Chinese hackers impersonated a former White House official to target US AI policy experts
TLDR
- A China-aligned hacking group tracked as TA419 impersonated a former White House science policy official and a prominent economist to target fewer than 10 AI policy experts at US think tanks, universities and law firms.
- The campaign, run in July 2026, opened with benign emails inviting targets to join a fictitious "AI Policy Advisory Committee" before steering them to credential-phishing pages.
- Reuters identified one target as Alex Engler, a Penn-affiliated centre head and former White House official.
- Proofpoint says TA419 previously impersonated an Anthropic employee in February 2026 to target a separate AI policy analyst, and the activity likely supports Chinese intelligence efforts to track US AI policy and regulatory developments.
Proofpoint said TA419, a China-aligned, espionage-motivated group it has tracked conducting credential-phishing campaigns against think tanks, universities, defence contractors and law firms since at least April 2025, ran a previously unreported campaign in July 2026 impersonating Lynne Edwards Parker, former Principal Deputy Director of the White House Office of Science and Technology Policy, and separately economist and foreign policy expert Heidi Crebo-Rediker.2 The emails opened with benign outreach inviting targets to join a fictitious "AI Policy Advisory Committee" or to contribute to a Senate Committee on Foreign Relations report on AI export controls, before following up with a shortened link that led to a fake OneDrive page using a customised version of the open-source Browser-in-the-Browser phishing tool Frameless BitB.2
Proofpoint said the campaign targeted fewer than 10 individuals across a handful of organisations.1 Reuters identified one of the targets as Alex Engler, head of a centre at the University of Pennsylvania and a former White House official.1 Proofpoint separately disclosed that in February 2026, TA419 impersonated a senior Anthropic employee, using the subject line "Request for Feedback on Military Integration of Claude," to target an AI policy analyst at a US think tank with a similar credential-phishing chain.2
Proofpoint assessed the activity likely supports wider Chinese intelligence objectives to track developments in US AI policy and regulation, occurring amid strategic competition between the US and China that includes accusations of AI model distillation and export-control disputes.2
Why it matters: impersonating the people who shape AI policy, rather than attacking AI systems directly, lets a state-aligned group read the regulatory and export-control debate from the inside, well before any resulting rules are public.