Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing
A suspected Chinese espionage group has impersonated senior AI policy figures in phishing campaigns targeting American experts at universities, think tanks, and law firms, according to security researchers at Proofpoint. The group, tracked as TA419, aimed to harvest login credentials from AI policy specialists working on issues of strategic importance to Beijing. This campaign represents part of a broader pattern of Chinese cyberespionage targeting the artificial intelligence sector, complementing earlier reports of data theft by Chinese AI firms.
The bulk of the phishing campaign occurred in July 2026, beginning 8 July when the group impersonated Lynne Edwards Parker, former principal deputy director of the White House Office of Science and Technology Policy, and Heidi Crebo-Rediker, a prominent economist and foreign policy expert. Targets received emails inviting them to join a fake AI policy advisory committee or contribute to a Senate foreign relations committee report, which then directed them to malicious domains using fake OneDrive loading screens to steal Microsoft 365 credentials. A separate February 2026 campaign had spoofed a senior Anthropic employee in an email with the subject line "Request for Feedback on Military Integration of Claude," targeting an AI policy analyst at a US think tank.
- Chinese espionage group impersonated AI policy figures in phishing campaigns targeting US experts.
- Campaigns in July 2026 used fake advisory committee invitations to steal cloud credentials.
- Broader effort targeting AI policy makers on technologies of strategic interest to China.
New here? Start with this
Cyberspies believed to be working for China have conducted phishing attacks against American experts in artificial intelligence policy. These specialists work at universities, think tanks and law firms on issues of strategic importance to Beijing. Phishing is a fraud technique in which fraudsters send deceptive emails designed to trick recipients into revealing sensitive information such as passwords.
The attacks involved impersonating senior figures in artificial intelligence policy and research, including a former White House official and executives at leading technology companies. Targets received emails that appeared to come from these respected figures, inviting them to contribute to government reports or join advisory committees. The links in these emails led to fake websites mimicking legitimate Microsoft services, designed to capture their login credentials.
This is part of a broader pattern of Chinese government cyberespionage targeting the artificial intelligence industry. Such operations are understood as attempts to gather intelligence on American artificial intelligence policy and national security concerns. The targeting of policy specialists suggests China is interested in understanding how the United States is developing its policy approach to artificial intelligence.