contribute to a supposed Senate Foreign Relations Committee report on AI export controls and supply chains.

Anyone who replied was sent a malware-laced document or pointed to a fake OneDrive page built to capture Microsoft login details. Proofpoint said fewer than 10 people at a handful of organisations were targeted, which it read as “an intelligence interest in US policymaking rather than technology theft alone”.

Reuters identified one target: Alex Engler, a former White House official who now runs the Penn Center on Media, Technology, and Democracy. He said the invitation from “Parker” felt slightly off, and checking with others confirmed it was an impostor.

Parker told CNN that colleagues began contacting her when the emails arrived, and that she wanted to warn people but couldn’t know who had been targeted:

On a personal level, I felt sadness that relationships I’ve built over my career were being exploited by bad actors to deceive others.

Lynne Parker, former White House technology official, to CNN

No sign of a breach, yet

Proofpoint found no evidence that any of the targeted organisations were breached, though it said it may have seen only part of the activity. It linked the group to China through its malware, the servers it used and its choice of targets. “We are confident that [the hacking group] is a Chinese government-aligned threat actor,” Proofpoint researcher Mark Kelly told CNN, citing its targeting, infrastructure and “corroboration from industry partners”.

The group has gone after defence, national security, energy and foreign policy targets in the US and Japan since at least 2025, and Proofpoint called the AI policy campaign “an extension of that remit rather than a departure from it”, according to Nextgov/FCW. It expects TA419 to keep spoofing real experts. China routinely denies US hacking allegations, and Anthropic hasn’t commented on the findings.

The campaign adds to a run of accusations about Chinese efforts to get at American AI. This week OpenAI said people linked to Moonshot AI tried to copy its models’ hidden reasoning, and Britain’s MI5 warned universities about a Chinese institute funding AI research. It also comes days after Donald Trump and Xi Jinping discussed AI at their summit.

Why it matters

The people who shape AI rules are now intelligence targets in their own right. Reading their inboxes could show Beijing how Washington is thinking about export controls and military AI before decisions are made, and using a real Anthropic employee’s name shows how easily trust in the AI world can be turned into a way in.

Sources: CNN; Reuters; Nextgov/FCW.

Latest Policy & Safety news

More Policy & Safety news