October 2, 2026, (Inside AI) — A China-linked threat group known as TA419 launched a targeted phishing campaign against US AI policy experts, impersonating a senior employee at AI safety company Anthropic and two former government officials. The operation, disclosed by cybersecurity firm Proofpoint on October 1, aimed to steal emails and gain unauthorized access to sensitive accounts.
The campaign began in February 2026 and targeted fewer than 10 individuals across think tanks, universities, law firms, and defense companies. Attackers spoofed Lynne Parker, former White House technology official, and Caroline Crebo-Rediker, former State Department economist, alongside the unnamed Anthropic employee. Proofpoint noted that later messages carried malware-laced files or attempted to trick recipients into surrendering passwords.
This selective targeting suggests a state-sponsored intelligence operation focused on policy deliberations, not mass data theft. The inclusion of an Anthropic employee signals growing Chinese interest in AI development centers. Attribution to China rests on malware analysis, server infrastructure, and targeting patterns consistent with decades of Chinese espionage priorities.
Proofpoint assessed TA419 as an established actor active since at least 2025 and expected to continue indefinitely. The campaign's success remains unclear; Proofpoint did not disclose whether any accounts were compromised.
Read: North Korean Hacking Group Builds AI Tools for Cyberattacks
Why AI Policy Experts Are Now Prime Targets
The targeting of AI policy experts reflects a strategic shift in Chinese espionage. Rather than focusing solely on proprietary technology or financial data, TA419 pursued insight into US policy formulation. This aligns with China's long-standing interest in influencing and anticipating regulatory decisions around emerging technologies.
Anthropic, a leading AI safety and research company, has become a focal point due to its work on large language models and policy advocacy. The impersonation of a senior Anthropic employee indicates that Chinese intelligence views AI companies as gatekeepers of both technical and policy knowledge. The campaign also targeted personnel at institutions involved in AI governance, such as think tanks and universities.
Proofpoint's disclosure highlights the sophistication of TA419's social engineering. Attackers crafted convincing messages that appeared to originate from trusted sources. The escalation from credential theft to malware deployment shows adaptability. The narrow scope suggests extensive reconnaissance to identify high-value targets.
What Proofpoint's Disclosure Leaves Unanswered
Proofpoint did not reveal whether any targets fell victim to the phishing attempts. The timing of the disclosure, months after the campaign began, suggests that most attempts may have been thwarted by security awareness training or email filtering. However, the possibility of partial success remains.
The campaign's focus on policy experts rather than technical staff indicates that China seeks to understand US decision-making processes. This could inform future influence operations or diplomatic strategies. The inclusion of Japanese institutions in TA419's targeting patterns suggests a broader Indo-Pacific focus.
Anthropic has not publicly commented on the campaign. The company's security team likely cooperated with Proofpoint's investigation. The incident underscores the need for heightened vigilance among AI policy professionals.
Read: Major Tech Companies Call for Defensive Surge Against AI-Driven Hacks
As AI regulation evolves, such espionage attempts may increase. The line between technical and policy intelligence blurs. Companies like Anthropic must protect both their intellectual property and their policy insights.
Proofpoint's report serves as a warning. State-sponsored actors will continue to exploit trust and human error. The AI community must adapt its defenses accordingly.