Category
War in Ukraine

China-Linked Hackers Pose as US Officials in Bid to Breach America’s AI Experts

3 min read
Google logo Prefer U24 Media on Google
Authors
Photo of Ivan Khomenko
News Writer
Illustrative image of digital code overlaid with the Chinese flag. (Source: Getty Images)
Illustrative image of digital code overlaid with the Chinese flag. (Source: Getty Images)

China-linked hackers attempted to breach the cloud accounts of US artificial intelligence policy experts by posing as former senior American officials and an employee of AI company Anthropic, using fake policy outreach to lure targets into handing over their Microsoft credentials.

We bring you stories from the ground. Your support keeps our team in the field.

DONATE NOW

According to Defense One on October 1, cybersecurity firm Proofpoint linked the campaign to TA419, a China-aligned hacking group that researchers say operates in support of Beijing’s intelligence interests. The hackers targeted AI specialists at US think tanks, universities, and law firms.

The attackers approached researchers with invitations to advise on AI policy and export controls, presenting the messages as legitimate professional outreach. Once a recipient engaged, the hackers followed up with links directing them to a fake OneDrive page designed to steal Microsoft login credentials.

Among those impersonated were Lynne Parker, a former principal deputy director of the White House Office of Science and Technology Policy, and Heidi Crebo-Rediker, who previously served as the State Department’s first chief economist.

Beginning July 8, the hackers posed as Parker and Crebo-Rediker while inviting AI experts to join a fictitious “AI Policy Advisory Committee” or contribute to a purported Senate Foreign Relations Committee report on AI export controls and supply chains, according to Defense One.

Proofpoint also identified a similar operation in February, when the group impersonated a senior Anthropic employee while contacting an AI policy analyst at a US think tank. The message carried the subject line “Request for Feedback on Military Integration of Claude,” referring to discussions over the military use of Anthropic’s AI models.

Proofpoint said the hackers have “consistently shown an interest in defense, national security, energy, international relations, and foreign policy targets, predominantly with a nexus to the US and Japan.” The company assessed that targeting AI policy experts represented an expansion of the group’s existing intelligence interests.

Parker learned about the impersonation on July 9 after two recipients contacted her separately to verify whether she had sent the emails. She confirmed the messages were fraudulent and subsequently warned other colleagues, Defense One reported.

The hackers also registered web addresses impersonating the Heritage Foundation, Japanese Defense Minister Shinjiro Koizumi, and the Japan–Taiwan Exchange Association, according to Proofpoint. Such domains could be used to make fraudulent approaches appear more credible to potential targets.

The report did not establish how many people were targeted, whether any accounts were successfully breached, or whether the hackers ultimately obtained sensitive information.

Earlier, Russian state-backed hackers were reported to have targeted the email systems of US nuclear scientists, defense contractors, and government employees, with researchers linking the campaign to intelligence gathering on nuclear research, military logistics, procurement, and policy.

See all

Never miss a frontline update

Make UNITED24 Media a preferred source on Google and get our exclusive reporting and military analysis from inside Ukraine.