Proofpoint ties TA419 hackers to phishing of US AI policy experts
Proofpoint researchers reported that China-linked group TA419 ran a July phishing campaign impersonating US officials, including a former White House science and technology policy staffer, to steal credentials from AI experts at US think tanks, universities, defense contractors and law firms. The campaign followed similar activity in February, when the group posed as an Anthropic employee to target a think tank AI policy expert, and is part of a pattern Proofpoint says dates back to at least April 2025.
GoKawiil's interpretation of the reporting above, not reported fact.
Proofpoint suggests the campaign aims to help Chinese intelligence track US AI policy and regulatory developments at a time of intense US-China competition over AI, including disputes about model distillation and export controls. The use of credible impersonation before any malicious payload indicates attackers are investing in social engineering to bypass traditional phishing defenses, which could make such campaigns harder for institutions to detect.
- TA419, a China-aligned group, impersonated US officials to phish AI policy experts in July 2025.
- The campaign targeted think tanks, universities, defense contractors and law firms, per Proofpoint.
- Researchers link the activity to broader Chinese efforts to monitor US AI policymaking.
YubiKey 5 NFC Security Key — Phishing campaigns like this one rely on stealing credentials through fake login pages, and a hardware security key like the YubiKey 5 NFC makes that kind of attack far harder to pull off since it requires physical possession for authentication. It's a practical step for researchers, policymakers, or anyone handling sensitive AI or government-related work to harden their accounts against AiTM phishing. Simple to set up and works across major platforms supporting FIDO2/U2F.
See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: darkreading.com — Elizabeth Montalbano, 2026-10-05
Published there as: “Chinese Hackers Impersonate US Officials for AI Cyber Espionage”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.