{"slug": "chinese-hackers-pose-as-us-ai-policy-figures-in-campaign-targeting-ai-experts", "title": "Chinese hackers pose as US AI policy figures in campaign targeting AI experts", "summary": "Proofpoint attributed a credential-harvesting campaign targeting AI policy and national security specialists to a Chinese state-aligned group it tracks as TA419, according to a report published October 1, 2026. In a February 2026 incident, TA419 impersonated a senior Anthropic employee with the subject line \"Request for Feedback on Military Integration of Claude,\" and also impersonated Lynne Parker and former State Department chief economist Heidi Crebo-Rediker, to lure think tank, university, and law firm targets to a fake OneDrive page that captured typed credentials. Proofpoint did not confirm any stolen credentials, successful breaches, or compromised data in the campaign.", "body_md": "Anthropic official brand assets (anthropic.com)\n\n# Chinese hackers pose as US AI policy figures in campaign targeting AI experts\n\nProofpoint says state-aligned group TA419 posed as AI policy figures to try to harvest email credentials from think tanks, universities, and law firms\n\nA Chinese state-aligned hacking group has reportedly been posing as prominent voices in US artificial intelligence policy. The goal: to trick experts into handing over their email logins.\n\nOne of the borrowed identities belonged to a senior [Anthropic](https://cryptobriefing.com/markets/anthropic/) employee. The fake message asked recipients for feedback on putting Claude to military use, which is an unusually specific way to get an AI researcher’s attention.\n\n## What Proofpoint found\n\nCybersecurity firm Proofpoint attributes the activity to a group it tracks as **TA419**. Its findings appeared in a report published on October 1, 2026.\n\nAccording to Proofpoint, TA419 has been going after specialists in AI policy and national security since at least 2025. The activity appears to have intensified since then.\n\nThe targets sit in three places: think tanks, universities, and law firms. Many work on AI regulation and national strategy.\n\nSome targets were also tied to organizations connected to the US-Japan relationship.\n\nThe standout incident came in February 2026. The attackers sent an email impersonating a senior Anthropic employee with this subject line:\n\nRequest for Feedback on Military Integration of Claude\n\n## A familiar con, carefully dressed\n\nThe technique itself is not exotic. The hackers first send what looks like a genuine request to collaborate. Once a target engages, a follow-up arrives with a link.\n\n### AI, tech, and the markets they move—in one daily briefing.\n\nDaily. Free. Join 34,000+ readers across crypto, finance, and policy.\n\nThat link leads to a fake OneDrive page. The page is built to capture whatever credentials the victim types in.\n\nAnthropic was not the only name used as a lure. Proofpoint says TA419 also impersonated Lynne Parker and Heidi Crebo-Rediker, a former chief economist at the State Department.\n\nOne important caveat: Proofpoint’s findings did not confirm any stolen credentials in this campaign. No successful breaches or compromised data have been disclosed.\n\n## Why the AI policy world is a target\n\nPolicy experts are an attractive entry point for a simple reason. They often sit between the labs building the models and the officials writing the rules.\n\nAn inbox at a think tank or law firm might contain draft regulatory language, private correspondence with officials, or candid views on national strategy.\n\nTargeting the US-Japan nexus fits that logic too. Experts working across both countries’ policy circles may have visibility into coordination between allies on technology questions.\n\n## What this means\n\nFor AI labs, the campaign is a reminder that their brand is now an attack surface. A company does not have to be breached to be useful to hackers. Its name just has to be trusted enough to open doors.\n\nThe defensive lesson is unglamorous but clear. Collaboration requests from high-profile names deserve a quick check through a separate, known channel before anyone clicks a file-sharing link. A sudden OneDrive login prompt after a flattering email is worth a second look.\n\nThe specificity of the lures also tells you something about the attackers. A subject line about military integration of a particular AI model reflects real familiarity with the debates happening in this community.\n\n**Disclosure:** This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our\n\n[Editorial Policy](https://cryptobriefing.com/editorial-policy/).", "url": "https://wpnews.pro/news/chinese-hackers-pose-as-us-ai-policy-figures-in-campaign-targeting-ai-experts", "canonical_source": "https://cryptobriefing.com/chinese-hackers-impersonate-anthropic-employee-phishing/", "published_at": "2026-10-01 11:24:27+00:00", "updated_at": "2026-10-01 11:47:01.695623+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "artificial-intelligence"], "entities": ["Proofpoint", "TA419", "Anthropic", "Claude", "Lynne Parker", "Heidi Crebo-Rediker", "US State Department", "OneDrive"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/chinese-hackers-pose-as-us-ai-policy-figures-in-campaign-targeting-ai-experts", "markdown": "https://wpnews.pro/news/chinese-hackers-pose-as-us-ai-policy-figures-in-campaign-targeting-ai-experts.md", "text": "https://wpnews.pro/news/chinese-hackers-pose-as-us-ai-policy-figures-in-campaign-targeting-ai-experts.txt", "jsonld": "https://wpnews.pro/news/chinese-hackers-pose-as-us-ai-policy-figures-in-campaign-targeting-ai-experts.jsonld"}}