Proofpoint says the group impersonated a former White House science official, an economist, and a senior Anthropic employee in emails to AI policy experts at U.S. think tanks, universities, and law firms.
Hackers linked to China posed as well-known AI policy figures to try to steal the email and cloud account logins of AI policy experts in the United States, security company Proofpoint said on Oct. 1.
Proofpoint calls the group TA419 and describes it as aligned with China and focused on spying. The company said the targets worked at U.S. think tanks, universities, and law firms. It did not name those organizations, say how many people were targeted, or say whether any account was broken into.
Proofpoint did not report that the hackers used AI. The connection to AI is the targets: people who study and advise on U.S. AI policy.
The emails looked like invitations from people the experts would recognize
Starting July 8, 2026, the group sent emails under the name of Lynne Edwards Parker, a former principal deputy director of the White House Office of Science and Technology Policy, and then under the name of Heidi Crebo-Rediker, an economist and foreign policy expert. The emails came from accounts the hackers had set up in the two women’s names.
The first email to each expert invited the expert to join an “AI Policy Advisory Committee,” which does not exist, or to contribute to a Senate Committee on Foreign Relations report on AI export controls and supply chains.
Only when an expert replied did the hackers send a link, which they described as a way to share more information.
Earlier, in February 2026, the group posed as a senior Anthropic employee in an email to an AI policy analyst at a U.S. think tank. The subject line read “Request for Feedback on Military Integration of Claude.” Proofpoint said that email led to a similar fake sign-in page.
The subject line referred to a dispute over how the U.S. military could use Claude, Anthropic’s AI model. The Defense Department said AI companies it works with must allow their models to be used for “any lawful use.” Anthropic asked for two exceptions: surveillance of U.S. citizens at home and fully autonomous weapons. In March, the department barred its contractors from using Anthropic’s AI.
A fake Microsoft sign-in page gave the hackers access even when an expert used a one-time code
The link the hackers sent led to a page made to look like OneDrive, Microsoft’s file storage service, showing a folder of documents. When an expert clicked a document, what looked like a Microsoft sign-in window appeared.
The window was the hackers’ own, but it carried out a real sign-in. It passed everything the expert typed to Microsoft and passed Microsoft’s responses back. The expert’s password worked, and so did the one-time code many organizations require as a second step.
When Microsoft approved the sign-in, the hackers kept a copy of the small file a browser stores to show someone is already signed in. With that file, the hackers could open the expert’s account without the password or a new code.
The hackers’ software also clicked “Keep me signed in” on the expert’s behalf, which Proofpoint said extends how long the stolen access lasts.
Proofpoint says the emails likely serve Chinese intelligence
Proofpoint said the emails to AI policy experts “likely” support Chinese intelligence efforts to understand U.S. AI policy and regulation. It pointed to the people TA419 has targeted.
Since at least April 2025, Proofpoint has seen the group send similar emails to people at think tanks, defense contractors, universities, and law firms in the United States and Japan. Those people work on defense, national security, energy, and foreign policy. This year the group also sent emails from web addresses that resemble those of the Heritage Foundation, a U.S. think tank, and of the official website of Japan’s defense minister, Shinjirō Koizumi.
Proofpoint noted that the emails come as the United States and China compete over AI and dispute export controls. The company said the group’s activity had not been reported publicly before.
Proofpoint expects the group to keep impersonating real experts
Proofpoint said TA419 will likely continue to target think tanks and policy experts working on technologies and regions that interest the Chinese government, and to keep using the names of real experts.
Proofpoint advised organizations the group might target to consider passkeys. A passkey replaces the password and one-time code with a check on the person’s own phone or computer, and it works only on the real website. Proofpoint advised individuals to treat an unexpected invitation from an expert in their field as a possible first step in an attack, and to confirm it by contacting the sender another way instead of replying to the email.

