Technology

Chinese Hackers Posed as a Former White House AI Official to Target US AI Policy Experts

Zaara Abbas

By: Zaara Abbas

4 min read

A Chinese hacking group that Proofpoint tracks as TA419 impersonated AI experts, including former White House AI official Lynne Parker, to steal the email passwords of fewer than 10 people working on AI regulation, export controls, and national AI strategy. One target, Penn’s Alex Engler, spotted the fake invitation before it worked.

[For more news, click here] 

An email that landed in Alex Engler’s inbox appeared to come from Lynne Parker, one of the best-known former White House officials on AI, and it invited him to join a new AI policy project. Engler, the executive director of the Penn Center on Media, Technology, and Democracy, said the message “felt slightly, nebulously off.” He checked with colleagues and confirmed it was fake.

It was part of a campaign by Chinese hackers to break into the email accounts of people who work on AI policy, according to a report published the same day by the cybersecurity company Proofpoint. The firm tracks the group as TA419 and says it has been trying to steal passwords from staff at US and Japanese think tanks, defense contractors, universities, and law firms since at least 2025.

How the TA419 Phishing Campaign Worked

In this round, the hackers posed as US AI experts, including Parker, and sent messages proposing collaborations on AI projects. Targets who replied were steered toward websites built to capture their login details, which would hand the attackers their email. Proofpoint said fewer than 10 people at a handful of organizations were targeted, all of them working on AI regulation, export controls, or national AI strategy.

Engler’s own background fits that profile, since before Penn he was assistant director of AI policy at the White House Office of Science and Technology Policy and director for democracy and technology at the National Security Council, and earlier a fellow at the Brookings Institution, according to his Penn biography. An invitation from Parker, another White House AI veteran, would not have looked out of place in his inbox.

Proofpoint tied the activity to China based on the malware involved, the internet infrastructure the hackers relied on, and how closely the choice of targets matched Chinese intelligence priorities. China’s embassy did not respond to requests for comment and Beijing has long denied carrying out cyberespionage.

Why AI Policy Experts are on the List

Parker, who was the founding director of the White House’s National AI Initiative Office, said she started receiving suspicious messages in early July.

“The United States and China are in a competition around AI,” said Parker. She added that efforts to get people in the AI policy space to reveal their plans were “not surprising,” assuming that was what the hackers were after.

The people Proofpoint says were targeted work on the issues where Washington and Beijing clash most directly over technology, including which advanced chips can be sold to China and how the US plans to regulate AI. Their inboxes can show how those policies are taking shape, who is being consulted, and what is still being argued over, well before anything is made public.

AI policy has become one of the busiest fronts in that rivalry, with Washington restricting sales of advanced AI chips to China since October 2022 and changing those rules several times since. Japan, whose think tanks were also on TA419’s list, passed its own law to promote AI development in 2025 and works closely with the US on technology security.

Chinese Hackers have Used this Approach Before

A different group that Proofpoint tracks as TA415, also known as APT41, sent emails in July and August 2025 posing as Representative John Moolenaar, who chairs the House select committee on competition with the Chinese Communist Party, and asked recipients for feedback on draft sanctions legislation, according to SecurityWeek. Those messages went to government agencies, think tanks, and academics working on US-China relations and trade. Proofpoint has also reported this year that TA416, another China-linked group, resumed espionage campaigns against European governments.

Invitations to join projects, review drafts, or speak on panels arrive constantly in policy work, and that is what makes them useful cover for this kind of attack. In Engler’s case, the only reason the attempt failed was because he felt the message seemed off and consulted with colleagues before doing anything with it.

Password theft of this kind is one reason the US Cybersecurity and Infrastructure Security Agency urges organizations to use phishing-resistant multifactor authentication, such as hardware security keys, which will not work on a fake login page even if someone types their password into it.

Proofpoint did not name the other people or organizations targeted in the TA419 campaign.

Related Articles

The Middle East’s Next Battle May Be Fought in Code

An Exposed Server Revealed How a Ransomware Affiliate Used AI to Plan Attacks

Exclusive: Nikita Astionov on the Security Risks of Giving AI Agents More Control

Share this article

Related Articles