Hackers believed to be linked to China impersonated a former White House tech official in their email-phishing attacks against U.S. experts specialized in artificial intelligence policy, according to cybersecurity firm Proofpoint.
The campaign targeted a small number of people at think tanks, universities, and law firms, with a particular focus on experts working on AI regulation, export controls, and national strategy, Proofpoint said on Thursday in a report detailing the hackers’ behavior.
The report says the attacks likely support wider Chinese intelligence objectives to follow developments in U.S. AI policy and regulations.
Proofpoint tracks the group as TA419 and describes it as a China-aligned espionage operation.
The firm said the group has been observed targeting people at U.S. and Japanese institutions since at least April 2025.
In July, the group impersonated Lynne Parker, an AI and robotics researcher who held senior roles in the White House tech team under both President Donald Trump and former President Joe Biden, in emails inviting recipients to participate in an “AI Policy Advisory Committee.”
Alex Engler, a former White House official who leads the Penn Center on Media, Technology, and Democracy, confirmed he had received an email falsely claiming to be from Parker.
In another campaign, the hackers posed as Heidi Crebo-Rediker, who served as the State Department’s Chief Economist during President Barack Obama’s administration, asking recipients to contribute to a purported “Senate Foreign Relations Committee” report on AI export controls and supply chains.
Those initial messages were ordinary-looking and contained no obvious attempt to steal information. If a target replied, the hackers followed up with a link supposedly containing additional information.
That link, according to Proofpoint, would eventually take the recipient to a fake Microsoft OneDrive sign-in page designed to capture account credentials and give the attackers access to the victim’s account.
The method could also allow attackers to take over an active login even after the victim completed multifactor authentication.
TA419 used a similar approach in February, when it impersonated a senior employee at Anthropic, Proofpoint said.
An email sent to an AI policy analyst at a U.S. think tank carried the subject line “Request for Feedback on Military Integration of Claude,” referring to Anthropic’s AI model.
The exchange ultimately directed the recipient toward another fraudulent login page.
Proofpoint said it found no evidence that the targeted individuals or organizations were successfully breached.
It warned, however, that organizations in the scope of TA419 espionage should consider measures such as phishing-resistant authentication.
“TA419 will likely continue targeting think tanks and policy experts working on technologies, and in geographies, of particular interest to the Chinese government,” the firm concluded.
“These campaigns will likely also continue spoofing the identities of real subject-matter experts.”
The real Lynne Parker said she was disheartened to see her name used in attempts to target colleagues in the U.S. AI community.
“As this community knows, AI can make impersonations very convincing, so we can’t rely on a message looking suspicious,” she wrote in a LinkedIn post.
The episode, she said, should remind researchers and policy experts to practice “good cybersecurity hygiene,” including independently verifying unexpected requests and links before responding.
The Chinese Embassy in Washington did not respond to a request for comment.









