Chinese Hackers Impersonated AI Experts to Target US Policy Experts, Proofpoint Says

Proofpoint says China-aligned hackers TA419 impersonated real AI experts to steal login details from US and Japanese policy experts.

maisiekooc
Maisie Morrison

AgentLocker Editor

AI News
Chinese Hackers Impersonated AI Experts to Target US Policy Experts, Proofpoint Says

Chinese hackers posed as artificial intelligence experts to target policy specialists in the United States and Japan, according to a new report from cybersecurity firm Proofpoint.

The report was released on Thursday. It said a China-aligned hacking group known as TA419 used the names of real people to gain the trust of its targets.

One of the people impersonated was Lynne Edwards Parker. She is the former principal deputy director of the White House Office of Science and Technology Policy.

The hackers did not use their own names. Instead, they pretended to be real AI experts so their messages would seem trustworthy.

How the TA419 Scheme Worked

According to Proofpoint, the campaign took place in July. The hackers reached out to US policy experts while pretending to be well-known figures in the AI field.

The first emails looked harmless. One example was an invitation to join an "AI Policy Advisory Committee."

The messages were meant to start a conversation rather than attack right away. Once a target responded, they were sent to a fake login page built to steal their usernames and passwords.

The hackers also used a trick that places a fake browser pop-up window inside a real webpage. The pop-up looks like a normal sign-in prompt.

This makes it harder for victims to notice that they are handing their information to hackers. The fake window is designed to look authentic.

Proofpoint said the group has been active since April 2025. That means the July campaign was part of a longer effort stretching back more than a year.

Who Was Targeted

The targets included policy experts at think tanks, defence contractors, universities and law firms. These people were located in both the US and Japan.

Proofpoint did not name the people who were targeted. However, Reuters confirmed that at least one of them was Alex Engler.

Engler is a former White House official. He now heads the Penn Center on Media, Technology, and Democracy.

He told Reuters that he received one of the emails. After checking with colleagues in the industry, he learned that the message came from an impersonator.

This is not the first time TA419 has used this approach. In February, the same group impersonated a "prominent" employee of AI company Anthropic to target AI policy experts.

In both cases, the hackers borrowed the identity of a trusted person in the AI world to open a conversation with their targets.

Parker did not respond to a request for comment from Al Jazeera.

Proofpoint said it expects TA419 to keep targeting think tanks and other policy experts. The firm also believes the group will continue using the identities of real-world experts to do so.

From our research desk
AI Jobs Automation Index
Which jobs are AI tools targeting most? We mapped 3,400+ AI tools to real job functions — with BLS employment & salary data.
Explore the index
maisiekooc

Written by

Maisie is a news writer at Agent Locker, covering the latest developments in artificial intelligence, emerging technology and the companies shaping the future.

Discover AI Agents