China-Linked Hackers Impersonate Anthropic Staff and Ex-White House Officials to Phish AI Experts
A China-aligned hacking group spent months impersonating a senior Anthropic employee and former US government officials to break into the email accounts of
A China-aligned hacking group spent months impersonating a senior Anthropic employee and former US government officials to break into the email accounts of American AI policy experts. Security firm Proofpoint, which tracks the group as TA419, says the targets worked at think tanks, universities and law firms.
The goal wasn't model weights or source code. It was the conversations around them: who is advising Washington on AI export controls, military use and chip policy, and what they are saying in private.
The Anthropic lure
In February, the attackers posed as a senior Anthropic employee asking targets for feedback on the military use of Claude. For someone working on AI governance, that is exactly the kind of email you open.
Starting in July, the group switched personas. It impersonated Lynne Parker, a former deputy at the White House Office of Science and Technology Policy, and Heidi Crebo-Rediker, a former State Department chief economist, according to The Next Web. Targets were invited to fake AI policy panels or asked to review supposed Senate reports on export controls.
Stealing sessions, not just passwords
The links led to fake Microsoft OneDrive pages built with a modified version of Frameless BitB, a browser-in-the-browser kit that draws a convincing fake login window inside a webpage. The pages ran an adversary-in-the-middle setup, relaying the real Microsoft login so the attackers could grab both credentials and session cookies.
That second part matters. A stolen session cookie lets an attacker walk past multi-factor authentication entirely. It is a different trick from the invisible-text ASCII smuggling Microsoft recently flagged, but it reaches the same place: a phishing page that the usual defenses wave through.
Small target list, big intelligence value
Fewer than ten people were targeted in the campaigns Proofpoint described. That tiny number is the point. Proofpoint frames the operation as policy intelligence gathering, aimed at people who shape what the US does about AI rather than people who build it.
TA419 has been active since at least April 2025, going after US and Japanese think tanks, defense contractors, universities and law firms. Its domains have spoofed the Heritage Foundation, the World Economic Forum and the Japan-Taiwan Exchange Association, Infosecurity Magazine notes.
AI labs keep showing up in state-backed operations, sometimes as tools and now as disguises. Anthropic's own September threat report catalogued attackers abusing Claude directly. Here, the company's name was simply the bait.
China has denied the hacking allegations, as it does with every US attribution, Reuters reported.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free