China-linked hackers posed as former US officials, Anthropic employee to target AI experts China-aligned hackers tracked as TA419 impersonated former White House OSTP principal deputy director Lynne Parker, former State Department chief economist Heidi Crebo-Rediker and a senior Anthropic employee to phish AI policy experts at think tanks, universities and law firms, according to Proofpoint findings released Thursday. Starting July 8, the attackers invited targets to a fictitious "AI Policy Advisory Committee" or a purported Senate Foreign Relations Committee report on AI export controls, then sent fake OneDrive links to steal Microsoft login credentials; a February campaign used the subject line "Request for Feedback on Military Integration of Claude." Proofpoint did not say how many people were targeted or whether any accounts were compromised. China-linked hackers posed as former US officials, Anthropic employee to target AI experts Proofpoint identified phishing campaigns that borrowed prominent figures’ identities to approach U.S. policy researchers before attempting to steal access to their cloud accounts. Chinese hackers impersonated a former senior White House technology official, a former State Department economist and a senior Anthropic employee in attempts to break into the cloud accounts of artificial intelligence policy experts, according to findings from cybersecurity company Proofpoint released Thursday. The campaigns targeted researchers at think tanks, universities and law firms, using invitations to advise on AI policy and export controls to start conversations. Once recipients responded, the attackers sent links designed to steal their Microsoft login credentials, per the findings. Among those impersonated were Lynne Parker, a former principal deputy director of the White House Office of Science and Technology Policy, and Heidi Crebo-Rediker, who served as the State Department’s first chief economist. Proofpoint connected the activity to a group tracked as TA419, describing it as a China-aligned outfit supporting Beijing’s intelligence interests. The report doesn’t say how many people were targeted, whether any accounts were successfully compromised or if the attackers obtained any information. Beginning July 8, the hackers posed as Parker and then Crebo-Rediker in messages inviting AI experts to join a fictitious “AI Policy Advisory Committee” or contribute to a purported Senate Foreign Relations Committee report on AI export controls and supply chains. Parker’s White House roles included assistant director for AI and founding director of the National AI Initiative Office. Crebo-Rediker, now a Council on Foreign Relations senior fellow, previously worked as the Senate Foreign Relations Committee’s chief of international finance and economics. After a recipient engaged with the initial messages, the attackers followed up with correspondence that directed targets to a fake OneDrive page used to attempt the account theft. The group had also used a similar approach in February, impersonating a senior Anthropic employee in an email to an AI policy analyst at a U.S. think tank, Proofpoint said. The subject line read, “Request for Feedback on Military Integration of Claude,” invoking ongoing debate over military use of the company’s AI models. The research did not name the impersonated employee. The hackers have “consistently shown an interest in defense, national security, energy, international relations, and foreign policy targets, predominantly with a nexus to the U.S. and Japan,” the report says. “The targeting of AI policy experts represents an extension of that remit rather than a departure from it.” In an email to Nextgov/FCW , Parker confirmed that she learned of the impersonation on July 9, when two recipients contacted her through separate channels to ask whether she had sent the emails. She told them the messages were fraudulent and alerted other colleagues. “The challenge is that, without knowing who the bad actors are targeting, it’s difficult to reach everyone who might be at risk,” Parker said. “It is personally troubling to see the trust and relationships I’ve built over my career exploited to deceive others,” she added. “Targeting people in the field can be a way to gain access to valuable information and networks. Protecting America’s AI leadership requires protecting the people and institutions behind it and recognizing that trusted relationships can themselves become a target.” Crebo-Rediker and Anthropic did not respond to requests for comment. China’s embassy in Washington, D.C., was also contacted. Chinese officials have routinely denied allegations of state-backed hacking and espionage. The decision to target policy researchers highlights expanding intelligence threats in the global AI race between the U.S., China and other nation-states. Access to experts’ accounts could expose private discussions and professional contacts relevant to decisions about AI’s development, military use and sale abroad. The cyberspies’ approach also illustrates how attackers continue to exploit the dynamics of routine professional exchanges for information-gathering. The findings also come as AI companies gain an increasingly direct role in Washington’s debate over how to oversee the fast-evolving technology. President Donald Trump met with industry leaders Tuesday to endorse voluntary AI safety commitments https://www.wsj.com/tech/ai/tech-ceos-privately-questioned-amodei-for-sounding-ai-alarm-bells-aaa47df3 . Anthropic CEO Dario Amodei also had dinner with Trump on Sunday. Proofpoint found that the attackers registered web addresses impersonating the Heritage Foundation, Japan’s defense minister Shinjiro Koizumi and the Japan–Taiwan Exchange Association. Posing as those figures and organizations could help the hackers convince experts that a malicious email is worth their time. “At the end of the day, humans are our best line of defense,” Don Styer, a former Navy Supply Corps officer and executive vice president for federal services at Consulting Solutions, said in an interview. Attackers can exploit trust through impersonation or seemingly routine requests, he said, adding that foreign adversaries value intelligence they can’t find in public sources and may combine seemingly innocuous details to build a larger picture of a target. Professional outreach has long been used as an intelligence tool. Nextgov/FCW reported in January https://www.nextgov.com/people/2026/01/suspected-chinese-spies-targeted-former-state-official-venezuela-research/410943/ that a suspected Chinese spying outfit approached a former senior State Department official last year with an offer to pay for research on U.S. policy toward Venezuela. The International Consortium of Investigative Journalists reported in June https://www.icij.org/investigations/china-targets/chinese-spies-are-posing-as-recruiters-to-target-officials-and-journalists/ that its reporters received suspicious consulting offers after publishing an investigation into China’s transnational repression. Separately, Britain’s MI5 on Wednesday accused the China General Technology Research Institute of funding academic work https://www.reuters.com/world/uk/uk-accuses-china-using-academics-spy-ai-other-tech-research-2026-09-30/ to improve Chinese intelligence capabilities. Over 100 U.K.-based academics had contributed to its projects, including research involving AI and cybersecurity, according to the agency, which added that many participants may have been unaware of the institute’s intelligence ties. The targeting comes amid broader U.S. concerns about Chinese efforts to siphon American AI capabilities. Early last month, the NSA and other agencies accused Chinese developers https://www.nextgov.com/artificial-intelligence/2026/09/intelligence-agencies-warn-chinas-large-scale-ai-model-distillation-efforts/415851/ of conducting large-scale distillation campaigns that use responses from advanced U.S. models to train competing systems. The attackers revealed in Proofpoint’s findings “will likely continue targeting think tanks and policy experts working on technologies, and in geographies, of particular interest to the Chinese government” and will “likely also continue spoofing the identities of real subject-matter experts,” the company said.