A group of hackers believed to have been acting on behalf of China pretended to be well-known American AI experts to obtain the email accounts of people who specialize in AI policy.
According to Reuters, the security firm Proofpoint released the findings on Thursday.
Proofpoint has identified the group as TA419 and has said that the hackers concentrated on people at think tanks, universities and law firms who are engaged in AI regulation, export controls and national AI strategy.
The company linked the group to China through its malware, the servers used in the attacks, and the targets it chose, all of which align with what Chinese spies typically look for.
According to CNN, China has on numerous occasions denied the US allegations of hacking.
The hackers sent emails using the names of actual people; according to CNN, in February they posed as a senior employee of Anthropic and emailed an AI policy analyst at a US think tank, with the subject line requesting feedback on the military use of Claude, Anthropic’s AI model.
From July, the group took on the identities of Lynne Parker, a former senior White House technology official, and Caroline Crebo-Rediker, a former State Department economist.
The emails requested that experts join a fictitious AI policy panel or assist with a Senate report concerning AI export controls.
Later messages carried malware-laced files or tried to trick people into handing over their passwords, according to Proofpoint.
Fewer than ten individuals in a number of groups were targeted. Proofpoint stated that this showed a concern with how the US develops policy rather than a desire to steal technology.
Reuters named one of the targets as Alex Engler, a former White House official who is currently in charge of the Penn Center on Media, Technology, and Democracy.
According to Parker, Engler was one of two individuals to receive suspicious emails early on.
“The United States and China are in a competition around AI,” Parker told Reuters.
Proofpoint stated that the group had been targeting US and Japanese think tanks, defence companies, universities and law firms since at least 2025 and that it expects the group to continue impersonating genuine experts.
Get the TNW newsletter
Get the most important tech news in your inbox each week.