- Category
- War in Ukraine
China-Linked Hackers Pose as US Officials in Bid to Breach America’s AI Experts

China-linked hackers attempted to breach the cloud accounts of US artificial intelligence policy experts by posing as former senior American officials and an employee of AI company Anthropic, using fake policy outreach to lure targets into handing over their Microsoft credentials.
We bring you stories from the ground. Your support keeps our team in the field.
According to Defense One on October 1, cybersecurity firm Proofpoint linked the campaign to TA419, a China-aligned hacking group that researchers say operates in support of Beijing’s intelligence interests. The hackers targeted AI specialists at US think tanks, universities, and law firms.
The attackers approached researchers with invitations to advise on AI policy and export controls, presenting the messages as legitimate professional outreach. Once a recipient engaged, the hackers followed up with links directing them to a fake OneDrive page designed to steal Microsoft login credentials.

Among those impersonated were Lynne Parker, a former principal deputy director of the White House Office of Science and Technology Policy, and Heidi Crebo-Rediker, who previously served as the State Department’s first chief economist.
Beginning July 8, the hackers posed as Parker and Crebo-Rediker while inviting AI experts to join a fictitious “AI Policy Advisory Committee” or contribute to a purported Senate Foreign Relations Committee report on AI export controls and supply chains, according to Defense One.
Proofpoint also identified a similar operation in February, when the group impersonated a senior Anthropic employee while contacting an AI policy analyst at a US think tank. The message carried the subject line “Request for Feedback on Military Integration of Claude,” referring to discussions over the military use of Anthropic’s AI models.
Proofpoint said the hackers have “consistently shown an interest in defense, national security, energy, international relations, and foreign policy targets, predominantly with a nexus to the US and Japan.” The company assessed that targeting AI policy experts represented an expansion of the group’s existing intelligence interests.

Parker learned about the impersonation on July 9 after two recipients contacted her separately to verify whether she had sent the emails. She confirmed the messages were fraudulent and subsequently warned other colleagues, Defense One reported.
The hackers also registered web addresses impersonating the Heritage Foundation, Japanese Defense Minister Shinjiro Koizumi, and the Japan–Taiwan Exchange Association, according to Proofpoint. Such domains could be used to make fraudulent approaches appear more credible to potential targets.
The report did not establish how many people were targeted, whether any accounts were successfully breached, or whether the hackers ultimately obtained sensitive information.
Earlier, Russian state-backed hackers were reported to have targeted the email systems of US nuclear scientists, defense contractors, and government employees, with researchers linking the campaign to intelligence gathering on nuclear research, military logistics, procurement, and policy.
Discuss this article:





-72b63a4e0c8c475ad81fe3eed3f63729.jpeg)
-874d7af41d843e5292ccf23a83f91f37.png)

