Chinese Hackers Impersonate AI Experts in Password Theft Campaign

The420.in Staff
4 Min Read

Chinese hackers impersonated AI experts in an email campaign aimed at stealing passwords from US policy specialists and officials.

How Did the Campaign Work?

Cybersecurity company Proofpoint said it had tracked a hacking group it calls “TA419” attempting to steal passwords from people working at US and Japanese think tanks, defence contractors, universities and law firms since at least 2025.

Proofpoint attributed the activity to a Chinese group based on the malware used, the internet infrastructure supporting the attacks and the types of targets pursued. The company said these characteristics aligned with Chinese intelligence collection priorities.

The recent campaign involved emails made to appear as though they had been sent by experts in artificial intelligence or statecraft. The messages typically proposed AI-related collaborations or initiatives before directing recipients towards websites designed to steal passwords.

The Chinese Embassy in Washington did not immediately respond to a request for comment. Beijing has long denied conducting cyberespionage operations.

Who Was Impersonated?

Among those impersonated was Lynne Parker, a former principal deputy director of the White House Office of Science and Technology Policy and an expert in artificial intelligence.

Alex Engler, a former White House official who now heads the Penn Center on Technology, Innovation, and Democracy, received an email that appeared to have come from Parker. The message invited him to join a new AI policy project. Engler said the approach seemed unusual, prompting him to check with others in the field. He subsequently concluded that the sender was an impostor.

Parker said Engler was one of two people who received suspicious messages purporting to come from her in early July.

What Were the Hackers Seeking?

Proofpoint did not identify the targets publicly but said they included experts working on AI regulation, export controls and national AI strategy.

The targeting involved fewer than 10 individuals across a handful of organisations, according to the cybersecurity company. It said the pattern suggested an intelligence interest in US policymaking rather than an interest limited to stealing technology.

Parker said competition between the United States and China over artificial intelligence made interest in the policy community understandable if the objective was to obtain information about AI policy plans.

The campaign illustrates how policy expertise itself can become a target when attackers seek information about government priorities, regulatory plans and strategic decision-making.

Why Are AI Policy Experts Being Targeted?

The activity focused on people positioned close to debates over AI regulation, export controls and national strategy. Such individuals can hold information about emerging policy directions even when they are not directly responsible for sensitive technical systems.

Proofpoint’s findings indicate that the attackers relied on social engineering rather than simply attempting direct technical intrusion. By impersonating recognised figures and proposing plausible professional collaborations, the campaign sought to establish enough trust to lead recipients to credential-stealing websites.

Engler said he could not speculate about why he was targeted. Proofpoint, however, assessed the wider selection of individuals as pointing towards intelligence collection related to US policymaking.

The campaign also demonstrates the security risks surrounding professional communications in the AI policy community, where apparently legitimate invitations and collaboration requests can be used as a route to credentials and potentially sensitive information.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected