Chinese hackers have been impersonating a former US official to steal emails from experts in artificial intelligence. According to cybersecurity firm Proofpoint, the hackers, known as TA419, have been attempting to steal passwords from individuals working in US and Japanese research centers, defense companies, universities, and law firms since 2025.
The hackers have been using a sophisticated approach, writing emails that appear to be from AI or public policy experts, including Lynne Parker, who previously served as the deputy director of the White House Office of Science and Technology Policy. These emails typically propose collaboration or AI-related initiatives before directing the targets to websites designed to steal passwords.
Proofpoint attributed the hacking attempts to the Chinese group based on the types of malware used, the internet infrastructure employed to carry out the attacks, and the targets, which align with Chinese intelligence gathering priorities. The firm did not disclose the names of the targeted individuals or organizations but stated that they included experts working on AI policy, export controls, and national AI strategies.
Reuters independently identified one of the targeted experts as Alex Engler, a former White House official who now heads the Penn Center for Media, Technology, and Democracy. Engler received an email that appeared to be from Parker, inviting him to join a new AI policy project. However, he became suspicious and verified with others in the field before realizing it was a hacking attempt.
Engler expressed uncertainty about the motives behind the hacking attempt but noted that Proofpoint's analysis suggested an interest in US policy-making rather than mere technology theft. The hacking attempts, which targeted fewer than 10 individuals from a small number of institutions, highlight the ongoing threat of cyber espionage.
Parker confirmed that Engler was one of two individuals who received suspicious emails appearing to be from her in early July. She found the hypothesis of Chinese involvement to be plausible, given the ongoing competition between the US and China in AI. Parker stated that it was not surprising that China would attempt to gather information on AI policy plans.
The incident underscores the importance of cybersecurity and vigilance in the face of increasingly sophisticated hacking attempts. As the US and China continue to compete in AI, experts and organizations must be aware of the risks and take measures to protect their information and systems from cyber threats.
Key points
- Chinese hackers impersonated a former US official to target AI experts
- The hacking attempts were attributed to the Chinese group TA419
- The incident highlights the ongoing threat of cyber espionage in AI policy-making