China-aligned hackers impersonate AI experts to target US and Japan policy minds

China-aligned hackers impersonate AI experts to target US and Japan policy minds

A China-aligned hacking group has been posing as artificial intelligence experts and former US officials in a phishing campaign aimed at policy specialists in the United States and Japan. Cybersecurity firm Proofpoint said the group, known as TA419, used the impersonations to try to draw victims to fake login pages and steal their credentials. The campaign has been active since April 2025, according to the report.

Shopify_Landscape

Sponsored

Proofpoint said the hackers sent emails that appeared harmless at first, including invitations to join an "AI Policy Advisory Committee". Once a target replied, the attackers redirected them to a fraudulent sign-in page designed to capture login details. The report said the group used a browser pop-up window embedded inside a legitimate webpage to make the prompt look authentic and reduce the chance that victims would notice the deception.

The targets included policy experts at think tanks, defence contractors, universities and law firms in both countries. Proofpoint did not name all of the people or organisations affected, but one recipient was confirmed as Alex Engler, a former White House official who now leads the Penn Center on Media, Technology, and Democracy. Engler said he received one of the emails and later realised it had come from an impersonator after checking with industry colleagues.

The campaign is significant because it shows how cyber-espionage efforts are increasingly focused on people who shape technology policy, rather than only on technical systems. By impersonating real figures such as Lynne Edwards Parker, the former principal deputy director of the White House Office of Science and Technology Policy, the attackers appear to have been trying to exploit trust within a narrow policy community. The inclusion of targets in Japan also suggests the operation had a wider international reach.

Santuzza_land

Sponsored

Proofpoint said the same group was behind an earlier effort in February that impersonated a "prominent" Anthropic employee in an attempt to reach AI policy experts. That history suggests a sustained interest in artificial intelligence policy circles and in using real-world identities to increase the credibility of phishing messages. The report said the group is likely to continue targeting think tanks and other policy experts.

It remains unclear how many people received the emails, whether any credentials were stolen, or whether any of the targeted organisations suffered further compromise. Proofpoint did not identify the full list of victims, and Parker did not respond to a request for comment. The next developments to watch are whether more targets are disclosed, whether the campaign expands beyond the US and Japan, and whether officials or institutions issue warnings to policy communities.

360LiveNews 360LiveNews | 01 Oct 2026 18:02 LONDON
← Back to Homepage