A China-aligned hacking group has been targeting people helping shape American artificial intelligence policy, using the identities of government, policy and technology figures in attempts to compromise their accounts.
Cybersecurity company Proofpoint says the espionage-focused group, which it tracks as TA419, carried out a series of highly targeted phishing operations against AI policy specialists during 2026.
In July, the attackers first attempted to establish a conversation rather than immediately sending a malicious link.
They impersonated Lynne Edwards Parker, former Principal Deputy Director of the White House Office of Science and Technology Policy, and economist and foreign policy expert Heidi Crebo-Rediker.
Targets received apparently legitimate approaches inviting them to join a fictitious “AI Policy Advisory Committee” or contribute to a purported Senate Committee on Foreign Relations report on AI export controls and supply chains.
Only after a recipient responded would the attackers send a link leading through several redirects to a fake OneDrive page and an adversary-in-the-middle phishing system designed to compromise the victim's cloud account.
The system relayed Microsoft's genuine authentication process in real time, allowing a victim's password, multi-factor authentication code and other security checks to succeed while attackers captured the resulting authenticated session cookies.
Reuters independently identified one of those approached as Alex Engler, executive director of the Penn Center on Media, Technology, and Democracy and a former White House National Security Council official. Engler became suspicious and checked with colleagues before determining that the approach was fraudulent.
The July operation was not TA419's first attempt to gain access to America's AI policy world.
In February, the group impersonated a senior Anthropic employee while targeting an AI policy analyst at a US think tank. The approach referenced the use of Anthropic's Claude models by the US military.
Reuters reported that fewer than 10 people at a handful of organisations were targeted. Proofpoint said the selectivity suggested an intelligence interest in US policymaking rather than technology theft alone.
The company assesses that TA419's activity likely supports broader Chinese intelligence objectives surrounding US artificial intelligence policy, regulation and export controls. The group has also targeted people associated with defence, national security, energy, international relations and foreign policy, particularly in the United States and Japan.
Proofpoint describes TA419 as China-aligned, but has not publicly identified it as a specific unit of the Chinese government.
Beijing has repeatedly denied allegations that it conducts cyberespionage, although Chinese officials have not publicly addressed the TA419 operation specifically.
The activity illustrates how the AI race is expanding beyond processors, data centres and increasingly powerful models. Government intentions, export restrictions and the direction of future AI policy may themselves now be valuable intelligence.
The struggle to shape AI is increasingly reaching the inboxes of the people deciding how the technology will be governed.
