China-Linked Hackers Target AI Policy Experts

China-Linked Hackers Target AI Policy Experts

China-Linked Hackers Target AI Policy Experts
China-linked threat actors are actively impersonating leading economists and AI policy experts through sophisticated phishing campaigns designed to steal credentials and gain access to sensitive policy discussions.

ai policy phishing

How Chinese Hackers Are Infiltrating U.S. AI Policy Circles

A China-nexus threat actor tracked as TA419 has launched multiple credential phishing campaigns targeting artificial intelligence policy experts across the United States, according to a report from cybersecurity firm Proofpoint. The attacks reveal a coordinated intelligence-gathering effort aimed at understanding American AI policy objectives and the regulatory landscape surrounding emerging technologies.

What makes these campaigns particularly sophisticated is the level of impersonation involved. Rather than casting wide nets with generic phishing emails, the attackers are specifically targeting individuals who directly influence U.S. AI policy—including economists, think tank researchers, and former government officials who shape the nation’s technology strategy.

The Tactics Behind the AI Policy Phishing Attacks

TA419 has employed a multi-stage approach that begins with seemingly legitimate requests. Initial emails ask targets to join advisory committees on AI policy, appearing to come from prominent figures in the field. This social engineering tactic is designed to trigger a response from the target.

Once a target replies to the fake request, the attackers activate the second phase: an adversary-in-the-middle attack using a tool called Frameless BitB, which creates a fake browser window within the target’s legitimate browser. This phishing technique is particularly effective because it operates within the user’s authentic session, making detection far more difficult.

The attacks specifically target Microsoft 365 and Entra ID accounts using what researchers describe as a first-party OfficeHome application interface. By compromising credentials for these widely-used platforms, attackers gain access to email systems, documents, and communications containing sensitive policy discussions.

Notable Targets and Impersonation Tactics

Among the victims of these campaigns are individuals with direct government influence. In July, TA419 impersonated Lynne Parker, who previously served as principal deputy director at the White House Office of Science and Technology Policy. The same actor later impersonated Heidi Crebo-Rediker, an economist and foreign policy expert with significant visibility in U.S. policy circles.

In a separate February attack, the group impersonated a senior-level executive at Anthropic, one of the leading artificial intelligence companies. This particular phishing attempt targeted an AI policy analyst at a U.S. think tank with questions about military applications of Anthropic’s Claude AI models.

The precision of these impersonations suggests extensive reconnaissance. Attackers clearly identified which individuals would be credible messengers within policy circles and researched the kinds of requests that would seem natural coming from those individuals.

Why AI Policy Experts Are High-Value Targets

Annie Fixler, director of the Center on Cyber and Technology Innovation at the Foundation for Defense of Democracies, explained the strategic value of compromising these particular targets: “Usually, when we see nation-state cyber actors targeting think tank and academic professionals, the goal is to collect information and insights into U.S. policymaking. These individuals often have regular conversations with government officials, and so gaining access to their email can provide the adversary with behind-the-scenes details about future policy changes or the thinking behind previous decisions.”

In the context of AI, this intelligence has enormous geopolitical value. The United States and China are engaged in a global race for AI dominance, with billions in funding and strategic advantage at stake. Understanding how American policymakers think about AI regulation, safety standards, and export controls would give China significant advantages in both commercial and national security contexts.

The Broader Context of China’s AI Espionage Campaign

The TA419 attacks don’t exist in isolation. Just last month, the Cybersecurity and Infrastructure Security Agency warned that China-based AI companies are launching what it termed “knowledge distillation” campaigns against U.S. AI firms on an industrial scale. These operations systematically extract valuable information about proprietary AI models and training techniques.

TA419 itself has been active since April 2025, according to Proofpoint’s tracking. During this time, the group has expanded beyond AI policy experts to target professionals at think tanks in both the United States and Japan, as well as defense contractors, law firms, and universities.

The technical infrastructure behind these campaigns also reveals sophistication. TA419 registered domains through NameSilo, a web hosting provider, and used Cloudflare’s content delivery network to mask the actual IP address hosting malicious backend infrastructure. This combination of services makes attribution and takedown efforts significantly more difficult.

How to Protect Against AI Policy Phishing Campaigns

Organizations and individuals working on AI policy should implement several defensive measures. First, enable multi-factor authentication (MFA) on all email and productivity accounts, particularly Microsoft 365 and Entra ID accounts. This creates an additional barrier even if credentials are compromised through phishing.

Second, establish verification protocols before responding to requests from colleagues or known contacts. Even if an email appears to come from a trusted individual, consider calling that person directly through a known phone number to confirm the request. The initial phishing message in TA419 attacks asks for a response—that response trigger is the moment when attackers shift to more direct credential theft.

Third, organizations should provide security awareness training that emphasizes the sophistication of adversary-in-the-middle attacks. Traditional phishing awareness often focuses on obvious red flags, but Frameless BitB attacks can appear nearly identical to legitimate login screens because they operate within the actual browser window.

Fourth, monitor for unusual login activity and email forwarding rules. Compromised accounts often show telltale signs like logins from geographic locations the user never visits or sudden forwarding of emails to external accounts.

What’s Next for AI Policy Security

As the U.S.-China competition in AI intensifies, targeted phishing campaigns against policy experts will likely become more common and sophisticated. Intelligence agencies are already aware of these threats, but the burden of protection falls heavily on individual organizations and the policy community itself.

The fact that TA419 has operated successfully for over a year suggests that many phishing attempts may have succeeded without public disclosure. The attacks mentioned in Proofpoint’s report are only those discovered and attributed to this specific group—many more may go undetected.

Common Questions About AI Policy Phishing Attacks

Are only government officials targeted by these campaigns? No. Researchers identified victims at think tanks, academic institutions, and private sector AI companies. Anyone with influence on or knowledge of U.S. AI policy is potentially at risk.

Could these attacks happen to regular users, or only policy experts? The specific campaigns documented by Proofpoint targeted high-level experts through sophisticated impersonation. However, the underlying phishing techniques could be adapted for other targets. Standard phishing awareness remains important for everyone.

If my credentials were compromised, how would I know? Monitor your email for signs of unauthorized access, check your Microsoft 365 login history for unfamiliar sessions, and consider requesting a security audit from your organization’s IT department if you believe you may have been targeted.

Scroll to Top