Artificial intelligence is becoming increasingly important in government policy, national security and the technology industry. That growing importance is also making people involved in AI policy attractive targets for cyberattacks.
Cybersecurity company Proofpoint says a China-aligned hacking group known as TA419 has been impersonating real AI specialists and former US government officials while targeting people involved in artificial intelligence policy.
The campaign demonstrates how modern phishing attacks can go beyond simply sending suspicious links. Instead, the attackers reportedly attempted to establish credibility first, making their messages appear like genuine professional opportunities.
The hackers started by building trust
According to Proofpoint, a campaign observed in July targeted AI policy professionals connected to think tanks, universities, defence contractors and law firms in the United States and Japan.
Some targets received emails that appeared to come from recognized figures in the AI and policy community.
The messages included believable invitations to participate in projects, including a supposed AI Policy Advisory Committee.
Rather than immediately attempting to steal information, the attackers reportedly wanted recipients to engage with the conversation first.
After a target responded, the attackers could continue the interaction before eventually directing the person toward a fraudulent login page designed to collect account credentials.
Real people were used as bait
One of the identities reportedly used by the attackers belonged to Lynne Edwards Parker, a former principal deputy director at the White House Office of Science and Technology Policy.
The group also reportedly impersonated economist and foreign-policy expert Heidi Crebo-Rediker during another campaign.
Reuters independently confirmed that former White House official Alex Engler received one of the deceptive messages.
Engler, who now leads the Penn Center on Media, Technology, and Democracy, reportedly checked the message with colleagues and discovered that the person contacting him was an impersonator.
Proofpoint did not publicly identify all of the people targeted by the campaign.
The fake login page was designed to look convincing
The campaign reportedly used a technique known as Browser-in-the-Browser.
This technique can make a fake browser window appear inside a legitimate-looking webpage. To an unsuspecting user, the window can resemble a normal Microsoft sign-in prompt.
The goal is to make the victim believe they are entering their information into a familiar service when they are actually interacting with an attacker-controlled interface.
Proofpoint says the campaign also used an adversary-in-the-middle technique to capture Microsoft 365 authentication information.
These techniques make modern phishing attacks considerably harder to identify simply by looking at the appearance of a webpage.
TA419 has targeted the AI community before
The activity is not believed to be an isolated incident.
Proofpoint says it has tracked TA419 activity since at least April 2025, with the group targeting people and organizations connected to policy, technology and national security.
The group also reportedly targeted an AI policy analyst in February 2026 while impersonating a senior employee of AI company Anthropic.
That operation used a message connected to discussions about the potential military use of Anthropic's Claude AI models.
Using a current and sensitive AI policy issue gave the attackers a believable reason to contact someone already working in the field.
Why AI policy experts matter
AI policy is increasingly connected to national security, economic competition and technology regulation.
Experts working in this area can participate in discussions involving government regulations, AI safety, export controls, defence applications and national technology strategies.
Their communications may therefore contain information that could be valuable to an attacker.
Instead of directly attacking an AI system, an attacker can attempt to compromise the people helping governments and organizations decide how AI should be developed, regulated and deployed.
Trust has become part of the attack surface
The campaign highlights a growing challenge in cybersecurity: attackers can exploit trust just as effectively as technical weaknesses.
Traditional phishing emails may contain obvious warning signs such as strange wording, suspicious attachments or unfamiliar websites.
An email appearing to come from a real researcher, government official or technology expert can be much harder to question.
The attackers reportedly used real identities and current AI policy topics to make their communications appear authentic.
This makes independently verifying unexpected requests increasingly important, particularly when they involve documents, account access or sensitive information.
What users can learn from the campaign
Security researchers recommend using strong, phishing-resistant authentication methods, including passkeys where available.
Users should also be cautious when receiving unexpected invitations, documents or login requests, even when the message appears to come from someone familiar.
If an important request seems unusual, contacting the supposed sender through a separate, trusted communication channel can help establish whether the message is genuine.
Organizations working with sensitive AI, government or technology information can also reduce risk through stronger authentication, employee security awareness and procedures for verifying unusual requests.
The bigger lesson from the campaign is that artificial intelligence is creating new opportunities for attackers to exploit human trust.
As AI becomes more closely connected to government policy, business and national security, the people shaping those decisions are likely to remain valuable targets for sophisticated cyber operations.




