Chinese Hackers Target AI Experts by Impersonating Trusted Policy Figures

· · Views: 2,350 · ⏱ 3 min time to read

A China-linked hacking group has been impersonating prominent U.S. artificial-intelligence experts and former government officials in an effort to steal email credentials from researchers working on AI policy, according to cybersecurity researchers.

Reuters reported that Proofpoint has tracked the hackers, designated TA419, attempting to compromise specialists at think tanks, universities, defense contractors and law firms since at least 2025.

Rather than relying on obviously malicious messages, the attackers posed as people whose names would make sense inside the professional networks of their targets.

Attackers impersonated a former White House AI official

One campaign impersonated Lynne Parker, who previously served as principal deputy director of the White House Office of Science and Technology Policy.

Reuters reported that emails pretending to come from Parker approached AI specialists about what appeared to be collaborative work on artificial-intelligence policy.

Among those targeted was Alex Engler, head of the Penn Center on Media, Technology, and Democracy.

Engler told Reuters that he received an email proposing an AI-policy project but eventually recognized the approach as fraudulent.

Proofpoint said the campaign involved fewer than 10 observed targets, suggesting that the operation emphasized carefully selected individuals rather than mass phishing.

The apparent objective was intelligence, not model theft

The target selection is significant.

According to Reuters, Proofpoint assessed that the campaign appeared aimed at collecting intelligence about U.S. AI policy and decision-making, rather than directly stealing source code or AI models.

That makes researchers, lawyers and policy specialists attractive targets even when they do not work inside frontier AI laboratories.

A compromised inbox can reveal unpublished research, government contacts, policy discussions, meeting schedules and relationships between companies and regulators.

The Chinese Embassy did not provide Reuters with comment on the specific allegations. Beijing has repeatedly denied accusations that it conducts cyberespionage.

Impersonating trusted experts is a recurring espionage tactic

The technique fits a broader pattern documented by Proofpoint.

In a separate investigation published in 2025, the security company described another China-linked group, TA415, impersonating U.S. government officials and the U.S.-China Business Council while targeting government, academic and think-tank personnel.

Proofpoint said those messages used the credibility associated with recognizable public figures and institutions to make the phishing approaches more convincing.

That method attacks something security software cannot fully patch: professional trust.

If a message apparently comes from someone working in the same field, discusses a plausible research topic and asks for collaboration, the interaction resembles normal academic or policy work.

AI competition is creating new high-value identities

The latest campaign illustrates how the AI race is expanding the cyberattack surface beyond chipmakers and model developers.

Experts who understand regulation, government strategy or national AI policy can possess intelligence just as valuable as technical information.

For cybersecurity teams, that means protecting AI organizations cannot stop at infrastructure.

The identities of researchers, executives, advisers and public officials can themselves become attack infrastructure when adversaries use their reputations as phishing tools.

As AI becomes more strategically important, the people who shape the rules around it may increasingly require the same level of cyber protection as the systems they are debating.

Share
f 𝕏 in
Copied