cd /news/ai-safety/chinese-hackers-pose-as-us-ai-policy… · home › topics › ai-safety › article
[ARTICLE · art-143152] src=cryptobriefing.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Chinese hackers pose as US AI policy figures in campaign targeting AI experts

Proofpoint attributed a credential-harvesting campaign targeting AI policy and national security specialists to a Chinese state-aligned group it tracks as TA419, according to a report published October 1, 2026. In a February 2026 incident, TA419 impersonated a senior Anthropic employee with the subject line "Request for Feedback on Military Integration of Claude," and also impersonated Lynne Parker and former State Department chief economist Heidi Crebo-Rediker, to lure think tank, university, and law firm targets to a fake OneDrive page that captured typed credentials. Proofpoint did not confirm any stolen credentials, successful breaches, or compromised data in the campaign.

by read3 min views1 publishedOct 1, 2026
Chinese hackers pose as US AI policy figures in campaign targeting AI experts
Image: Cryptobriefing (auto-discovered)

Anthropic official brand assets (anthropic.com)

Proofpoint says state-aligned group TA419 posed as AI policy figures to try to harvest email credentials from think tanks, universities, and law firms

A Chinese state-aligned hacking group has reportedly been posing as prominent voices in US artificial intelligence policy. The goal: to trick experts into handing over their email logins.

One of the borrowed identities belonged to a senior Anthropic employee. The fake message asked recipients for feedback on putting Claude to military use, which is an unusually specific way to get an AI researcher’s attention.

What Proofpoint found #

Cybersecurity firm Proofpoint attributes the activity to a group it tracks as TA419. Its findings appeared in a report published on October 1, 2026.

According to Proofpoint, TA419 has been going after specialists in AI policy and national security since at least 2025. The activity appears to have intensified since then.

The targets sit in three places: think tanks, universities, and law firms. Many work on AI regulation and national strategy.

Some targets were also tied to organizations connected to the US-Japan relationship.

The standout incident came in February 2026. The attackers sent an email impersonating a senior Anthropic employee with this subject line:

Request for Feedback on Military Integration of Claude

A familiar con, carefully dressed #

The technique itself is not exotic. The hackers first send what looks like a genuine request to collaborate. Once a target engages, a follow-up arrives with a link.

AI, tech, and the markets they move—in one daily briefing.

Daily. Free. Join 34,000+ readers across crypto, finance, and policy.

That link leads to a fake OneDrive page. The page is built to capture whatever credentials the victim types in.

Anthropic was not the only name used as a lure. Proofpoint says TA419 also impersonated Lynne Parker and Heidi Crebo-Rediker, a former chief economist at the State Department.

One important caveat: Proofpoint’s findings did not confirm any stolen credentials in this campaign. No successful breaches or compromised data have been disclosed.

Why the AI policy world is a target #

Policy experts are an attractive entry point for a simple reason. They often sit between the labs building the models and the officials writing the rules.

An inbox at a think tank or law firm might contain draft regulatory language, private correspondence with officials, or candid views on national strategy.

Targeting the US-Japan nexus fits that logic too. Experts working across both countries’ policy circles may have visibility into coordination between allies on technology questions.

What this means #

For AI labs, the campaign is a reminder that their brand is now an attack surface. A company does not have to be breached to be useful to hackers. Its name just has to be trusted enough to open doors. The defensive lesson is unglamorous but clear. Collaboration requests from high-profile names deserve a quick check through a separate, known channel before anyone clicks a file-sharing link. A sudden OneDrive login prompt after a flattering email is worth a second look.

The specificity of the lures also tells you something about the attackers. A subject line about military integration of a particular AI model reflects real familiarity with the debates happening in this community.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our

Editorial Policy.

── more in #ai-safety 4 stories · sorted by recency
── more on @proofpoint 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/chinese-hackers-pose…] indexed:0 read:3min 2026-10-01 · —